The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Assign user personal keys to users or user groups

Prev Next

You can assign a user personal key only to Active Directory domain users, user groups, or organizational units and Entra ID users and user groups.

Before a user personal key can be assigned to a Directory Server Object, verify that the LDAP Sync Server task is set up to register the LDAP server or Microsoft Entra ID server. For more details, see Register an LDAP server with Trellix ePO On-Prem and Register Microsoft Entra tenant with Trellix ePO On-Prem.

Note

The FRP Upgrade task fails to process user personal keys, on ePO - On-prem versions other than 5.1.2 and 5.3, even though the Active Directory server is turned online after being offline. The workaround for this is to restart the services of ePO - On-prem (any version) to process the user personal keys.

  1. Click Menu → Data Protection → FRP keys.

  2. Actions → Key Assignments → Assign UPKs to assign a user personal key.

  3. Assign the user personal key to the user, user group, or organizational unit by selecting from either Users, From the groups, or From the organizational units accordingly.

  4. (Optional) Select Recursive to assign the key to subgroups of the selected groups (if applicable).

  5. In the Authentication Type area, select either of the following:

    • OS authentication — To enable users to access assigned keys through operating system authentication.

      Note

      The ePO - On-prem administrator has the flexibility to mandate that the user authenticates using the Active Directory or Entra ID user name and password for the first time that the OS token is used on a given Windows system. This can be configured from the OS Token tab of the Authentication policy.

    • Password authentication — To enable users to access assigned keys through password authentication.

    • Smart card PKI authentication — To enable users to access assigned keys through smart card authentication. Smart card PKI authentication is not supported for Entra ID users.

    • Virtual smart card authentication — To enable users to access assigned keys through virtual smart card authentication. Virtual smart card authentication is not supported for Entra ID users.

      Note

      The ePO - On-prem administrator has the flexibility to mandate that the user authenticates using the Active Directory user name and password for the first time that the Virtual smart card token is used on a given Windows system. This can be configured from the Virtual smart card Token tab of the Authentication policy.

  6. Click OK.

    The key assignment is processed as a task. You can view the task progress in the Trellix server task log. This task is automated and runs immediately after key assignment. If this task is not successfully run immediately after key assignment, it is run as part of the daily FRP Process key assignments task or when the task is run manually.

When the key assignment task is complete, the key is available to users or user groups. The key assignment process can be in these states:

  • Pending Processing — In the queue or being prepared for processing.

  • Processing in Progress — Key assignment process is in progress.

  • Processing was Successful — Keys are available to the assigned users and user groups.

Note

Similar to the key assignment, the key unassignment process can be in these states: Pending Unassignment, Processing Unassignment, and Successfully Unassigned.