The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Installation prerequisites

Prev Next

Before installing Drive Encryption, verify that the following relevant prerequisites are satisfied.

Prerequisite checklist

List

Check

Make sure that the Secure Boot database is updated with the Microsoft UEFI CA 2023 and Microsoft Option ROM UEFI CA 2023 on all Windows 10 and later systems.

This update is required for Drive Encryption 8.1.1 installation. For more information, see article 000015304.

[ ]

Make sure the target client systems meets the system requirements as detailed in KB79422.

[ ]

Make sure the latest version of hardware compatibility XML file attached to KB81900 to make sure you have the latest version.

[ ]

Deploy Trellix Agent for Windows on the client system.

[ ]

Install the EEADMIN.ZIP and EEPC.ZIP extensions into the ePO - On-prem server.

Note

The EEADMIN.ZIP extension is a prerequisite for the EEPC.ZIP extension.

[ ]

Check in the DriveEncryption.zip software package into the ePO - On-prem server.

[ ]

Register an Active Directory server on the ePO - On-prem server.

[ ]

Create client tasks and deploy the Drive Encryption Agent for Windows and Drive Encryption for PC package sequentially to the client system, then restart the client only when prompted.

[ ]

Note

After rebooting, check that the status is Inactive by navigating to Trellix system tray icon, select Quick Settings | Show Drive Encryption Status and you can see Trellix Drive Encryption System Status.

Add users to the client system from the ePO - On-prem server and send an Agent wake-up call.

[ ]

Create product setting policy or edit the default policy and assign it to a system or a group of systems. While modifying the default policy or creating the new policy, make sure to select any one of the disk encryption options other than None, by navigating to Encryption → Encrypt. The default option None does not initiate encryption.

[ ]

Send an Agent wake-up call. It is a good practice to select the Force complete policy and task update option while sending this Agent wake-up call. You will now find that the encryption is initiated on the client system.

[ ]

After complete installation of the Drive Encryption, check that the status is Active by navigating to Trellix system tray icon, select Quick Settings | Show Drive Encryption Status and you can see Trellix Drive Encryption System Status on the client system.

[ ]