Sanitize an Active System Disk

Applies to: All editions; the alternate host must meet edition requirements

System-disk protection

DriveErase marks the disk containing the active Windows installation as the system disk and prevents it from being selected. The Privileged Execution Environment also refuses to erase the disk from which it is running.

This protection prevents DriveErase from destroying the operating files required to prepare, start, and control the job.

Supported workflow

To sanitize a former system disk:

  1. Shut down the original computer;
  2. Remove the target disk or otherwise ensure it is no longer the active system disk;
  3. Connect it as a secondary non-system device to another supported DriveErase computer;
  4. Start the host from its own separate Windows system disk;
  5. Scan and identify the target by model, serial, capacity, and physical connection;
  6. Apply the appropriate method and report procedure;
  7. Return the sanitized device to the approved disposition process.

Whole-computer retirement

For multiple-device computers, inventory every internal and removable storage component. Systems can contain separate NVMe, SATA, recovery, cache, expansion-card, or removable devices.

Encrypted system disks

Encryption does not remove the need for the approved sanitization or destruction process. A locked encrypted disk can still require a device-level operation, key-management evidence, or physical destruction according to policy.

OEM and recovery storage

Recovery partitions located on the target disk are included when the complete physical device is sanitized. Recovery media stored on another disk, USB device, network share, or vendor service remains separate.