The user-based policy controls the parameters for Drive Encryption user accounts. For example, it contains the options for selecting a token type (including password and smartcard) and password content rules.
You can configure the user-based policies by clicking → → , then selecting Drive Encryption 7.4 from the Product drop-down list.
Select User Based Policies from the Category drop-down list. Locate the My Default policy and click Edit Settings. For more information about individual policy settings, see the Trellix Drive Encryption 7.4.x Product Guide.
User-based policies in Drive Encryption
Drive Encryption 7.3.x or later requires that you specify which groups of users are allowed to use the Policy Assignment Rules. The allowed users get their required user-based policies. Users that are not allowed to use the Policy Assignment Rules inherit the default user-based policies assigned to the system.
Enforce the desired user-based policy to a user assigned to a client system by enabling the Configure UBP enforcement option.
Note
If possible, it is always better to assign user-based policies at the system level or branch level, rather than using the Policy Assignment Rules. However, you can use the Policy Assignment Rule option, if required, to assign different policies to different users.
The user-based policy options are organized into these tabs.
Policy Options | Recommendations |
|---|---|
Token type | Password authentication is recommended. if multi-factor authentication is required, configure and select the required smart card token. |
Certificate rule | Drive Encryption enhances the use of PKI and tokens to allow users to authenticate using their certificates. You can use certificate rules to efficiently update Drive Encryption about all certificate-holding users, and allow them to be allocated to PCs using Drive Encryption without having to create new smart cards or other forms of token for their use.
NoteThe Certificate rule options are not active if Password only is selected. |
Logon Hours | You can set the days and the hours when the user can log on to the client system. The restrictions are applied using the Apply Restrictions option. We recommend enabling this option only if you have a specific requirement. |
Policy Options | Recommendations |
|---|---|
Change Default Password |
|
Password Change | Disable all of these settings as you would be using SSO and don't want to cause conflict with Windows password requirements.
|
Incorrect Passwords |
|
Allow showing of password | Enable this option if you want the password of the user to be displayed while entering it. |
Policy Options | Recommendations |
|---|---|
Display list of password rules | Enable this option to display the password requirements to users. |
Password length | Leave the default value. |
Enforce password content | Leave the default value. |
Password content restrictions | Leave the default value or enable restrictions for increased password strength. |
Policy Options | Recommendations |
|---|---|
Enable self-recovery | Leave this option checked (enabled). |
Invalidate self-recovery after no. of invalid attempts | Enable and set the number of attempts to a number that does not abruptly lock out the Self Recovery. |
Questions to be answered | Can be set to 3. This can provide the required security without overly inconveniencing the user. It is up to the administrator to decide how many questions are required. |
Logons before forcing user to set answers | Set this to 0. This makes sure that the users set the answers during the user initialization. |
Questions | Leave the default questions or configure new questions as required. |
Policy Options | Recommendations |
|---|---|
Enable Companion Device Support | Select this option to allow the user to perform system recovery using a smartphone or mobile device. NoteThe Companion Device application is now known as Trellix Endpoint Assistant. |
Password Definition | Enable this option to create a password according to the option selected. NoteIf the user has once set a higher password definition to the system, the user cannot change the password to a lower password definition (that is less secure) even if that policy is set in Trellix ePO - On-prem. |