The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Configure UBP enforcement

Prev Next

By default, all users inherit the default User-Based Policy assigned to a system, and are prevented from using Policy Assignment Rules. This inheritance allows maximum system scalability.

To allow a user to use a non-default UBP, you must enable the Configure UBP enforcement option for that user. This option allows Policy Assignment Rules to select a specific non-default user-based policy for the user. If not enabled, Policy Assignment Rules are not performed and the user inherits the default user-based policy.

Note

When the Configure UBP enforcement option is enabled for a user who is not assigned a Policy Assignment Rule, activation fails on the client systems.

Drive Encryption requires that you specify which groups of users can use the Policy Assignment Rules. The allowed users get their required user-based policy. Users who are not allowed to use the Policy Assignment Rules inherit the default user-based policy assigned to the system.

Task
  1. Click Menu → Reporting → Queries & Reports, then from Shared Groups in the Groups pane, select Drive Encryption. The standard DE query list appears.

  2. Run the DE: Users query to list all Drive Encryption users.

  3. Select at least one user from the list to enforce the policy.

  4. Click Actions → Drive Encryption → Configure UBP enforcement.

  5. Select Enable or Disable, then click OK to configure the UBP enforcement state.

    Note

    At each ASCI, ePO - On-prem makes sure that all relevant user-based policies are deployed to each client in addition to the user-based policy for the logged-on user configured with UBP enforcement.

    When Enable is selected, Policy Assignment Rules are enabled for the selected users, and a specific UBP is assigned to the user according to the rule defined. Policy Assignment Rules are enabled for the selected users only if a rule has been set for those users.