Drive Encryption previously required a user to authenticate through pre-boot before password synchronization could be performed. This caused two major pain points.
After a period of autoboot use, it was difficult to re-enable pre-boot because user credentials were no longer in sync.
When using TPM autoboot, users do not routinely use pre-boot. When a TPM measurement changes and pre-boot shows, users were unable to log in with their Windows password.
From version Trellix Drive Encryption 7.4.2 onward, password synchronization can now be performed even when autoboot is enabled. This is configurable through policy. When a password is synchronized to a user who has not logged in through pre-boot, the user is re-initialized (Q&A self-recovery, SSO, and password history are all reset), and the password is updated to match their Windows password.
Click → → , then select a group from the System Tree.
Select the target system, then click → → to open the Policy Assignment page.
From the Product drop-down list, select Drive Encryption 8.x. The policy categories under Drive Encryption display the system's assigned policy.
Select the Product Settings policy category, then click Edit Assignments to open the Product Settings page.
If the policy is inherited, select Break inheritance and assign the policy and settings below next to Inherit from.
From the Assigned Policy drop-down list, select the policy, then click Edit Policy to open the Policy Settings page.
From this page, you can edit the selected policy or create a new policy.
On the Log On tab, enable Password synchronization, then select Synchronize password for matching usernames, when autoboot is enabled .
Click Save on the Policy Settings page.
Send an agent wake-up call.