The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Deploying the client package in FIPS mode

Prev Next

(Windows only) The Trellix FRP client needs to be deployed in FIPS mode to operate in a FIPS-certified manner.

Note

FIPS 140-3 defines minimum requirements for entropy during key generation. This might lead to key generation errors during Removable Media device initialization when using offline access support, CD/DVD/ISO creation, self-extractor creation, user local key creation, and when changing authentication methods for removable media where insufficient entropy (randomness) is available at the point of key generation. To avoid this, ensure that the product is running on a CPU that supports the RDRAND instruction to allow entropy generation.

Deploy Trellix FRP on the client in one of these ways:

  • Deployment task — Make sure to add the keyword FIPS on the task command line in ePO - On-prem. For installation steps, see Deploy the software to managed systems.

  • Third-party deployment software — Make sure to pass the parameter FIPS_MODE=1 when you install the Trellix FRP client package, according to the following command:

    • 32-bit system — msiexec.exe/q/i eeff32.msi FIPS_MODE=1

    • 64-bit system — msiexec.exe/q/i eeff64.msi FIPS_MODE=1