The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Different phases of Trellix FRP extension upgrade

Prev Next

To verify whether the Trellix FRP upgrade is completed successfully, you can compare the features before and after running the upgrade task.

Feature

Before running the Trellix FRP Upgrade Task

After running the Trellix FRP Upgrade Task

Key assignment

Grant Keys policies are still the mechanism to assign keys to system/users through the System Tree or policy assignment rules.

Once the Trellix FRP upgrade task has been run, you can now assign keys to systems and users directly from the FRP Keys page. It is recommended to move away from Grant Key policies key assignment mechanism. You can, over a period, make assignments that are same as the Grant Key assignments using the new assignment workflows. Trellix FRP cleans up and delete any unused Grant Key policy objects that either have no keys or no assignments automatically. Once all Grant Key policy objects are deleted by this task, you no longer see this policy type in ePO - On-prem. Existing Grant Key policies work as they do before the upgrade, but no new keys can be added to these policies.

User Personal Keys

No change in functionality to older Trellix FRP versions

User Personal Keys (UPKs) can only be assigned to user/user groups or organizational units. UPKs previously assigned and created for users that were part of the domain are automatically upgraded into the corresponding user’s operating system token. For this to happen, the AD server must be registered with ePO - On-prem and be available at the time of running the upgrade task. UPKs that were not upgraded to users operating system token now show up as “Deprecated User Keys”. This happens if the AD server was not reachable at the time of running the task or if the UPK was not created for a domain user, for example WORKGRP1\User1. If the UPK was not upgraded because of AD connectivity issues, you can run the Trellix FRP Upgrade Task again and it processes all deprecated user keys.

Assignment methods

No change in functionality to older Trellix FRP versions

You can now assign keys to systems directly from the FRP Keys page. With Trellix FRP you can enable assignment of keys to users directly from the FRP Keys page. You can also assign UPKs to users directly from the FRP Keys page.

Policies

The removable media policy has now been enhanced for an improved end-user authentication experience. You can set up removable media policies with a key as an authentication mechanism in addition to the existing password/certificate authentication methods. Trellix FRP supports recovering removable media devices through administrator helped recovery. This feature is enabled by default. This also means that older clients managed with Trellix FRP continue to function as they do now, but no policy updates are possible.

The key cache expiry option has now been moved to the Encryption Options tab in the Authentication policy. Older clients retain their existing settings until upgraded to Trellix FRP 5.0.8.

This behavior does not change after running the Trellix FRP Upgrade Task.

New Grant key policy objects can no longer be created. Existing Grant key policies can be assigned / reassigned using System Tree or policy assignment rules as before. Grant keys policies can also now be edited only to remove keys; you can no longer add keys to it. To assign new keys to old clients, you can do it directly from the FRP Keys page.