The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Drive Encryption system recovery

Prev Next

The purpose of encrypting the client's data is to control access to the data by controlling access to the encryption keys. It is important that keys are not accessible to users.

The key that encrypts the hard disk sectors needs to be protected. These keys are referred to as Machine Keys. Each system has its own unique Machine Key. The Machine Key is stored in the ePO - On-prem database to be used for client recovery, when required. There are four different system recovery options available in Drive Encryption that can be reached through: Menu → Systems → System Tree → System → Actions → Drive Encryption.

Drive Encryption system recovery

Option

Definition

Decrypt offline recovery file

The encrypted machine key is stored in a recovery information file (xml) on the client system. To enable the recovery procedures on the client systems, the user can use ePO - On-prem to decrypt the offline recovery file that is retrieved from the client system.

Destroy all recovery information

When you want to secure-erase the drives in your Drive Encryption installed system, remove all users from the system (including those inherited from parent branches in the System Tree). This makes the disks inaccessible through normal authentication as there are no longer any users assigned to the system. You need to then destroy the recovery information for the system using the option Menu → Systems → System Tree → Systems → Actions → Drive Encryption → Destroy All Recovery Information in the ePO - On-prem console. This means that the system can never be recovered.

Key Re-use

This option is used to activate the system with the existing key present in the ePO - On-prem server. This option is highly useful when a boot disk gets corrupted and the user cannot access the system. Other disks on the system can be recovered by activating it with the same key from ePO - On-prem.

Export recovery information

This option is used to export the recovery information file (.xml) for the desired client system from ePO - On-prem. Every client system that is encrypted using Drive Encryption has a recovery information file in ePO - On-prem. Any user trying to enable the recovery procedures on the client systems should get the file from the ePO - On-prem administrator for Drive Encryption. For more information, see the DETech User Guide.

Note

The recovery information file has a general format of client system name.xml.

Export recovery information based on Disk Keycheck

This option is used to export the recovery information file (.xml) for a disk of a client system from ePO - On-prem. Every disk of a client system has a disk keycheck value. For instance, if a client system has a disk called 'Disk1', you can recover that client system (when on unrecoverable state) using the keycheck value of 'Disk1'. However, if a new disk 'Disk2' is installed and activated in that same client system, you must use the keycheck value of 'Disk2' and the keycheck value of 'Disk1' loses priority.

To perform this task, you need to access the client system using DETech and obtain the disk keycheck value using the Disk Information option from the DETech user interface.

  • In ePO - On-prem, click Actions → Drive Encryption → Export recovery information based on Disk Keycheck and enter the obtained disk keycheck value in the Key Check field.

  • The recovery information file (.xml) appears, export it to the inserted removable media.

  • Use this file to authenticate to the client system using DETech. For more information, see DETech User Guide.



You cannot log on to the client system before a proper agent-server communication occurs. In this situation, use the DETech tool to obtain the Key Check value from the client and obtain the recovery key for this machine from the ePO - On-prem console to perform an Emergency Boot.