When the DEAgent and Drive Encryption packages are successfully deployed, the system gets restarted.
Note
The restart is essential for activation of Drive Encryption on the client to proceed. The restart can be canceled, however, Drive Encryption will not become active on the client until the restart has occurred. In addition, hibernation and the use of new USB devices will be impaired until a restart is issued.
Drive Encryption Status
System restarts as initiated. You don't yet see the PBA page as the Drive Encryption software is not yet active on the client system. However, you should now be able to see the new option.
Note
(Optional) Navigate to Quick Settings | Show Drive Encryption Status using the Trellix system tray icon on the client system and you can see Trellix Drive Encryption System Status.
DEAgent synchronization with the ePO - On-prem server
The status in the Show Drive Encryption Status window is Inactive until DEAgent synchronizes with the ePO - On-prem server and gets all the users assigned to it. This is referred to as an ASCI event.
It can be manually triggered on the client by opening the Trellix Agent Status Monitor, then clicking Collect and Send Props. It can also be triggered from the ePO - On-prem server by an agent wake-up call, otherwise, you need to wait for the scheduled agent-server communication interval to occur (the default is 60 minutes). After two agent-server communication intervals, Drive Encryption activation begins. The activation process requires a number of ePO - On-prem events to be sent, and this can take some minutes to occur. Once the client-server communication has completed, the Drive Encryption Status switches to Active and encryption starts based on the policy defined.
Note
When Drive Encryption activation is complete, it should be restarted once before hibernation takes place. For this reason, we recommend that hibernation be disabled from the Control Panel on Window clients.
User intervention during encryption
The user can continue to work on the client system as normal even during encryption. Once the entire disk is encrypted, the technology is completely transparent to the end user.
Note
It is safe and risk-free to restart the client system during encryption.
Managing Pre-Boot Authentication (PBA)
When the client system is restarted and Drive Encryption is first activated, the user should log on with the username that matches the user attribute set in the LdapSync: Sync across users from LDAP task and the default password of 1234567 (this is the Trellix default password which can be changed in the User Based Policy) in the PBA page. The user is then prompted to change this password and enroll for self-recovery based on the policy set.
If you want the system to automatically capture the user's credentials without making them use a default password on PBA, enable the Do not prompt for default password option under User Based Policies | Password.
Note
We recommend that you change the default password and enforce policies with stronger passwords.
Single authentication using Single-Sign-On (SSO)
The Drive Encryption client system then boots to Windows. This first boot establishes SSO (if it has been enabled). On future restarts, the user needs to log in to PBA only. Once authenticated, SSO automatically logs on to Windows.
In short, the SSO option facilitates the user with the single authentication to the Operating System even when PBA is enabled. Though it requires an extra step, disabling SSO is the more secure configuration.
Note
When the Must match username option is enabled, both the Drive Encryption user name and the Windows user name should match for SSO to work, regardless of which domain the user is part of. This user can even be a local user.
When the Synchronize Drive Encryption password with Windows option is enabled, the Drive Encryption password is reset to the Windows password. However, be aware that if the Password history option is enabled or Password content rules are set, and the Drive Encryption password is same as the Windows password, then synchronization does not occur.
Note
On changing the Drive Encryption password, the synchronization is reset. Synchronization of the password occurs only when there is a change in the Windows password.