The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Pre-Boot Smart Check

Prev Next

The Pre-Boot Smart Check performs various tests to ensure that the Drive Encryption pre-boot environment can work successfully on a device.

It tests the areas that have been identified as causing incompatibility issues in the past.

The flow for this process is made up of these stages:

  • System receives the system policy with Pre-Boot Smart Check enabled.

  • System activates with default Pre-Boot configuration, but encryption does not commence.

  • System forces a restart to occur.

  • User must log on through Pre-Boot.

  • If Windows logon is successfully achieved, encryption commences.

  • If there is a compatibility issue on the platform, the system does not reach Windows.

    • The user must hard-boot the system.

    • Pre-Boot starts in a different Pre-Boot configuration.

    • User must log on through Pre-Boot.

      Note

      Repeat this until all Pre-Boot configurations are exhausted.

  • If no Pre-Boot configuration successfully boots Windows, Drive Encryption is removed from the system the next time Windows restarts.

  • If a device fails the Pre-Boot Smart Check, it does not activate Drive Encryption. You can view the audit log to get the latest information on the check's progress from the last time the device synchronized with ePO - On-prem.