The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Enable the Pre-Boot Smart Check feature

Prev Next

Enable this feature to perform the hardware compatibility check before Drive Encryption activation and encryption.

You must have administrator rights to perform this task.

When you enable this feature, it modifies the Drive Encryption activation sequence and creates a pre-activation stage. During this stage, a series of hardware compatibility checks are performed prior to actual activation and subsequent encryption to successfully activate Drive Encryption on platforms where BIOS issues might exist.

This feature is available only for BIOS systems using PC software encryption. It is not available for UEFI or Opal systems.

Note

The client system might need to be restarted several times before the Smart Check is complete. If the boot sequence appears to freeze, make sure to power cycle the system and try again. It might take up to 8 restarts before all configuration options have been exhausted and for Drive Encryption to be deactivated.

For details about product features, usage, and best practices, click ? or Help.

  1. Click Menu → Systems → System Tree, then select a group from the System Tree.

  2. Select at least one system, then click Actions → Agent → Modify Policies on a Single System. The Policy Assignment page for that system appears.

  3. From the Product drop-down list, select Drive Encryption 7.x. The policy categories under Drive Encryption are listed with the system’s assigned policy.

  4. Select the Product Settings policy category, then click Edit Assignments to open the Product Settings page.

  5. If the policy is inherited, select Break inheritance and assign the policy and settings below next to Inherit from.

  6. Select the policy from the Assigned policy drop-down list, then click Edit Policy to open the Policy Settings page.

    From this location, you can edit the selected policy or create a new policy.

  7. In the Encryption Providers tab, select Enable Pre-Boot Smart Check to update this policy on the client systems.

    Note

    This feature is applicable only for BIOS-based systems using PC software encryption.

    After you select this option, the Force system restart once activation completes option is selected automatically.

  8. Click Save.

    After the policy is applied to the client systems, Drive Encryption activation starts and completes after a period of time. Drive Encryption is not in Active state now. The user is notified that the system is about to restart. A few moments later, the system restarts automatically.

  9. After the client system restarts, authenticate to the PBA.

    If the system is successfully booted into Windows, the Drive Encryption status switches to Active and Drive Encryption is activated successfully.

If the system is not able to boot into Windows (or the PBA cannot run) due to hardware compatibility issues, the user must manually power off the system and try again. Several restarts are required before smart-check fails and boots into Windows. On each retry, the PBA configures a different set of compatibility configurations to work around any issues on the client system to boot into Windows. After all configurations are attempted, the client system bypasses the PBA and boots directly into Windows. The client system then deactivates and records the failure by sending an audit message to ePO - On-prem. The PBA is removed and Drive Encryption activation fails.