Use this page to enable and configure Trellix FRP authentication.
Password
Option | Definition |
|---|---|
Content Requirements (applicable to both Windows and Mac systems) | Defines the password policy rules for Trellix FRP Password Authentication, self-extractors, user local keys, CD/DVD/ISO, and removable media in the Trellix FRP client. If the password does not conform to a policy, an error message is displayed in the Trellix FRP client detailing the reason and prompting the user to try again.
|
Content Restrictions (applicable to Trellix FRP Password Authentication only) | Defines the password content restrictions that apply to Trellix FRP Password Authentication only.
|
Client Display Options (applicable to Trellix FRP Password Authentication only) |
|
Change Requirements (applicable to Trellix FRP Password Authentication only) |
|
Incorrect Password Behavior (applicable to Trellix FRP Password Authentication only) |
|
Smart card PKI
Option | Definition |
|---|---|
Initialization Method | Client-side Initialization
|
PIN Options |
|
Lock Triggers |
|
Virtual Smart card Token
Option | Definition |
|---|---|
Initialization Method | Require authentication using Active Directory credentials at first logon — Select this option to require users to authenticate using Active Directory domain credentials at first logon on a client system for access to encryption keys assigned to virtual smart card authentication. This option is disabled by default. NoteUsers will always be required to authenticate using Active Directory credentials with Trellix Endpoint Assistant. |
OS Token
Option | Definition |
|---|---|
Initialization Method | Require authentication using Active Directory credentials at first logon — Select this option to require users to authenticate using Active Directory domain credentials or Entra ID credentials at first logon on a client system for access to encryption keys assigned to OS Authentication. This option is disabled by default. NoteUsers will always be required to authenticate using Active Directory credentials with Trellix Endpoint Assistant. |
Trellix Endpoint Assistant
Option | Definition |
|---|---|
Passcode Definition | Select one of the following options to set a PIN or password to authenticate to the Trellix Endpoint Assistant app:
|
Client-to-Server Sync | Sync interval __ min (5-2880) — Enter the time in minutes to allow the Trellix Endpoint Assistant app on the client's mobile device to synchronize with the ePO - On-prem server periodically. Require periodic authentication using domain (AD) credentials — Enable this option to mandate periodic authentication on the Trellix Endpoint Assistant app using the Active Directory domain credentials. Every __ days (1-365) — Enter the number of days. NoteThis option is enabled only if the Require periodic authentication using domain (AD) credentials option is enabled. |
Connection Timeout | After seconds __ (5-300) — Enter the time in seconds to configure timeout before the Trellix Endpoint Assistant application stops waiting for response from ePO - On-prem. It is recommended to tune this value based on network latency in your specific environment. |
Encryption Key Options
Option | Definition |
|---|---|
Unlock Triggers | Specifies the conditions at which users are prompted to authenticate (if required) and encryption keys are loaded.
|
Lock Triggers | Specifies the conditions that trigger the unloading of encrypted keys.
|
Client-to-Server Sync | Sync interval __ min (5-2880) — Enter the time in minutes after which the client system synchronizes with the ePO - On-prem server periodically. Default value is 120 minutes. |
Key Cache (this option is applicable only to keys that are assigned to systems and not users) | Enable Key Cache expiry — Enables the automatic removal of keys from the key cache if the client system fails to connect to the ePO - On-prem server within the Key Cache expiry period. NoteStatus XML does not contain key information if the keys have been unloaded due to key cache expiry. Key Cache expiry period — Specifies the number of days after which all keys are removed from the key cache. This is applicable when Enable Key Cache expiry is selected and the client system has not connected to the ePO - On-prem server. Default value is 90 days. |
Custom Messages
Option | Definition |
|---|---|
OS/Virtual smart card Token Initialization Prompt (Windows) | The text displayed to prompt users to authenticate using the Active Directory domain credentials or Virtual smart card token or the Entra ID credentials to provide the OS token on a particular system. |
OS Token Initialization Prompt (Trellix Endpoint Assistant app) | The text displayed to prompt users to authenticate using the Active Directory domain credentials to allow provisioning of the Trellix Endpoint Assistant application. |
Authentication Prompt (Windows) | The text displayed to prompt users to authenticate to Trellix FRP. |
Authentication Failure (Windows) | The text displayed to users when authentication to Trellix FRP password token fails. |
Recovery Messages (Windows) | Password recovery — The text displayed to users when Trellix FRP password token recovery is initiated. Smart card recovery — The text displayed to users when Trellix FRP smart card recovery is initiated. |
Additional options
Option | Definition |
|---|---|
Duplicate | Duplicates or copies the policy with a different name that can be assigned to a different user or system. |
Save | Saves the product settings policy of Trellix FRP. |
Cancel | Closes the policy page without saving the changes. |