Release summary
This release ensures a smoother installation or upgrade process and improves management of Self Protection during connection issues.
Adds a Musarubra LLC digital signature to the UEFI 2023 check powershell script to ensure smooth execution under strict PowerShell policies.
Enforces Self Protection continuously, allowing administrators to safely enable/disable Self Protection even during SSL errors or SaaS connectivity issues.
Resolves critical upgrade and policy enforcement issues, including incorrect Event error messages, old product version entries remaining in ePO, and upgrade failures.
Release rating: Recommended
This release is recommended for all environments. It improves script execution security, protects policy enforcement during connection disruptions, and resolves key upgrade issues without requiring immediate customer action.
What's new
Digitally Signed UEFI 2023 Certificate check powershell script - The CheckUefiCA2023.ps1 PowerShell script used to verify UEFI 2023 Secure Boot certificates is now digitally signed by Musarubra LLC. This signature ensures script integrity, prevents unauthorized tampering, and allows seamless execution across various Windows PowerShell Execution Policies such as AllSigned, RemoteSigned, and Unrestricted without requiring policy bypasses in enterprise environments.
Note: When the PowerShell Execution Policy is set to AllSigned or RemoteSigned, the installation step adds the Musarubra LLC certificate to Trusted Publishers before executing the PowerShell script.
Enable Self Protection irrespective of enforcement failures - This enhancement ensures that the Self Protection is successfully applied even if overall policy enforcement fails due to SSL errors or SaaS connectivity issues. Previously, when cloud communication was lost, policy enforcement failed completely, preventing administrators from taking actions like disabling Self Protection. This allows administrators to safely manage and disable Self Protection during connectivity disruptions without compromising basic system integrity.
This release upgrades the following libraries to enhance security and cryptographic performance:
- OpenSSL from 1.0.2zd to 1.0.2zq
- libcurl from 8.18 to 8.21
Resolved issues
The following table lists the resolved issues in this release.
General
Issue ID | Description |
|---|---|
TDE-10857 | Event ID 2422 (Agent failed to enforce policy on at least one |
Installation
Issue ID | Description |
|---|---|
TDE-11177 | Drive Encryption 7.4.x to 8.x upgrades now proceed without intermittent failures at the RestoreV7Files stage, preventing installation rollbacks and undefined endpoint states. |
TDE-11043 | Upgrading Drive Encryption from version 7.2.x to 8.1.x now removes the legacy 7.2.x product version from the ePO System Tree. |
Known issues
For details about Trellix Drive Encryption 8.x known issues, see article KB84502.
Upgrade and installation information
Release information
This section details the release date, build numbers and installation packages included in this release.
Release date: September 23, 2026
Build information:
Component | Build Number |
|---|---|
Drive Encryption 8.1.2 | 8.1.2.9 |
Installation package
Deployment type | Package |
|---|---|
Drive Encryption | Extension:
Software package:
|
Prerequisites
Upgrade impact
Use this section to describe any expected operational impact during or after installation of the release.
Component | Impact |
|---|---|
PC Encryption/ Opal Driver | Requires a system restart to activate the updated driver. |
Trellix Drive Encryption Agent | Service restarts automatically during installation. |
ePO Communication | Connectivity might be interrupted for approximately 30 seconds during service restart. |
Supported upgrade path
The following table lists the supported upgrade paths to the current release.
Current version | Supported upgrade path | Deployment method |
|---|---|---|
7.4.x (UEFI) | 7.4.x → 8.1.2 | ePO only |
8.x.x | 8.x.x → 8.1.2 | Standalone MSI or ePO |
Deprecated items
Support for Master Boot Record (MBR) disk layouts was removed in the Drive Encryption 8.0.0 release. Drive Encryption 8.x exclusively supports GUID Partition Table (GPT) disks. Primary and secondary MBR disks must be converted to GPT before upgrading.
Additional information
Trellix Thrive: Access the unified portal for technical support, product downloads, support case management, diagnostic tools, knowledge base articles, product training, webinars, and community interaction.
Note: Access to the Trellix Thrive Portal requires login using valid Trellix customer support, partner, or employee credentials.
Trellix Drive Encryption Documentation: For detailed technical information, including product guides, release notes, and configuration instructions of [Product Name], visit our documentation portal.