The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Server policy settings

Prev Next

The server settings are organized into these tabs: General, Incompatible Products, Theme, Simple Words, Tokens, LDAP Attributes, PC software, PC Opal.

General tab

Option

Definition

If user is disabled in LDAP Server

Allows you to disable, delete, or ignore a user if the user has been disabled on the LDAP Server.

Machine key re-use

Enables activation of the system with the existing key present in the ePO - On-prem server. This option is useful when a boot disk gets corrupted and the user can't access the system. The corrupted system's disks, other than the boot disk, can be recovered by activating it with the same key from ePO - On-prem.

Note

Machine key re-use is not applicable to systems having self-encrypting (Opal) drives.

Batch size for retrieving users

Allows the system to send users to the client in batches rather than sending them all at the same time. Specify the number of users that are sent in each batch. Increasing the batch size increases the amount of memory required on the server and the client. But, this reduces the number of recommended messages required to be sent between the client and server.



Incompatible Products tab

Option

Definition

Manage incompatible products

Allows you to manage the list of products that are not compatible with Drive Encryption. You can also import an incompatible product rule that can detect and add the incompatible product to the list. You cannot activate Drive Encryption on a client system where these incompatible products are present.



Themes tab

Option

Definition

Manage Themes

Allows you to add and customize a theme that is used as a background in the Pre-Boot Authentication page.



Simple Words tab

Option

Definition

Add group

Allows you to create a group that can have a number of simple words. This will not be available for shared policy from another ePO - On-prem.

Remove group

Deletes a group of simple words.

Import words to group

Allows you to browse to a text file with a number of simple words that can't be used as passwords. You can also select an encoding type for the file.

Regenerate missing simple word package

Compiles all the simple word groups and creates the simple words package files (.xml file).



Tokens tab

Option

Definition

Manage Tokens

Allows you to add and manage extra token definitions. This allows the user to deploy and manage additional token modules any time after the initial installation.



LDAP Attributes tab

Option

Definition

Manage LDAP Attributes

Allows you to manage user attributes for Active Directory and User Directory.

Note

The User Directory attributes appear only if you have installed the User Directory extension.



PC software tab

Option

Definition

Algorithm

Specifies the algorithm AES-256-CBC for the software encryption.

Pre-boot storage size 50MB (20-100)

Allows you to set the size of the pre-boot file system. Increasing the size of the PBFS increases the number of users that can be successfully assigned to the client system. The size is specified in MB from 20 MB to 100 MB. If you are assigning a large set of users to the system, the PBFS size must be 100 MB.

Note

The default Pre-Boot storage size for PC software is 50 MB.



PC Opal tab

Option

Definition

Pre-boot storage size 50MB (20-100)

Allows you to set the size of the pre-boot file system for the client systems with self-encrypting (Opal) drives. Increasing the size of the PBFS increases the number of users that can be successfully assigned to the client system. The size is specified in MB from 20 MB to 100 MB. If you are assigning a large set of users to the system, the PBFS size must be 100 MB.