The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Assign regular keys to users or user groups

Prev Next

Before a user personal key can be assigned to a Directory Server Object, verify that the LDAP Sync Server task is set up to register the LDAP server or Microsoft Entra ID server. For more details, see Register an LDAP server with Trellix ePO On-Prem and Register Microsoft Entra tenant with Trellix ePO On-Prem.

To assign regular keys to users, user groups, or organizational units, follow this procedure.

  1. Log on to the ePO - On-prem server as an administrator.

  2. Click Menu → Data Protection → FRP Keys to open the FRP Keys page.

  3. Select the key that you want to assign, then click k Actions → Key Assignments → Assign to users.

  4. Assign the key to the user, user group, or organizational unit by selecting from Users, From the groups, or From the organizational units accordingly.

  5. (Optional) Select Recursive to assign the key to subgroups of the selected groups (if applicable).

  6. In the Authentication Type area, select one of the following:

    • OS authentication — To enable users to access assigned keys through operating system authentication.

      Note

      ePO - On-prem administrator has the flexibility to mandate that the user authenticates using the Active Directory or Entra ID user name and password for the first time that the OS token is used on a given Windows system. This requirement can be configured from the OS Token tab of the Authentication policy.

    • Password authentication — To enable users to access assigned keys through password authentication.

    • Smart card PKI authentication — To enable users to access assigned keys through smart card authentication. Smart card PKI authentication is not supported for Entra ID users.

    • Virtual smart card authentication — To enable users to access assigned keys through virtual smart card authentication. Virtual smart card authentication is not supported for Entra ID users.

      Note

      ePO - On-prem administrator has the flexibility to mandate that the user authenticates using the Active Directory user name and password for the first time that the Virtual smart card token is used on a given Windows system. This can be configured from the Virtual smart card Token tab of the Authentication policy.

  7. Click OK.

    The key assignment is processed as a task. You can view the task progress in the Trellix server task log. This task is automated and runs immediately after key assignment. If this task is not successfully run immediately after key assignment, it is run as part of the daily Trellix FRP Process key assignments task or when the task is run manually.

Note

The enrollment details for Trellix Endpoint Assistant (QR image) is not sent when a key is assigned to a user, who is part of an Organizational Unit (OU).

When the key assignment task is complete, the key is available to users or user groups. The key assignment process can be in these states:

  • Pending Processing — In the queue or being prepared for processing.

  • Processing in Progress — Key assignment process is in progress.

  • Processing was Successful — Keys are available to the assigned users and user groups.

Note

Similar to the key assignment, the key unassignment process can be in these states: Pending Unassignment, Processing Unassignment, and Successfully Unassigned.