Policy Requirements for ES GuardPoints
Initializing an ES GuardPoint requires a Standard or In-Place Data Transformation policy with a KMIP-accessible XTS-AES 256 key as described in Initialize Windows CTE-Efficient Storage Devices.
Rekeying an ES GuardPoint requires an In-Place Data Transformation policy with a KMIP-accessible XTS-AES 256 key as described in Changing the Encryption Key for a Windows ES GuardPoint.
You may add security rules to restrict certain user/process access to protected devices. For suggestions about what security rules you may want to use, see Use Cases involving Efficient Storage GuardPoints.