The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Removable media policy page

Prev Next

Use this page to configure the removable media policy settings for USB devices and floppy disks. The policy settings for removable media are organized in separate tabs according to media type.

USB Media settings

Option

Definition

USB Media Protection Level

Specifies protection level for removable media. These methods are mutually exclusive and the Enforce Encryption (with offsite access) option is enabled by default.

  • Allow Unprotected Access (report) — Does not encrypt files on removable media.

    Note

    This protection level is available for both Windows and macOS client systems.

  • Allow Encryption (with offsite access) — Enables users to create an encrypted container on the USB device and copy data to the device in a secure manner.

    This option allows the creation of media that can be securely authenticated and accessed by any system with a supported Windows or macOS operating system, without having to install the Trellix FRP client.

    Note

    This protection level is available for both Windows and macOS client systems.

  • Enforce Encryption (with offsite access) — Users must create an encrypted container on the USB device and copy data to the device in a secure manner. In addition, copying of data to the USB device is prevented if the user tries to copy data to the unencrypted part of the USB device. This option allows the creation of media that can be securely authenticated and accessed by any system with a supported Windows or macOS operating system, without having to install the Trellix FRP client.

  • Enforce Encryption (onsite access only) — Encrypts files and folders with the selected key while copying them to a USB device. The encrypted data is accessible only on Trellix FRP systems with the availability of the required key.

    Note

    This protection level is available only for Windows client systems.

  • Block Write Operations — Prevents the copying or writing of data onto a USB device.

    Note

    This protection level is available for both Windows and macOS client systems.

    Note

    Copying of data from the USB device is permitted.

Allow Mac OSX offsite browser application upgrades on Windows client

This option is disabled by default. When enabled, a Windows client checks if the MAC RM offsite browser on an EERM initialized USB needs to be upgraded with the previous version installed on client systems.

Note

Upgrades are allowed only if the on-USB MAC app version is 5.1.0 or higher.

USB Media Protection Options

Specifies the options for the encryption of USB devices. The All tab displays the complete set of media protection options. To filter the list to view specific settings, select the corresponding tab.

Note

The availability of this section and the options it contains depends on the protection level.

  • Protected Area — Specifies options to configure the encrypted area on a removable media. (Applicable for Allow Encryption (with offsite access) and Enforce Encryption (with offsite access) protection levels only.)

    • Full device — Creates an encrypted container that is equal to the size of the device.

      This option can be restricted based on device size by selecting Except when device is greater than, setting the maximum device size in GB. The default value is 64 GB. Then specifying either Do not encrypt or User Managed (Allows the user to determine the size of the encrypted container only when the device size is greater than the maximum size given in the policy).

      Note

      For Mac systems, the user is not provided an option to back up the existing data. Any existing data is deleted before a container is created.

    • User Managed — Allows the user to determine the size of the encrypted container.

  • Authentication — Specifies the methods used to authenticate the encrypted removable media. (Applicable for Allow Encryption (with offsite access) and Enforce Encryption (with offsite access) protection levels only.)

    • Password — Enables the user to specify a password during initialization that can be used to recover the encrypted removable media. Select Mandatory to require the user to specify an authentication password during initialization.

      Note

      For macOS systems, Password and Key are the only 2 authentication mechanisms.

    • Certificate — Enables the user to attach a Windows certificate during initialization that can be used to authenticate to the encrypted removable media. Select Mandatory to require the user to attach a certificate during initialization.

    • Key — Specifies the Regular or User Personal key that can be used to authenticate to the encrypted removable media.

      Note

      If Key authentication is not present, fall back option is Password authentication.

  • Customisable Recovery Message — Specifies the message that is displayed to the user when a removable media recovery is initiated.

  • Customize UI Text displayed on inserting Media — Specifies the message to be displayed to a user on inserting a removable media into an Trellix FRP client with removal media encryption enabled. This text is customizable, and limited to 300 characters. If left blank, the default message is shown. (Applicable for Allow Encryption (with offsite access) and Enforce Encryption (with offsite access) protection levels only.)

  • Encryption Key — The key to use to encrypt the USB device. This option is applicable only when Enforce Encryption (onsite access only) is selected.

    • Ignore existing content — Existing content on the USB device is left untouched.

  • Exempted Device IDs — Specifies devices for which the Removable Media encryption policies are not applicable. These devices are also exempted from explicit encryption and decryption.

    Note

    This policy is applicable for Windows systems only.

    • Add — Adds the ID of the device that is not updated with the changes in encryption policies.

    • Remove — Removes the device ID from the exemption list.

    • Edit — Edits the ID of the device that is not updated with the changes in encryption policies.

Floppy Disk Media settings

Option

Definition

Floppy Disk Protection Level

Specifies the options for the protection of floppy disks.

  • Allow Unprotected Access (report) — Does not encrypt files on floppy disks. Default value is enabled.

  • Block Write Operations — Prevents the copying of data onto a floppy disk.

Other options

Option

Definition

Share

Shares the policy between multiple ePO - On-prem servers.

Duplicate

Duplicates or copies the policy with a different name that can be assigned to a different user or system.

Save

Saves the product settings policy of Trellix FRP.

Cancel

Closes the policy page without saving the changes.