The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

FAQs for Drive Encryption 8.x

Prev Next

See below details for frequently asked questions on Drive Encryption.

For frequently asked questions on Drive Encryption compatibility, installation and upgrade, configuration, and functionality see KB79784.

How to troubleshoot when the registered LDAP server has either been removed or otherwise does not exist?

The following error occurs when trying to add Drive Encryption users through Encryption Users on a previously functioning Registered LDAP Server: The registered LDAP server has either been removed or otherwise does not exist. To troubleshoot this issue, see KB81169.

How to do a migration of managed encrypted systems from one ePO - On-prem server to another?

If you have an existing ePO - On-prem server that manages Drive Encryption encrypted systems, and wants to migrate those systems to a different ePO - On-prem server, see KB83186.

Drive Encryption 8.0.x Client Transfer Migration Guide— This document describes how to manage the transfer of systems protected with Drive Encryption from one ePO - On-prem server to another while preserving user assignments, user tokens, and other data. For details, see Trellix Drive Encryption 8.0.x Client Transfer Migration Guide.

How do I see my system encrypted with Trellix Drive Encryption?

On the client system, navigate to the Trellix system tray icon, Quick Settings | Show Drive Encryption Status to see encryption status.

How to use the Hardware Compatibility Settings tool for Drive Encryption?

The Hardware Compatibility Settings tool is only designed for Legacy BIOS systems and not UEFI systems. This tool allows the administrator to capture hardware compatibility settings. For details, see KB81900.

What are the supported USBs for Drive Encryption?

Drive Encryption 7.1.x and later versions add support for self-encrypting drives that support the Opal standard. Drive Encryption lists support for Opal drives based on makers or models of hardware and firmware versions as they are shipped from OEMs.

For information about supported operating systems, DE version, and Opal drives, see KB81136.

For frequently asked questions on the Opal Drives supported by Drive Encryption, see KB89333.

What is the Windows 10 upgrade path for Drive Encryption?

For details about the upgrade path for Drive Encryption, see the upgrade and migration section in KB79422.

How to upgrade Windows operating systems without having to decrypt the hard drive and uninstall Trellix Drive Encryption?

For upgrading Windows operating system with Drive Encryption installed on the client system, see KB79422 (upgrade and migration section) and KB79908.

How to resolve password synchronization issues between Windows and Drive Encryption pre-boot phase?

For troubleshooting issues with Single Sign On and/or Password Synchronization failures on systems that have third-party credential providers installed, see KB73040.

For troubleshooting issues with Single Sign-On fails even though Drive Encryption is properly configured, see KB75498.

How to resolve fatal error [0xEE0D0001] failed to read registry file?

For details about the fatal error, see KB89389.

How to use a PKI token in Drive Encryption?

For details about PKI token in Drive Encryption, see KB81274.

How to update expired user certificate?

Run the LDAP sync server task after the new certificate is available in the AD. In the subsequent policy enforcement (provided they have the latest certificate enabled in the UBP), the client receives the new certificate, and the corresponding user's TDE token information gets updated with the new certificate.