The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Configure Trellix FRP key authentication

Prev Next

Options related to Trellix FRP key authentication are configured on the Server Settings page.

Option

Definition

Enable FRP Key Authentication

Select this option to enable upgrade to the Trellix FRP step-up authentication functionality.

Note

This is a configurable option that is available only for users upgrading from Trellix FRP 4.3.x. For new installations, this option is enabled by default. Also, this option cannot be disabled after it has been enabled.

Option

Definition

Password Token Initialization Method

  • Email (Custom Email message) — Sends the configured text to the user's email together with a randomly generated password.

    Note

    The email server must be configured in the ePO - On-prem server settings.

    Important

    Ensure that the Active Directory includes the email attribute. If the email attribute is not available and this setting is selected for password token initialization, users must be led through a token recovery process.

  • Password (Default) — Assigns a default password when keys are assigned to the user's password token for the first time. The user will be forced to change this password on first logon. This is the default initialization method.

    • Change default password — Select this option to change the default password with a more secure initialization password, then enter a new password in the Password and Confirm fields.

  • No Password — Forces the user to set up a new password.

Smart card

  • Certificate Revocation List

    • Enable Certificate Revocation List processing — Select this option to maintain a list of certificates that have been revoked, and so, users presenting those (revoked) certificates will no longer be allowed to log on using their smart card.

    • Certificate Revocation List URL — The URL where the Certificate Revocation List is maintained.

    • Delta Certificate Revocation List URL — The URL where changes in the Certificate Revocation List are monitored.

Token Recovery

  • Generate random passwords — Generates random passwords for use in the recovery process.

    Note

    This option is automatically enabled and can't be disabled.

    • Generate simple passwords — Generates simple random passwords, which are easier to read out to the user. Default value is enabled.

      Note

      We recommend that you disable this option if you enable the Send recovery password by Email option.

    • Send recovery password by Email — Sends the recovery password to the email address configured for the user.

      Note

      Recovery by email requires that the ePO - On-prem email server settings be configured and that Active Directory contain the user's email address.

  • Smart card recovery token settings

    • Expire after __ logon attempts (1-60) — Sets the number of valid logon attempts after which the smart card recovery token expires.

    • Expire after __ days (1-366) — Sets the time period (in days) after which the smart card recovery token expires.

    • Warn after __ days (1-366) — Sets the time period (in days) after which a warning is displayed that the smart card recovery token is about to expire.

  • Enable special handling of file encryption keys — Enables the creation of keys designated for use with smart cards only.

    Important

    This setting can't be disabled after it is enabled.