The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Disable the Drive Encryption client

Prev Next

Modify the Drive Encryption product setting policy on the ePO - On-prem console to deactivate the Drive Encryption client.

Before you begin

You must have administrator rights to perform this task.



Task
  1. Log on to ePO - On-prem as an administrator.

  2. Click Menu → Systems → System Tree → Systems, then select a group from the System Tree.

  3. Select a system, then click Actions → Agent → Modify Policies on a Single System.

  4. From the Product drop-down list, select Drive Encryption <version>. The policy categories under Drive Encryption are listed with the system’s assigned policy.

  5. Select the Product Setting policy category, then click Edit Assignments.

  6. If the policy is inherited, select Break inheritance and assign the policy and settings below next to Inherit from.

    Select whether to lock policy inheritance. Any systems that inherit this policy can't have another one assigned in its place.

  7. From the Assigned policy drop-down list, select a product setting policy. And, click Edit Policy.

  8. On the General tab, deselect Enable policy.

    Note

    On Opal systems, make sure that you select the correct encryption provider and set the priority, as appropriate, so that the policy enforcement occurs correctly.

  9. Click Save on the Policy Settings page, then click Save on the Product Settings page.

  10. Send an agent wake-up call.

    Note

    On disabling the product setting policy, all the encrypted drives are decrypted, and the Drive Encryption status becomes Inactive. This can take a few hours depending on the number and size of the encrypted drives. However, client systems with Opal drives become Inactive quickly.