The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Generate the offline activation package

Prev Next

Using EpeOaGenXML.exe and the user configuration file, you can create the offline activation package with default policy settings that you export from the ePO - On-prem server.

  • Make sure that you have copied the required input files (EpeOaGenXML.exe, Userlist.txt) to the ePO - On-prem system.

  • You must have administrator rights to perform this task.

From Drive Encryption 7.2.10, offline activation now uses PC software encryption as first choice. For more details, see KB92634.

  1. Open the command prompt, then navigate to the folder that contains the EpeOaGenXML.exe and Userlist.txt files.

  2. Type EpeOaGenXML.exe --help to display the list of policy configuration options available with Drive Encryption 7.4.x.

  3. Generate the offline activation package using the command:

    EpeOaGenXML.exe --option arg

    where:--option arg specifies the required setting for any of the policy configurations. For example, --PbfsSize 60 --BackupMachineKey false --Sso true

    Note

    If you don't specify any input for arg on the command line, the default policy configuration is used to generate the offline activation package. However, you can also modify the default policy configuration options by specifying the required settings on the command line.

  4. To generate the offline activation package using the default policy settings and the Userlist.txt file, run the command:

    EpeOaGenXML.exe --user-file UserList.txt.

    Note

    If the user configuration file is in a different location than EpeOaGenXML.exe, specify its full path. If there are blank spaces in the path, make sure that you type the path within the double quotes. For example, EpeOaGenXML.exe --user-file "c:\documents and settings\user\my documents\UserList.txt".

  5. To generate the offline activation package with non-default policy settings and the Userlist.txt file, run the command: .

    EpeOaGenXML.exe --user-file UserList.txt --PbfsSize 60 --BackupMachineKey false --Sso true --SkipUnused true --Disable PF true

    Note

    If you enabled the SkipUnused option, enter Yes in response to the message: By using this feature you accept the risk associated with not encrypting unused sectors with respect to (deleted) sensitive data leakage.

    If the package is generated successfully, no feedback or error message appears. The offline activation package (ESOfflineActivateCmd.XML and OfflineActivation.exe) is created in the folder where the EpeOaGenXML.exe file is located.

    • ESOfflineActivateCmd.XML— Lists all users you added, the policy settings, and all policy configuration options. If you modified any of the policy configuration options while running the EpeOaGenXML.exe file, that change also appears in the XML file.

    • OfflineActivation.exe — This is the actual offline activation package to be used to activate Drive Encryption on the client system that is not connected to a network or ePO - On-prem.