Automatic Decryption Service
What is the Automatic Decryption Service?
The Automatic Decryption Service is a Windows endpoint feature that monitors a configured source directory for newly copied encrypted files, decrypts them automatically, and moves the decrypted output to a configured destination directory - all based on the policy configured in the admin dashboard.
What Problem Does the Automatic Decryption Service Solve?
Some workflows require decrypted copies of protected files to be produced quickly and consistently, without asking users to decrypt each file by hand and without decrypting the files in the source directory. The Automatic Decryption Service automates this step: drop an encrypted file into the watched folder and a decrypted copy appears in the destination folder, under controlled, time-bound conditions set by an administrator.
How Does It Work?
The service watches the configured source directory for file-creation events and decrypts newly copied encrypted files automatically.
Decrypted output is moved to the configured destination directory.
It runs under the currently logged-in Windows user account.
In addition to watching for file-creation events, the service performs periodic directory scans (a rescan interval) so that files are not missed if file-system notification events are lost or delayed.
Administrators configure the source and destination directories, an activation expiration window, the rescan interval, how long decrypted files are retained in the destination, and rate-limiting controls.
The Automatic Decryption Service must be enabled by an administrator in the user policy before it becomes active.
Use Cases
Streamlined downstream processing: Automatically produce decrypted copies for tools or pipelines that need plaintext input, without manual steps.
Controlled, time-bound decryption: The expiration window and destination retention settings keep decrypted output available only for as long as it is needed.
Key Benefits
Removes the manual effort of decrypting files one at a time.
Provides reliable coverage by combining real-time file-creation monitoring with periodic rescans.
Learn how to configure this from the Automatic Decryption Service policy settings.
For more information on how to enable and configure the Automatic Decryption Service, please contact FenixPyre Support.
Last updated
Was this helpful?
