The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Creating the offline activation package

Prev Next

The offline activation package is used for activating Drive Encryption on a client system that is not connected to the ePO - On-prem server.

These files are required to create the offline activation package:

  • EpeOaGenXML.exe

  • Key Server Public Key

  • User configuration file (Example: Userlist.txt)

You must extract and export the Key Server Public Key from the ePO - On-prem server, then manually create the user configuration file.

Important

  • When you activate a system with an offline activation, a recovery file is created by default in the root of the (C:) drive. For example, C:\EERecovery.xml.

  • After activation but before rebooting the client system, recovery file must be backed up to another secure location that isn't on the system's drives.

  • If a recovery situation arises, and the file resides only on an encrypted volume, the file is not available for use in recovery.

  • Once the system is managed by ePO, the recovery information will automatically be escrowed, enabling administrator recovery workflows (challenge/response, recovery key export).