The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Enable accessibility in the preboot environment

Prev Next

The USB audio functionality enables visually challenged users to listen to a voice (spoken words) for Legacy BIOS and an audio beep for UEFI systems. This serves as guidance when the user moves the focus from one field to the next using the mouse or keyboard in the preboot environment.

Accessibility allows any external USB audio device to be used and to play back pre-recorded audio files. These vocal prompts can indicate which control or option has the focus (that is, Username, Password, OK) and specific error conditions.

Note

This functionality provides audio guidance in English only for Legacy BIOS.

When you install or update the product, the vocal prompts are installed on the client system only. Only when the policy setting is enabled, the audio files are transferred to the PBFS. This saves space in the PBFS system, which does not need this functionality.

Note

Drive Encryption adds 508 compliance system beeps to UEFI. For details, see KB69853.

Task
  1. Click Menu → Systems → System Tree, then select a group from the System Tree.

  2. Select a system, then click Actions → Agent → Modify Policies on a Single System to open the Policy Assignment page for that system.

  3. From the Product drop-down list, select Drive Encryption 7.x. The policy categories under Drive Encryption display the system's assigned policy.

  4. Select the Product Settings policy category, then click Edit Assignments to open the Product Settings page.

  5. If the policy is inherited, select Break inheritance and assign the policy and settings below next to Inherit from.

  6. From the Assigned Policy drop-down list, select the policy, then click Edit Policy to open the Policy Settings page.

    From this page, you can edit the selected policy, or create a new policy.

  7. On the Boot Options tab, select Always enable pre-boot USB support to enable USB on the client system. Make sure that you also enable the Enable Accessibility option under Log On | Drive Encryption.

  8. Click Save on the Policy Settings page, then click Save on the Product Settings page.

  9. Send an agent wake-up call.

When the user tries to authenticate on the client system after enforcing this policy, the user can listen to the audio guidance in the preboot environment.