The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Add local domain users

Prev Next

This option automatically adds the previously logged in domain users to the client system, so that administrators don't have to manually assign users to the client systems in the ePolicy Orchestrator console.

This option can be enabled when needed through the Drive Encryption Product Settings Policies (Menu | Policy | Policy Catalog | Drive Encryption 8.x (Product Settings) | Log on tab | Add local domain users).

When enabled, the DEAgent queries the client system for the currently/previously logged on domain users. The DEAgent then sends the collected data to the ePO - On-prem server. These users are then assigned to the client system.

Note

We recommend that you enable this option so that you can authenticate to the client pre-boot without having to manually assign the users to the client system in the ePolicy Orchestrator console. However, it is the responsibility of the administrator to decide whether or not this is required depending on corporate requirements.

Prerequisites

These prerequisites must be met to add the local domain users to the Drive Encryption client systems:

  • The Trellix Agent package is deployed.

  • The Trellix DEAgent package is deployed to the required client systems.

  • The Drive Encryption package is deployed to the required client systems.

  • Registered Active Directory is added and configured correctly.

    Note

    The Add local domain users option is supported with Active Directory only.

  • An automated LDAP Server User/Group Synchronization task (LdapSync: Sync across users from LDAP) is scheduled and run.

    Note

    This task is used to map Active Directory attributes to the Drive Encryption settings. This is required for every Registered LDAP server that is to be used with Drive Encryption.

  • Client systems should use Active Directory for authentication.

    • These domain users must be previously or currently logged in users.

At the client side

The Add local domain user option is processed during the next agent-server communication. If this option is enabled in the policy settings, the DEAgent queries the client system for the domain users who have logged on to the client. The DEAgent then sends the collected data to the ePO - On-prem server.

The transmitted data is a list of user names and the domain names. Local Domain users are detected by examining the Windows registry that has the profile list, which lists the users who have logged in to the system.

At the server side

When the DE administrator receives a message for adding local domain users, it executes these steps.

  • It attempts to find the domain name that the user belongs to. This is done by querying the Registered Active Directory that is configured with the automated LdapSync: Sync across users from LDAP task.

  • If a registered LDAP server is found, then it matches the domain name of the user. An LDAP query is performed and attempts to find an LDAP node with a samaccountname that matches the user name.

If the user name is found, it is assigned to the corresponding client system. You can query the added users by using the View Users option under Menu | Data Protection | Encryption Users | Actions | Drive Encryption | View Users.