Trellix FRP 5.6.0 and later supports Microsoft Entra ID (formerly Azure AD) integration. You can register a Microsoft Entra tenant with Trellix ePO - On-prem to leverage user-based Policy Assignment Rules, regular and personal key assignments for Entra ID users and assignment of keys to Entra joined systems, on Windows clients.
This feature provides a seamless and consistent Trellix FRP policy enforcement and key assignment experience for Active Directory and Microsoft Entra ID users and devices, including:
Enforcement of User-based and System based ePO - On-prem Policy Assignment Rules.
Trellix FRP Key assignments to Entra ID users is supported only for operating system and password token.
Trellix FRP Key assignment to clients.
Note
Only internal member users are currently supported on Entra joined devices. Hybrid and migrated identities for devices or users are not supported.
This integration requires ePO - On-prem support for Entra ID and was introduced in ePO 5.10 SP1 U5. Before this feature can be used, the Entra tenant must be registered as a directory server with ePO, if it has not already been done.
Follow these steps in order to use all Entra ID compatible FRP features:
To register Microsoft Entra ID with ePO - On-prem, collect the following details from your Microsoft Azure portal: Tenant ID (Directory ID), Client ID (Application ID), and Client Secret (Application Password). For More information, see KB article Overview of Microsoft Entra ID (Azure AD) support for Trellix ePO - On-prem Directory Services (000014557).
Register the tenant as a directory server. To do this, see Registering a Microsoft Entra ID on Trellix On-prem in the ePO - On-prem Product Guide.
Before assigning Trellix FRP keys to Entra ID users, follow the steps in article 000015151 to avoid issues with user synchronization.