The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Create client deployment task

Prev Next

We recommend that you create a new system group in ePolicy Orchestrator for Drive Encryption deployment. Name it Drive Encryption Test Systems or Drive Encryption Production Systems, respectively, for example.

Do not create the deployment task at the My Organization level of the System Tree. Select a group in the System Tree, go to the Client Tasks tab and create the deployment task.

Importing systems from Active Directory to ePolicy Orchestrator

ePO - On-prem provides an AD Synchronization/NT domain task to synchronize ePolicy Orchestrator with the configured Active Directory. This option allows you to map the ePolicy Orchestrator System Tree structure with a registered Active Directory. Using this option, you can import and effectively manage large numbers of systems in ePolicy Orchestrator.

Note

This option works only with Active Directory.

For detailed procedures on how to import systems from Active Directory to ePolicy Orchestrator, refer to the product documentation for your version of ePO - On-prem.

Order of the Drive Encryption Agent and Drive Encryption deployment

It is not mandatory to have two different tasks for the product deployment, however the deployment order is critical. The DEAgent package must be deployed before the Drive Encryption package.

We recommend that you create a single task to deploy both packages, provided that it deploys the DEAgent package first, then the Drive Encryption package.

Note

If you configure the task to deploy the Drive Encryption package followed by the DEAgent package, the client system restarts in the middle as required, and the DEAgent is never deployed.

You can also create two separate tasks to deploy the packages, providing you wait for the first deployment (DEAgent) to complete before deploying the second package. You can also verify the completion of the DEAgent deployment, before deploying the Drive Encryption package, by creating and executing a customized query from the ePO - On-prem server. If the Drive Encryptionpackage is deployed first, you can run the DEAgent task and deploy it later. For more about custom queries, see Create Drive Encryption custom queries in the Drive Encryption Product Guide.

End user experience. Drive EncryptionDrive EncryptionDrive EncryptionDrive Encryption