The Drive Encryption client software is deployed from the ePO - On-prem server and installed on the client system through the Trellix Agent.
The client system requires a restart to complete the installation. After the restart, the client communicates with the ePO - On-prem server, pulls down the assigned Drive Encryption policies and the assigned users, and activates the system according to the defined policies. Drive Encryption creates the Pre-Boot File System (PBFS) on the client system at the time of activation, then proceeds to encrypt the disks according to specified policies. The assigned users can be initialized through the Pre-Boot screen after the restart.
The installation and deployment process is the same for both Drive Encryption software and Opal encrypted drives. The overall Drive Encryption installation and deployment process is made up of the following stages.
Note
This assumes that the user has already installed ePO - On-prem and has the Trellix Agent installed on various clients, which successfully communicate with the ePO - On-prem server.
Install the
EEAdmin.zip,EEPC.zip,help_de_740.zip,EEGO.zip, andUserDirectory.zipextensions into ePO - On-prem.Check in the Drive Encryption software packages (
MfeEEPC.zipandMfeEEAgent.zip) to the ePO - On-prem server.Configure the registered server (Microsoft Active Directory).
Note
You can also create and manage users using User Directory to remove the dependency on the LDAP server.
Deploy the Drive Encryption software packages to the client systems.
Note
System restarts automatically when the DEAgent and Drive Encryption packages are successfully deployed.
(Optional) Make sure the Trellix Drive Encryption system status window appears on the client system, and the System State is Inactive.
(Optional , if you don't use ALDU) Add users to the system or a group of systems in the Encryption Users page on ePO - On-prem.
Create a custom product settings policy or edit the default policy, then assign it to the system or a group of systems by using the standard ePO - On-prem policy assignment capabilities.
Create a custom user-based policy or edit the default policy, then assign it to a user or a group of users on a system. Configure UBP enforcement if you are using Policy Assignment Rules.
Note
The Show Drive Encryption Status changes from Inactive to Active only after adding at least one user and enforcing the policies correctly.
(Optional) Make sure Trellix Drive Encryption System Status is Active on the client system.