The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Create the user configuration file

Prev Next

You must have at least one user account within the offline activation package to activate Drive Encryption offline on a client system that is not connected to ePO - On-prem. You must add these users to a user configuration file, then use that file when creating the offline package.

  • Make sure that you have the list of user names to be added to the user configuration file.

  • Make sure that you have the required token details.

When using the Offline Activation process, the offline user can be set up as a password user or token user. For a token user, only SI tokens are supported, as standard PKI tokens need to sync back with ePO - On-prem to be authenticated.

  1. Open a text file and add the Drive Encryption users that you need to add to the client system. Name the file, as appropriate (for example: UserList.txt).

  2. Save the text file to a temporary location on the target system. The format of each user being added is name: token, where:

    • Name— The Drive Encryption user name that you need to add to the client system and that will be used for Drive Encryption logon. Make sure that you add a colon (:) after the user name.

    • Token— The token type you need to assign to that user.

    Note

    In the user configuration file, you can have any number of blank spaces between names and tokens.

    Five token types are supported:

    • Password

    • Four Self-Initiating (SI) token types (Gemalto, ActivID, PIV, and CAC)

    Note

    The token type is case-sensitive.

    Examples to update names and token types in a .txt file:

    • imaging_user1:Password

    • imaging_user2:Password

    • imaging_user3:Password

    • imaging_user_gemalto:Gemalto

    • imaging_user_activid:ActivID

    • imaging_user_piv:PIV

    • imaging_user_cac:CAC

    Remember:

    • If your SI token is configured using the Gemalto .NET PKI Smart Card token type, use the Gemalto tag.

    • If your SI token is configured using the ActivIdentity/CAC PKI Smart Card token type, use the ActivID tag.

    • If your SI token is configured using the PIV PKI Smart Card token type, use the PIV tag.

    • If your SI token is configured using the Common Access Card PKI Smart Card " token type, use the CAC tag.