The Product Settings policy options are organized into these tabs: General, Encryption, Log On, Recovery, Boot Options, Theme, Out-of-Band, Encryption Providers, and Companion Devices.
General tab
Option | Definition |
|---|---|
Enable policy | Enables the set policies on the client computers.
NoteYou can enable this option only if the DEGO extension 7.x is installed in Trellix ePO - On-prem and 7.x DEGO client package is installed in the clients. However, the DEGO Extension/Client package will no longer be provided as part of the TDE 8.0.x release. |
Self Protection | Provides protection against modification of files, folders, and registries related to Trellix Drive Encryption. Disable Self-Protection (Not recommended): Removes existing protection that stops modification of files, folders, and registries pertaining to Trellix Drive Encryption. Uninstall Self-Protection: Allowed only after disabling Self-Protection. Removes/Uninstalls Self-Protection software from the client system, as viewed from Trellix Drive Encryption's perspective. |
Logging level | Allows the administrator to set a different logging level for each client computer that has the specific policy setting assigned. NoteTo overwrite the logging level defined in Trellix ePO - On-prem, the LoggingLevelOverride registry key needs to be set on the client system.
|
Expire users who do not login | Allows the administrator to control and manage the users who have not logged on to the client system. This option forces the user account, which is not initialized, to expire after a number of hours as set in the policy. |
Allow users to create endpoint info file | Allows the user to collect client system details such as the list of assigned users, policy settings, recovery, and Drive Encryption status. After enabling this option, the Save Machine info button appears in:
You can click this button and save the text file for later reference. |
Enable logging for Credential provider | Select this option to enable or disable credential provider logging. |
Encryption tab
Option | Definition |
|---|---|
Encrypt | Allows you to select the required encryption type and to set the encryption priority. |
Encryption type | The type of encryption:
The Encryption type options None, All disks except boot disk, and Selected partitions are not applicable to self-encrypting drives in Opal mode. |
Log On (Drive Encryption) tab
Option | Definition |
|---|---|
Enable automatic booting | When enabled, the client system boots automatically without prompting for a preboot authentication. The expiration date for auto-booting can also be set. If required, the user can select the UTC time standard option. ImportantIf you enable this option without requiring the use of TPM for automatic booting, the Drive Encryption product does not protect the data on the drive when it is not in use.
|
Allow temporary automatic booting | Allows you to turn (on or off) the PBA screen, with a client-side utility. This eliminates the need to modify the policy in Trellix ePO - On-prem, and allows for client-side automation during patching and other client management scenarios. |
Use of TPM for automatic booting | Select one of these options:
NoteThis option is applicable only for systems installed with Drive Encryption 7.3.0 or later. If you apply a policy to the earlier versions of Drive Encryption with automatic booting enabled and use of TPM set to 'Required', it will leave the client system in an unprotected state since autoboot will be enabled with no protection of the disk encryption key. TPM autoboot is designed to display the preboot logon screen, if the TPM measurements change. This can occur due to firmware or operating system updates. It is recommended to use temporary autoboot during the deployment of updates, even when TPM autoboot is enabled. For more information about TPM autoboot, see KB79784. |
prevent automatic booting when the disk moves system (UEFI only) | This prevents autoboot from functioning when a disk is moved between the systems. |
Pre-boot power management: Automatically shutdown pre-boot after a period of inactivity: 1-60 minutes | The client system will shut down automatically after the set time at pre-boot. |
Log on message | Type a message that appears to the client user. |
Do not display previous user name at log on | Prevents the client system from automatically displaying the user name of the last logged on user on all Drive Encryption logon dialog boxes. |
Enable on screen keyboard | Enables the pre-boot On-Screen Keyboard (OSK) and the associated Wacom serial pen driver. When this option is enabled, the pen driver finds supported pen hardware (Panasonic CF-H1 and Samsung Slate 7) and displays the OSK. NoteIf you do not select this option, the BIOS uses mouse emulation. In such a situation, the BIOS treats the digitizer as a standard mouse, which might lead to the cursor being out of sync with the stylus on USB-connected Wacom pen digitizers.
|
Add local domain users (and tag with 'TDE:ALDU') |
|
Enable accessibility | Select this option to sound a beep as a signal when the user moves the focus from one field to the next using mouse or keyboard in the preboot environment. This option is helpful to visually challenged users. The USB audio functionality allows visually impaired users to hear an audio signal (spoken word) as guidance when the user moves the cursor from one field to the next in the preboot environment. The USB speakers and headphones can be used to listen to the audio signal. For more details, see Enable Accessibility (USB audio devices) in the preboot environment. |
Disable pre-boot authentication when not synchronized | Blocks a user from logging on to PBA in the client system, if the client system is not synchronized with the Trellix ePO - On-prem server for the set number of days. The user is blocked from logging on to PBA, and can then request the administrator to perform Administrator Recovery to unlock the client system. This allows the client system to boot and communicate with the Trellix ePO - On-prem server. NoteThe client system continues to block the user from logging on to the system until synchronization with Trellix ePO - On-prem. |
Read username from smartcard | Automatically retrieves the available user information about the client system from the inserted smartcard; hence the Authentication window does not prompt for a user name. The user can then authenticate by typing the correct PIN. You need to enable the matching rules that are required for matching smartcard user principle name (UPN) names with Drive Encryption user names.
NoteThis feature is supported on the Gemalto .Net V2+ tokens, and PIV and CAC tokens. |
Lock workstation when inactive: After x number of minutes | The client system is locked automatically when it is inactive for the set time. |
Option | Definition |
|---|---|
V7.2 Onwards | Third-party credential providers:
|
Single sign-on (SSO):
| |
Password synchronization:
| |
Preboot user options
| |
Windows username matching
| |
Credential provider bitmap
| |
Require Drive Encryption logon (only supported on V6 clients) — This requires you to mandatorily log on to PBA for EEPC 6.x.x systems, thereby disabling the SSO functionality.
|
Recovery tab
Option | Definition |
|---|---|
Enabled | The Recovery option is enabled by default. This activates the Administrator Recovery option in the client system. |
Administrator recovery |
|
Self-recovery | Allow users to re-enroll self-recovery information at PBA — Allows the client user's self-recovery details can be reset. The user must then re-enroll their self-recovery details with new self-recovery answers. NoteBefore resetting the self-recovery questions on the client system, make sure that you have enabled the Enable Self Recovery option under User Based Policy | Self-recovery. When this option is enabled, the preboot authentication (user name) screen includes the Reset self-recovery option. On selecting Reset self-recovery , the user is prompted for a password, then self-recovery enrollment. NoteOnly initialized users can reset their self-recovery details. |
DETech disaster recovery (v7.3 Onwards, UEFI only) | Allow users to perform disaster recovery using DETech — Allows the user to perform disaster recovery using the option Trellix Drive Encryption Recovery within the boot menu. NoteDETech disaster recovery will be enabled by default for Fresh install and will be disabled on upgrades. |
Theme tab
Option | Definition |
|---|---|
Select theme | Contains the options for selecting a theme. |
Preview | Displays the preview of the selected theme. The preview is not available for shared policies from another Trellix ePO - On-prem. |
Encryption Providers tab
Option | Definition |
|---|---|
PC Software |
|
Opal | Require all disks to be Opal — Requires all the drives in your client system to be Opal drives for the PC Opal encryption provider to be activated. |
Companion Devices tab
Option | Definition |
|---|---|
Enable Companion Device Support | Allows for the use of smartphone recovery on the system. NoteTo enable smartphone recovery on the system for a user, it must also be enabled in the corresponding user-based policy. NoteThe Companion Device application is now known as Trellix Endpoint Assistant. |