The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Generate a Challenge Response Code

Prev Next

If the user's password or logon tokens have been lost, you need to perform administrator recovery on the client computer to recover the user or system.

User calls the administrator to perform the administrator recovery, and provides the Challenge Code. The administrator initiates the ePO - On-prem Scripting API to generate the Challenge Response Code. A valid Response Code is supplied by the scripting API to the administrator. When typing the Response Code, access is granted to the Client system. Use the eeadmin.administratorRecovery command to generate the Challenge Response Code.

There are four different administrator recovery types:

  • machineRecovery='1'

  • resetUserToken='2'

  • unlockDisabledUser='3'

  • reserUserToPasswordToken='4'

machineRecovery recovery type

Command

Syntax

Description

eeadmin.administratorRecovery

eeadmin.administratorRecovery

challengeCode=<>

recoveryType=<>

Specify recoveryType='1', to perform Machine Recovery.



resetUserToken recovery type

Command

Syntax

Description

eeadmin.administratorRecovery

eeadmin.administratorRecovery

challengeCode=<>

recoveryType=<>

userDn=<>

Specify recoveryType='2' and pass the Distinguished Name (DN) of the user, to perform the Reset User Token Recovery.



unlockDisabledUser recovery type

Command

Syntax

Description

eeadmin.administratorRecovery

eeadmin.administratorRecovery

challengeCode=<>

recoveryType=<>

userDn=<>

Specify recoveryType='3' and pass the Distinguished Name (DN) of the user, to perform the Unlock Disabled User Recovery.



resetUserToPasswordToken recovery type

Command

Syntax

Description

eeadmin.administratorRecovery

eeadmin.administratorRecovery

challengeCode=<>

recoveryType=<>

userDn=<>

Specify recoveryType='4' and pass the Distinguished Name (DN) of the user, to perform the Reset User To Password Token Recovery.



unlockDisabledUser recovery type

Command

Syntax

Description

eeadmin.administratorRecovery

eeadmin.administratorRecovery

challengeCode=<>

recoveryType=<>

userDn=<>

Specify recoveryType='3' and pass the Distinguished Name (DN) of the user, to perform the Unlock Disabled User Recovery.



resetUserToPasswordToken recovery type

Command

Syntax

Description

eeadmin.administratorRecovery

eeadmin.administratorRecovery

challengeCode=<>

recoveryType=<>

userDn=<>

Specify recoveryType='4' and pass the Distinguished Name (DN) of the user, to perform the Reset User To Password Token Recovery.