The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Offline activation recommendations

Prev Next

To activate Drive Encryption on a system that has no network connectivity or no connection to ePO - On-prem, you can create an offline activation package on the ePO - On-prem server and later distribute it to the required client system. This package contains the initial set of policies and a list of offline users.

Once the Drive Encryption software is installed successfully using the MSI package, you must run the offline activation tool to apply and enforce your selected policies and to add user accounts. When the system is active, encryption commences. If autoboot is not enabled, you might be required to authenticate on the Pre-Boot Authentication page using the offline user account specified as part of the offline install.

Note

These offline users are not part of the Active Directory.

During the activation process, the disk encryption key is written to a user-specified location in an encrypted form. This key is useful in recovery scenarios where the disk encryption key is manually sent to the ePO - On-prem server for decryption.

What happens when an offline activated system connects to ePO - On-prem?

Assuming that the offline activation was performed for provisioning purposes, the system connects to ePO - On-prem. Upon successful communication with ePO - On-prem, the client moves into an online mode. Online mode is a normal connection between the Trellix Agent and ePO - On-prem. It discards the offline policy that was enforced at activation. In its place, it receives the real policy from ePO - On-prem and the list of assigned users as in a normal activation, and saves its encryption key in ePO - On-prem. You could view it as a second, but automatic, activation.