The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Password synchronization with autoboot enabled

Prev Next

Drive Encryption previously required a user to authenticate through Preboot before password synchronization could be performed. This caused two major pain points.

  • After a period of autoboot use, it was difficult to re-enable Preboot because user credentials were no longer in sync.

  • When using TPM autoboot, users do not routinely use Preboot. When a TPM measurement changes and Preboot shows, users were unable to log in with their Windows password.

From version Trellix Drive Encryption 7.4.2 onward, password synchronization can now be performed even when autoboot is enabled. This is configurable via policy. When a password is synchronized to a user who has not logged in through Preboot, the user is re-initialized (Q&A self-recovery, SSO, and password history are all reset), and the password is updated to match their Windows password.

Task
  1. Click Menu → Systems → System Tree, then select a group from the System Tree.

  2. Select the target system, then click Actions → Agent → Modify Policies on a Single System to open the Policy Assignment page.

  3. From the Product drop-down list, select Drive Encryption 7.x. The policy categories under Drive Encryption display the system's assigned policy.

  4. Select the Product Settings policy category, then click Edit Assignments to open the Product Settings page.

  5. If the policy is inherited, select Break inheritance and assign the policy and settings below next to Inherit from.

  6. From the Assigned Policy drop-down list, select the policy, then click Edit Policy to open the Policy Settings page.

    From this page, you can edit the selected policy or create a new policy.

  7. On the Log On tab, enable Password synchronization, then select Synchronize password for matching usernames, when autoboot is enabled .

  8. Click Save on the Policy Settings page.

  9. Send an agent wake-up call.