Applies to: All editions
Final preparation
Before selecting Secure Erase:
- Confirm authorization and custody for every selected device.
- Export a device inventory where required.
- Review model, serial number, capacity, bus, and physical location.
- Confirm pre-erasure SMART and fail behaviour.
- Confirm the sanitization approach and method.
- Confirm the post-erasure assessment.
- Resolve all preflight blocks and review every warning.
- Close other applications and stop storage-management tasks.
- Connect the system to stable power.
- Ensure the operator can remain available for the restart and completion prompt.
Start the job
- Select Secure Erase.
- Read the destructive-operation warning.
- Review the complete target and settings summary.
- Cancel immediately when any information is unexpected.
- Confirm the restart only after all targets are correct.
DriveErase then prepares the Privileged Execution Environment, creates a signed one-use job containing the selected device identities and licence policy, and creates a temporary boot entry.
Job protections
Before disk operations can begin, the privileged environment validates:
- The job signature;
- The supported job and policy format;
- The active licence capabilities encoded in the job;
- The creation and expiry times;
- The number and structure of target entries;
- The requested methods and health options;
- The identity and path of each target;
- That the target is not the environment’s own boot disk.
A failed validation stops the job before destructive processing.
Job validity
A staged job is short-lived and intended for the immediate restart. Do not delay the reboot or attempt to reuse old job data. When a job expires or is rejected, return to DriveErase, refresh the devices, revalidate the settings, and create a new job.
Reboot and encryption considerations
DriveErase can temporarily prepare the system for a one-time boot. Where the system volume uses BitLocker, the required boot-protection handling is performed for the restart on a best-effort basis. Ensure that authorized recovery information is available before changing boot state in a managed environment.
