Use this file to discover all available pages before exploring further.
The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.
Use this page to configure the removable media policy settings for USB devices and floppy disks. The policy settings for removable media are organized in separate tabs according to media type.
USB Media settings
Option
Definition
USB Media Protection Level
Specifies protection level for removable media. These methods are mutually exclusive and the Enforce Encryption (with offsite access) option is enabled by default.
Allow Unprotected Access (report) — Does not encrypt files on removable media.
Note
This protection level is available for both Windows and macOS client systems.
Allow Encryption (with offsite access) — Enables users to create an encrypted container on the USB device and copy data to the device in a secure manner.
This option allows the creation of media that can be securely authenticated and accessed by any system with a supported Windows or macOS operating system, without having to install the Trellix FRP client.
Note
This protection level is available for both Windows and macOS client systems.
Enforce Encryption (with offsite access) — Users must create an encrypted container on the USB device and copy data to the device in a secure manner. In addition, copying of data to the USB device is prevented if the user tries to copy data to the unencrypted part of the USB device. This option allows the creation of media that can be securely authenticated and accessed by any system with a supported Windows or macOS operating system, without having to install the Trellix FRP client.
Enforce Encryption (onsite access only) — Encrypts files and folders with the selected key while copying them to a USB device. The encrypted data is accessible only on Trellix FRP systems with the availability of the required key.
Note
This protection level is available only for Windows client systems.
Block Write Operations — Prevents the copying or writing of data onto a USB device.
Note
This protection level is available for both Windows and macOS client systems.
Note
Copying of data from the USB device is permitted.
Allow Mac OSX offsite browser application upgrades on Windows client
This option is disabled by default. When enabled, a Windows client checks if the MAC RM offsite browser on an EERM initialized USB needs to be upgraded with the previous version installed on client systems.
Note
Upgrades are allowed only if the on-USB MAC app version is 5.1.0 or higher.
USB Media Protection Options
Specifies the options for the encryption of USB devices. The All tab displays the complete set of media protection options. To filter the list to view specific settings, select the corresponding tab.
Note
The availability of this section and the options it contains depends on the protection level.
Protected Area — Specifies options to configure the encrypted area on a removable media. (Applicable for Allow Encryption (with offsite access) and Enforce Encryption (with offsite access) protection levels only.)
Full device — Creates an encrypted container that is equal to the size of the device.
This option can be restricted based on device size by selecting Except when device is greater than, setting the maximum device size in GB. The default value is 64 GB. Then specifying either Do not encrypt or User Managed (Allows the user to determine the size of the encrypted container only when the device size is greater than the maximum size given in the policy).
Note
For Mac systems, the user is not provided an option to back up the existing data. Any existing data is deleted before a container is created.
User Managed — Allows the user to determine the size of the encrypted container.
Authentication — Specifies the methods used to authenticate the encrypted removable media. (Applicable for Allow Encryption (with offsite access) and Enforce Encryption (with offsite access) protection levels only.)
Password — Enables the user to specify a password during initialization that can be used to recover the encrypted removable media. Select Mandatory to require the user to specify an authentication password during initialization.
Note
For macOS systems, Password and Key are the only 2 authentication mechanisms.
Certificate — Enables the user to attach a Windows certificate during initialization that can be used to authenticate to the encrypted removable media. Select Mandatory to require the user to attach a certificate during initialization.
Key — Specifies the Regular or User Personal key that can be used to authenticate to the encrypted removable media.
Note
If Key authentication is not present, fall back option is Password authentication.
Customisable Recovery Message — Specifies the message that is displayed to the user when a removable media recovery is initiated.
Customize UI Text displayed on inserting Media — Specifies the message to be displayed to a user on inserting a removable media into an Trellix FRP client with removal media encryption enabled. This text is customizable, and limited to 300 characters. If left blank, the default message is shown. (Applicable for Allow Encryption (with offsite access) and Enforce Encryption (with offsite access) protection levels only.)
Encryption Key — The key to use to encrypt the USB device. This option is applicable only when Enforce Encryption (onsite access only) is selected.
Ignore existing content — Existing content on the USB device is left untouched.
Exempted Device IDs — Specifies devices for which the Removable Media encryption policies are not applicable. These devices are also exempted from explicit encryption and decryption.
Note
This policy is applicable for Windows systems only.
Add — Adds the ID of the device that is not updated with the changes in encryption policies.
Remove — Removes the device ID from the exemption list.
Edit — Edits the ID of the device that is not updated with the changes in encryption policies.
Floppy Disk Media settings
Option
Definition
Floppy Disk Protection Level
Specifies the options for the protection of floppy disks.
Allow Unprotected Access (report) — Does not encrypt files on floppy disks. Default value is enabled.
Block Write Operations — Prevents the copying of data onto a floppy disk.
Other options
Option
Definition
Share
Shares the policy between multiple ePO - On-prem servers.
Duplicate
Duplicates or copies the policy with a different name that can be assigned to a different user or system.
Save
Saves the product settings policy of Trellix FRP.
Cancel
Closes the policy page without saving the changes.