The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Recommended user-based policy settings

Prev Next

The user-based policy controls the parameters for Drive Encryption user accounts. For example, it contains the options for selecting a token type (including password and smartcard) and password content rules.

You can configure the user-based policies by clicking Menu → Policy → Policy Catalog, then selecting Drive Encryption 8.1.x from the Product drop-down list.

Select User Based Policies from the Category drop-down list. Locate the My Default policy and click Edit Settings. For more information about individual policy settings, see the Trellix Drive Encryption 8.1.x Product Guide.

User-based policies in Drive Encryption

Drive Encryption 7.3.x or later requires that you specify which groups of users are allowed to use the Policy Assignment Rules. The allowed users get their required user-based policies. Users that are not allowed to use the Policy Assignment Rules inherit the default user-based policies assigned to the system.

Enforce the desired user-based policy to a user assigned to a client system by enabling the Configure UBP enforcement option.

Note

If possible, it is always better to assign user-based policies at the system level or branch level, rather than using the Policy Assignment Rules. However, you can use the Policy Assignment Rule option, if required, to assign different policies to different users.

The user-based policy options are organized into these tabs.

Authentication tab

Policy Options

Recommendations

Token type

Password authentication is recommended. if multi-factor authentication is required, configure and select the required smart card token.

Certificate rule

Drive Encryption enhances the use of PKI and tokens to allow users to authenticate using their certificates. You can use certificate rules to efficiently update Drive Encryption about all certificate-holding users, and allow them to be allocated to PCs using Drive Encryption without having to create new smart cards or other forms of token for their use.

  • Provide LDAP user certificate — Leave this option checked (enabled).

  • Enforce certificate validity period on client — Leave this option checked (enabled) to enforce certificate validity period for the added certificate rule.

  • Use latest certificate — Leave this option checked (enabled).

Note

The Certificate rule options are not active if Password only is selected.

Logon Hours

You can set the days and the hours when the user can log on to the client system. The restrictions are applied using the Apply Restrictions option. We recommend enabling this option only if you have a specific requirement.



Password tab

Policy Options

Recommendations

Change Default Password

  • Do not prompt for default password — Leave this option checked (enabled). When enabled, users are prompted to type in their Drive Encryption password without having to remember a common default password. If you enable this option, you don't have to enable the Change Default Password option.

Password Change

Disable all of these settings as you would be using SSO and don't want to cause conflict with Windows password requirements.

  • Enable password history____changes (1-100) — Leave this option checked (enabled) to prevent users from reusing passwords unless your security policy exempts users from using new passwords.

  • Prevent change — Leave this option unchecked (disabled).

    • Require change after ____ days (1-366) — Leave this option unchecked (disabled).

      • Warn user _____ days before password expiry (0-30) — This is disabled by default when you disable the Require change after ____ days (1-366) option.

Incorrect Passwords

  • Timeout password entry after ____ invalid attempts (3-20) — Set the number of invalid attempts to trigger a timeout.

    • Maximum disable time ____minutes (1-64) — This is disabled by default when you disable the Timeout password option.

  • Invalidate password after ____ invalid attempts — Leave this option checked (enabled).

Allow showing of password

Enable this option if you want the password of the user to be displayed while entering it.



Password Content Rules tab

Policy Options

Recommendations

Display list of password rules

Enable this option to display the password requirements to users.

Password length

Leave the default value.

Enforce password content

Leave the default value.

Password content restrictions

Leave the default value or enable restrictions for increased password strength.



Self-Recovery tab

Policy Options

Recommendations

Enable self-recovery

Leave this option checked (enabled).

Invalidate self-recovery after no. of invalid attempts

Enable and set the number of attempts to a number that does not abruptly lock out the Self Recovery.

Questions to be answered

Can be set to 3. This can provide the required security without overly inconveniencing the user.

It is up to the administrator to decide how many questions are required.

Logons before forcing user to set answers

Set this to 0. This makes sure that the users set the answers during the user initialization.

Questions

Leave the default questions or configure new questions as required.



Companion Devices tab

Policy Options

Recommendations

Enable Companion Device Support

Select this option to allow the user to perform system recovery using a smartphone or mobile device.

Note

The Companion Device application is now known as Trellix Endpoint Assistant.

Password Definition

Enable this option to create a password according to the option selected.

Note

If the user has once set a higher password definition to the system, the user cannot change the password to a lower password definition (that is less secure) even if that policy is set in ePO - On-prem.