The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Configure DPSSP server settings on ePO - On-prem

Prev Next

The administrator must configure DPSSP server settings within ePO - On-prem to allow a user to obtain the recovery key or response code on the client system using DPSSP.

Make sure that you have installed the dpssp.zip extension on the ePO - On-prem server before performing this task.

Task
  1. Log on to the ePO - On-prem server as an administrator.

  2. Click Menu → Configuration → Server Settings.

  3. On the left pane, select DPSSP Settings and click Edit to open the Edit DPSSP Settings page.

  4. Enable the Self Service Portal option.

  5. Next to ePO user, type the ePO - On-prem user name.

    Note

    Make sure that the ePO - On-prem user name that you enter has the permission to perform recovery operations in Drive Encryption. We recommend that you create a specific ePO - On-prem user for DPSSP recoveries, and limit the permission set privileges to Drive Encryption recovery only.

  6. Next to Authentication, select the Active Directory sever that the users need to authenticate to.

    Note

    Make sure to note that the administrator has selected the registered AD in ePO - On-prem.

  7. Next to Logging, enable the Log authentication attempts and Log user activity options.

  8. Next to Blocking, enable the Enable IP address blocking option, and perform the following operations:

    1. Block IP address after (failed logins) — Type the numeric value to block the IP address after the specified number of unsuccessful logon attempts.

    2. Unblock after (minutes) — Type the numeric value in minutes to unblock the respective IP address after the specified number of minutes.

      Note

      To instantly unblock an IP address, refer to the How to instantly unblock a user or IP address section.

  9. Next to Blocking, enable the Enable user blocking option, and perform the following operations:

    1. Block user after (failed logins) — Type the numeric value to block the user after the specified number of unsuccessful logon attempts.

    2. Unblock after (minutes) — Type the numeric value in minutes to unblock the respective user after the specified number of minutes.

      Note

      If you either install the dpssp.zip extension or restart the ePO - On-prem system, you cannot block or unblock users for 10 minutes.

      Note

      To instantly unblock a user, refer to the How to instantly unblock a user or IP address section.

  10. Next to Session, type the numeric value in minutes to log off the user's session after the specified number of minutes.

  11. Click Save.