Use this file to discover all available pages before exploring further.
The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.
Use this page to enable and configure Trellix FRP authentication.
Password
Option
Definition
Content Requirements (applicable to both Windows and Mac systems)
Defines the password policy rules for Trellix FRP Password Authentication, self-extractors, user local keys, CD/DVD/ISO, and removable media in the Trellix FRP client. If the password does not conform to a policy, an error message is displayed in the Trellix FRP client detailing the reason and prompting the user to try again.
Minimum Password Length — Specifies the minimum number of characters (7–40) that must be included in a password. Default value is 7.
Minimum Special Characters — Specifies the minimum number of special characters (0–15) that must be included in a password. Default value is 0.
Minimum Numeric Characters — Specifies the minimum number of numeric digits (0–15) that must be included in a password. Default value is 0.
Minimum Alphabetical Characters — Specifies the minimum number of letters (0–15) that must be included in a password. Default value is 0.
Minimum lowercase characters — Specifies the minimum number of lowercase letters (0–15) that must be included in a password. Default value is 0.
Minimum uppercase characters — Specifies the minimum number of uppercase letters (0–15) that must be included in a password. Default value is 0.
Content Restrictions (applicable to Trellix FRP Password Authentication only)
Defines the password content restrictions that apply to Trellix FRP Password Authentication only.
No anagrams — The password must not contain a word or phrase formed by rearranging the letters of another word or phrase.
No palindromes — The password must not comprise a string that reads the same backward and forward.
No user name— The password must not contain the user name.
No simple sequences — The password must not contain simple sequences (for example, 1234 or abcd) or a sequence based on the previous password.
Client Display Options (applicable to Trellix FRP Password Authentication only)
Allow user to see typed password — Enables the user to view the password as it is being typed. This option is disabled by default.
Display list of password rules to user — Enables the user to view the password content requirements from the client. This option is enabled by default.
Change Requirements (applicable to Trellix FRP Password Authentication only)
Prevent change — Prevents the user from changing the password.
Require change after __ days (1-366) — Requires that the user change the password at predefined intervals.
Warn user before change required - days __ (1-30) — Notifies the user to change the password before it expires.
Enable password history - changes __ (1-10) — Prevents the user from reusing the last X number of passwords in the password history.
Incorrect Password Behavior (applicable to Trellix FRP Password Authentication only)
Invalidate password after __ invalid attempts (1-100) — The number of failed logon attempts before the user password is invalidated and a recovery operation is required.
Initiate exponential backoff timeout after __ invalid attempts (1-20) — The number of times a user can enter an incorrect password before a timeout is enforced.
Maximum timeout - minutes __ (1-64) — The maximum time that the user is unable to enter password credentials after exceeding the allowed number of invalid attempts.
Smart card PKI
Option
Definition
Initialization Method
Client-side Initialization
Use Windows user name if DN not available — Initializes the smart card with the Windows user name when a DN is not available. This option is enabled by default.
PIN Options
Allow PIN change — Allows the user to change the PIN.
Note
This option works only if the smart card allows a change PIN operation.
Allow user to see typed PIN — Allows the user to view the PIN in the user interface.
Lock Triggers
On smart card removal — Unloads encryption keys when the smart card is removed making encrypted files inaccessible.
Virtual Smart card Token
Option
Definition
Initialization Method
Require authentication using Active Directory credentials at first logon — Select this option to require users to authenticate using Active Directory domain credentials at first logon on a client system for access to encryption keys assigned to virtual smart card authentication. This option is disabled by default.
Note
Users will always be required to authenticate using Active Directory credentials with Trellix Endpoint Assistant.
OS Token
Option
Definition
Initialization Method
Require authentication using Active Directory credentials at first logon — Select this option to require users to authenticate using Active Directory domain credentials or Entra ID credentials at first logon on a client system for access to encryption keys assigned to OS Authentication. This option is disabled by default.
Note
Users will always be required to authenticate using Active Directory credentials with Trellix Endpoint Assistant.
Trellix Endpoint Assistant
Option
Definition
Passcode Definition
Select one of the following options to set a PIN or password to authenticate to the Trellix Endpoint Assistant app:
PIN, exactly 4 digits — Enforces a PIN with exactly 4 digits.
PIN, exactly 6 digits — Enforces a PIN with exactly 6 digits.
PIN, exactly 8 digits — Enforces a PIN with exactly 8 digits.
Password: Minimum 6 characters with 1 numeric, 1 alphabetical characters — Enforces a password with minimum 6 characters containing 1 numeric and 1 alphabetic characters.
Password: Minimum 6 characters with 1 numeric, 1 uppercase and 1 lowercase character — Enforces a password with minimum 6 characters containing 1 numeric, 1 uppercase, and 1 lowercase characters.
Password: Minimum 8 characters with 1 numeric, 1 uppercase, 1 lowercase and 1 symbol characters — Enforces a password with minimum 8 characters containing 1 numeric, 1 uppercase, 1 lowercase, and 1 symbol characters.
Client-to-Server Sync
Sync interval __ min (5-2880) — Enter the time in minutes to allow the Trellix Endpoint Assistant app on the client's mobile device to synchronize with the ePO - On-prem server periodically.
Require periodic authentication using domain (AD) credentials — Enable this option to mandate periodic authentication on the Trellix Endpoint Assistant app using the Active Directory domain credentials.
Every __ days (1-365) — Enter the number of days.
Note
This option is enabled only if the Require periodic authentication using domain (AD) credentials option is enabled.
Connection Timeout
After seconds __ (5-300) — Enter the time in seconds to configure timeout before the Trellix Endpoint Assistant application stops waiting for response from ePO - On-prem. It is recommended to tune this value based on network latency in your specific environment.
Encryption Key Options
Option
Definition
Unlock Triggers
Specifies the conditions at which users are prompted to authenticate (if required) and encryption keys are loaded.
Windows logon — If there are any keys associated with Password token, an authentication prompt is shown to users immediately after Windows logon.
If there are any keys associated with OS token, those get loaded (if available) immediately following a successful OS logon.
Enable smart card single sign-on — Enabling this option lets you log on to Trellix FRP and Windows using the single sign-on feature. When you log on to Windows, the system sends a notification that you are logged on to Trellix FRP as well.
Note
You can't override smart card single sign-on policy settings with user-based assignment rules.
Configure custom credential providers to wrap — By default, Trellix FRP works with the built-in Microsoft smart card credentials at Windows logon. If necessary, Trellix FRP can be configured to work with a different credential provider by entering the GUID of the credential provider in Configure custom credential providers to wrap.
Note
There are systems in which Trellix Drive Encryption or other third-party products are installed and configured to provide single sign-on facilities specific to those products. On such systems, enabling single sign-on for Trellix FRP might not work because the built-in Microsoft smart card credentials can't be used at logon. To have Trellix FRP smart card single sign-on work on these systems, you must identify the custom credential provider installed by the other software to Trellix FRP. Credential providers are identified by a GUID defined in the Windows registry. This allows the single sign-on facility provided by both the third-party software and Trellix FRP to work simultaneously.
Encryption key access — Prompts the user to authenticate when a user-initiated action requires access to an encryption key.
Trellix tray — Enables the user to manually log on/log off to Trellix FRP using the Trellix tray Quick Settings menu.
Lock Triggers
Specifies the conditions that trigger the unloading of encrypted keys.
Windows screen lock — Requires that the user reauthenticate if Windows is not used for the configured time period (0-720 minutes). Default value is 0.
Note
This option can either be disabled or enabled with a timeout. If disabled, the keys are always dropped when Windows is locked. Being disabled is same as being enabled with timeout as 0.
Key use inactivity — Requires that the user reauthenticate if encryption keys have not been used for the configured time period (5-720 minutes). Default value is 60.
Client-to-Server Sync
Sync interval __ min (5-2880) — Enter the time in minutes after which the client system synchronizes with the ePO - On-prem server periodically. Default value is 120 minutes.
Key Cache (this option is applicable only to keys that are assigned to systems and not users)
Enable Key Cache expiry — Enables the automatic removal of keys from the key cache if the client system fails to connect to the ePO - On-prem server within the Key Cache expiry period.
Note
Status XML does not contain key information if the keys have been unloaded due to key cache expiry.
Key Cache expiry period — Specifies the number of days after which all keys are removed from the key cache. This is applicable when Enable Key Cache expiry is selected and the client system has not connected to the ePO - On-prem server. Default value is 90 days.
The text displayed to prompt users to authenticate using the Active Directory domain credentials or Virtual smart card token or the Entra ID credentials to provide the OS token on a particular system.
OS Token Initialization Prompt (Trellix Endpoint Assistant app)
The text displayed to prompt users to authenticate using the Active Directory domain credentials to allow provisioning of the Trellix Endpoint Assistant application.
Authentication Prompt (Windows)
The text displayed to prompt users to authenticate to Trellix FRP.
Authentication Failure (Windows)
The text displayed to users when authentication to Trellix FRP password token fails.
Recovery Messages (Windows)
Password recovery — The text displayed to users when Trellix FRP password token recovery is initiated.
Smart card recovery — The text displayed to users when Trellix FRP smart card recovery is initiated.
Additional options
Option
Definition
Duplicate
Duplicates or copies the policy with a different name that can be assigned to a different user or system.
Save
Saves the product settings policy of Trellix FRP.
Cancel
Closes the policy page without saving the changes.