Start a DriveErase Sanitization Job

Applies to: All editions

Final preparation

Before selecting Secure Erase:

  1. Confirm authorization and custody for every selected device.
  2. Export a device inventory where required.
  3. Review model, serial number, capacity, bus, and physical location.
  4. Confirm pre-erasure SMART and fail behaviour.
  5. Confirm the sanitization approach and method.
  6. Confirm the post-erasure assessment.
  7. Resolve all preflight blocks and review every warning.
  8. Close other applications and stop storage-management tasks.
  9. Connect the system to stable power.
  10. Ensure the operator can remain available for the restart and completion prompt.

Start the job

  1. Select Secure Erase.
  2. Read the destructive-operation warning.
  3. Review the complete target and settings summary.
  4. Cancel immediately when any information is unexpected.
  5. Confirm the restart only after all targets are correct.

DriveErase then prepares the Privileged Execution Environment, creates a signed one-use job containing the selected device identities and licence policy, and creates a temporary boot entry.

Job protections

Before disk operations can begin, the privileged environment validates:

  • The job signature;
  • The supported job and policy format;
  • The active licence capabilities encoded in the job;
  • The creation and expiry times;
  • The number and structure of target entries;
  • The requested methods and health options;
  • The identity and path of each target;
  • That the target is not the environment’s own boot disk.

A failed validation stops the job before destructive processing.

Job validity

A staged job is short-lived and intended for the immediate restart. Do not delay the reboot or attempt to reuse old job data. When a job expires or is rejected, return to DriveErase, refresh the devices, revalidate the settings, and create a new job.

Reboot and encryption considerations

DriveErase can temporarily prepare the system for a one-time boot. Where the system volume uses BitLocker, the required boot-protection handling is performed for the restart on a best-effort basis. Ensure that authorized recovery information is available before changing boot state in a managed environment.