The Product Settings policy options are organized into these tabs: General, Encryption, Log On, Recovery, Boot Options, Theme, Out-of-Band, Encryption Providers, and Companion Devices.
Option | Definition |
|---|---|
Enable policy | Enables the set policies on the client computers.
NoteYou can enable this option only if the DEGO extension 7.x or higher is installed in Trellix ePO - On-prem. |
Logging level | Allows the administrator to set a different logging level for each client computer that has the specific policy setting assigned. NoteTo overwrite the logging level defined in Trellix ePO - On-prem, the LoggingLevelOverride registry key needs to be set on the client system.
|
Harden against cold boot attacks when | Allows you to use the Elevated Security Crypt mode to help protect against cold-boot and other RAM-based attacks, when:
For more information, see the Protection of systems in Windows lock, log off, and standby states section. |
Expire users who do not login | Allows the administrator to control and manage the users who have not logged on to the client system. This option forces the user account, which is not initialized, to expire after a number of hours as set in the policy. |
Allow users to create endpoint info file | Allows the user to collect client system details such as the list of assigned users, policy settings, recovery, and Drive Encryption status. After enabling this option, the Save Machine info button appears in:
You can click this button and save the text file for later reference. |
Enable logging for Credential provider | Select this option to enable or disable credential provider logging. |
Option | Definition |
|---|---|
Encrypt | Allows you to select the required encryption type and to set the encryption priority. |
Encryption type | The type of encryption:
The Encryption type options None, All disks except boot disk, and Selected partitions are not applicable to self-encrypting drives in Opal mode. |
Option | Definition |
|---|---|
Enable automatic booting | When enabled, the client system boots automatically without prompting for a preboot authentication. The expiration date for auto-booting can also be set. If required, the user can select the UTC time standard option. ImportantIf you enable this option without requiring the use of TPM for automatic booting, the Drive Encryption product does not protect the data on the drive when it is not in use.
|
Allow temporary automatic booting | Allows you to turn (on or off) the PBA screen, with a client-side utility. This eliminates the need to modify the policy in Trellix ePO - On-prem, and allows for client-side automation during patching and other client management scenarios. |
Use of TPM for automatic booting | Select one of these options:
NoteThis option is applicable only for systems installed with Drive Encryption 7.3.0 or later. If you apply a policy to the earlier versions of Drive Encryption with automatic booting enabled and use of TPM set to 'Required', it will leave the client system in an unprotected state since autoboot will be enabled with no protection of the disk encryption key. TPM autoboot is designed to display the preboot logon screen, if the TPM measurements change. This can occur due to firmware or operating system updates. It is recommended to use temporary autoboot during the deployment of updates, even when TPM autoboot is enabled. For more information about TPM autoboot, see KB79784. |
Pre-boot power management: Automatically shutdown pre-boot after a period of inactivity: 1-60 minutes | The client system will shut down automatically after the set time at preboot. |
Log on message | Type a message that appears to the client user. |
Do not display previous user name at log on | Prevents the client system from automatically displaying the user name of the last logged on user on all Drive Encryption logon dialog boxes. |
Enable on screen keyboard | Enables the preboot On-Screen Keyboard (OSK) and the associated Wacom serial pen driver. When this option is enabled, the pen driver finds supported pen hardware (Panasonic CF-H1 and Samsung Slate 7) and displays the OSK. NoteIf you do not select this option, the BIOS uses mouse emulation. In such a situation, the BIOS treats the digitizer as a standard mouse, which might lead to the cursor being out of sync with the stylus on USB-connected Wacom pen digitizers.
|
Add local domain users (and tag with 'EE:ALDU') |
|
Enable accessibility | Select this option to sound a beep as a signal when the user moves the focus from one field to the next using mouse or keyboard in the preboot environment. This option is helpful to visually challenged users. The USB audio functionality allows visually impaired users to hear an audio signal (spoken word) as guidance when the user moves the cursor from one field to the next in the preboot environment. The USB speakers and headphones can be used to listen to the audio signal. For more details, see Enable Accessibility (USB audio devices) in the preboot environment. |
Disable pre-boot authentication when not synchronized | Blocks a user from logging on to PBA in the client system, if the client system is not synchronized with the Trellix ePO - On-prem server for the set number of days. The user is blocked from logging on to PBA, and can then request the administrator to perform Administrator Recovery to unlock the client system. This allows the client system to boot and communicate with the Trellix ePO - On-prem server. NoteThe client system continues to block the user from logging on to the system until synchronization with Trellix ePO - On-prem. |
Read username from smartcard | Automatically retrieves the available user information about the client system from the inserted smartcard; hence the Authentication window does not prompt for a user name. The user can then authenticate by typing the correct PIN. You need to enable the matching rules that are required for matching smartcard user principle name (UPN) names with Drive Encryption user names.
NoteThis feature is supported on the Gemalto .Net V2+ tokens, and PIV and CAC tokens. |
Lock workstation when inactive: After x number of minutes | The client system is locked automatically when it is inactive for the set time. |
Option | Definition |
|---|---|
V7.2 Onwards | Third-party credential providers:
|
Single sign-on (SSO):
| |
Password synchronization:
| |
Preboot user options
| |
Windows username matching
| |
Credential provider bitmap
| |
Pre V7.2 | Enable SSO — Select this option to enable Single Sign On.
NoteMake sure to note that SSO now works with Drive Encryption 7.3.0 or later when the client system resumes from hibernation or when booting the system using Windows 8 fast boot. |
Require Drive Encryption logon (only supported on V6 clients) — This requires you to mandatorily log on to PBA for EEPC 6.x.x systems, thereby disabling the SSO functionality.
|
Option | Definition |
|---|---|
Enabled | The Recovery option is enabled by default. This activates the Administrator Recovery option in the client system. |
Administrator recovery |
|
Self-recovery | Allow users to re-enroll self-recovery information at PBA — Allows the client user's self-recovery details can be reset. The user must then re-enroll their self-recovery details with new self-recovery answers. NoteBefore resetting the self-recovery questions on the client system, make sure that you have enabled the Enable Self Recovery option under User Based Policy | Self-recovery. When this option is enabled, the preboot authentication (user name) screen includes the Reset self-recovery option. On selecting Reset self-recovery , the user is prompted for a password, then self-recovery enrollment. NoteOnly initialized users can reset their self-recovery details. |
DETech disaster recovery (v7.3 Onwards, UEFI only) | Allow users to perform disaster recovery using DETech — Allows the user to perform disaster recovery using the option Trellix Drive Encryption Recovery within the boot menu. NoteDETech disaster recovery will be enabled by default for Fresh install and will be disabled on upgrades. |
Option | Definition |
|---|---|
Enable Boot Manager | Activates the built-in preboot partition manager. This allows you to select the primary partition on the hard disk that you want to boot. Naming of the partition is also possible with the boot manager. The timeout for the booting to start can also be set. |
Always enable pre-boot USB support | Forces the Drive Encryption preboot code to always initialize the USB stack. USB audio functionality allows the visually impaired users to listen to an audio signal (spoken word) as a guidance when the user moves the cursor from one field to the next, in the preboot environment. The USB speakers and headphones can be used to listen to the audio signal. NoteYou will notice an improper synchronization of the mouse cursor and the stylus on USB connected Wacom pen digitizers. To avoid this, make sure to enable this option. For more details, see Enable Accessibility (USB audio devices) in the preboot environment. |
Enable pre-boot PCMCIA support | If selected, the policy enables preboot PCMCIA support. |
Graphics mode | Allows you to select the screen resolution for a system or a system group. The default option is Automatic. |
Option | Definition |
|---|---|
Select theme | Contains the options for selecting a theme. |
Preview | Displays the preview of the selected theme. The preview is not available for shared policies from another Trellix ePO - On-prem. |
Drive Encryption: Out Of Band Management Option | Definition |
|---|---|
Enable at PBA | Enables the Drive Encryption out-of-band management features through policies and then perform actions on Intel® AMT provisioned client systems. NoteYou can select this option only if you installed the Drive Encryption: Out Of Band Management extension in Trellix ePO - On-prem. NoteThis option is no longer supported. |
Option | Definition |
|---|---|
PC Software |
|
Opal | Require all disks to be Opal — Requires all the drives in your client system to be Opal drives for the PC Opal encryption provider to be activated. |
Option | Definition |
|---|---|
Enable Companion Device Support | Allows for the use of smartphone recovery on the system. NoteTo enable smartphone recovery on the system for a user, it must also be enabled in the corresponding user-based policy. NoteThe Companion Device application is now known as Trellix Endpoint Assistant. |