SecureDoc: Removable Media Container Encryption (RMCE)
What happens to an encrypted USB drive when the person who knew the password leaves? WinMagic SecureDoc™ RMCE replaces shared passwords with enterprise key management, so authorized users on managed endpoints open encrypted containers automatically and departing employees lose access the moment their key is revoked. The brochure covers dual drive letters, Disc Access Control policies, executable quarantine, and secure sharing with external partners. Download the brochure to see how it works.
How does SecureDoc RMCE protect data on USB drives without using passwords?
SecureDoc RMCE reimagines removable media security by replacing passwords with enterprise key management.
On managed Windows or macOS endpoints, users access encrypted USB drives and external media automatically:
- No password prompts
- No shared credentials
- No helpdesk resets for forgotten passwords
Here’s how it works in practice:
- Users create an AES 256-bit encrypted container (up to 4 TB) on a USB drive, external hard drive, network share, or CD/DVD.
- When the media is inserted into a managed endpoint, it mounts with two drive letters (Windows): one for the encrypted container and one for any allowed unencrypted space.
- Group-based cryptographic keys unlock the encrypted container automatically in the background, so users just open File Explorer and work with files as usual.
Because keys—not passwords—control access, IT can:
- Assign company-wide, group, or personal keys per profile
- Revoke a single user’s key instantly when they leave, without changing any passwords
- Maintain long-term recoverability using human-readable key labels that link keys to users, departments, or groups
This approach reduces operational risk, removes the need for shared passwords, and keeps encrypted media recoverable even years later.
Can we still share encrypted USB data with external partners and unmanaged devices?
Yes, SecureDoc RMCE is designed to support secure sharing beyond your managed environment.
When you prepare a removable drive for external use, RMCE can embed a Media Viewer and Key File directly on the media. For recipients on unmanaged Windows or macOS devices:
- They insert the USB drive or other media.
- They use the built-in Media Viewer to open the encrypted container.
- They authenticate with a single password—no SecureDoc installation is required.
If that password is lost, the user can perform a Challenge Response recovery with an administrator to restore access, avoiding permanent data loss.
This model lets you:
- Share sensitive data securely with external partners, contractors, courts, or agencies
- Keep your internal users on passwordless, key-based access on managed endpoints
- Provide a straightforward password-based experience only for unmanaged recipients
In short, internal users benefit from automatic key unlocking, while external users get a simple, self-contained way to open encrypted content on any compatible device.
What management and compliance controls does SecureDoc RMCE provide for IT and security teams?
SecureDoc RMCE is centrally managed through SecureDoc Enterprise Server (SES), giving IT and security teams detailed control over how removable media is used and audited.
Key management and policy controls include:
- Group-based keys & key rings: Company-wide, group, and user keys can be assigned per profile so multiple users or AD groups can unlock the same container without sharing passwords.
- Key labeling: Human-readable labels tie keys to users, departments, or groups, making it easy to identify the right key even years later and ensuring long-term data recoverability.
- Granular policy control: Policies are applied at the device level, with user and key associations managed via SES. You can configure behavior per specific user on a specific device.
- Disc Access Control (DAC): Enforce encryption on all writes and define how unencrypted space is handled (no access, read-only, or read-only if not encrypted).
- Partial encryption with dual drive letters: RMCE can split media into encrypted and unencrypted areas, each with its own drive letter and policy set.
- Trusted Device Allow List: Only pre-approved drives are allowed to connect; unauthorized devices are blocked before any content is accessed.
- Executable quarantine: Executable files on unencrypted space are automatically renamed to
.quarantine, preventing them from running on managed endpoints while remaining recoverable by an admin.
For compliance and visibility, RMCE provides:
- File activity logging: Names of all files written to both encrypted containers and unencrypted space on managed devices are logged.
- Centralized audit trail: Logs are transferred to the SES console, supporting audits for regulations such as HIPAA, GDPR, and PCI DSS.
Together, these capabilities help IT teams reshape how removable media is controlled, monitored, and governed across the organization.