The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Product Settings Policy — General tab

Prev Next

The General tab under the Product Settings Policy provides you the settings required for activating the product, to collect the log messages from the client system, and to manage the users who are not logged on.

Option

Definition

Enable policy

Enables the set policies on the client computers.

  • Only activate if health check (Drive Encryption: Go) passes —Select this option to activate Drive Encryption on client systems only when the Drive Encryption: GO health check passes.

Note

You can enable this option only if the DEGO extension 7.x or higher is installed in Trellix ePO - On-prem.

Logging level

Allows the administrator to set a different logging level for each client computer that has the specific policy setting assigned.

Note

To overwrite the logging level defined in Trellix ePO - On-prem, the LoggingLevelOverride registry key needs to be set on the client system.

  • None — Does not create any log for the client system managed by Trellix ePO - On-prem.

  • Error — Logs only error messages.

  • Error and Warnings — Logs the error and warning messages.

  • Error, Warnings, and Informational — Logs the error and warning messages with more descriptions.

  • Error, Warnings, Informational and Debug — Logs the error, warning, and debug messages.

Harden against cold boot attacks when

Allows you to use the Elevated Security Crypt mode to help protect against cold-boot and other RAM-based attacks, when:

  • The system is locked.

  • The user is logged off.

  • The system is in standby.

  • Always (On systems that support Intel SGX)

For more information, see the Protection of systems in Windows lock, log off, and standby states section.

Expire users who do not login

Allows the administrator to control and manage the users who have not logged on to the client system. This option forces the user account, which is not initialized, to expire after a number of hours as set in the policy.

Allow users to create endpoint info file

Allows the user to collect client system details such as the list of assigned users, policy settings, recovery, and Drive Encryption status.

After enabling this option, the Save Machine info button appears in:

  • Windows — Trellix Agent Tray → Quick Settings → Show Drive Encryption Status.

You can click this button and save the text file for later reference.

Duplicate

Duplicates or copies the policy settings with a different name and this can be assigned to a different user.

Save

Saves the product settings policy of Drive Encryption.

Cancel

Exits the current page.