The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Enforce Drive Encryption policies on a system

Prev Next

Enable or disable policy enforcement for Drive Encryption on a client system. Policy enforcement is enabled by default, and is inherited in the System Tree.

Before you begin

You must have administrator rights to perform this task.



Task
  1. Click Menu → Systems → System Tree → Systems tab, then from the System Tree, select the group where the system belongs. The systems within this group appear in the details pane.

  2. Select a system, then click Actions → Agent → Modify Policies on a Single System.

  3. Select Drive Encryption 8.x, then click Enforcing next to Enforcement status.

  4. Select Break inheritance and assign the policy and settings below to change the enforcement status.

  5. Next to Enforcement status, select Enforcing, then click Save.

After restarting, the client system communicates with the ePO - On-prem server and pulls down the assigned Drive Encryption policies and encrypts the system according to the defined policies. The assigned user can be initialized through the Pre-Boot screen after the subsequent restart.