The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Trellix Data Loss Prevention Endpoint for Windows 11.10.0 Release Notes

Prev Next

The Trellix DLP Endpoint for Windows 11.10.0 release includes new features and resolved issues.

Product rebranding changes

This is solely for informational purpose, there is no action required. You can continue to secure your organization with Trellix DLP Endpoint as usual. You will notice the following changes in the software:

As Trellix continues to evolve, you will begin to see our solutions reflect our new name and brand. In this release, you will notice the following changes in the software. This rebranding change requires an effort from your end if your enterprise manages root certificate updates manually.

  • Product name - McAfee Data Loss Prevention Endpoint is renamed as Trellix Data Loss Prevention Endpoint. All features and options prefixed with product name are renamed with the new product name.

  • Brand logo and name - McAfee logo and name are replaced with Trellix logo and name.

  • User interface - Color and typeface are updated and provide better user experience.

  • End-User License Agreement and Copyright - The End-User License Agreement and Copyright are updated according to legal requirements. Please read the agreement for details.

Certificate update changes

As part of rebranding, the certificates used to sign our software have been updated. If your enterprise automatically updates root certificates, the software update or installation does not require any additional effort. However, if your enterprise manages root certificate updates manually, you need to install the new intermediate and root certificates.

For information about downloading and installing the certificates, see KB91697.

Release details

Release date - February 1, 2023

Release builds:

  • Trellix Data Loss Prevention Endpoint client build 11.10.0.29

  • Trellix Data Loss Prevention extension build 11.10.5.9

Important

We are aware of a BSoD issue with Intel 11th Gen CPUs. It is recommended not to deploy Trellix DLP Endpoint v11.9.0 to these specific systems until the issue is fixed. For more information, see KB95295.

Note

For Trellix DLP Endpoint 11.10.0, make sure that you use Trellix DLP 11.10.5.5 extension. Trellix DLP Endpoint 11.10.0 client software is not compatible with earlier versions of Trellix DLP extensions.

For the specific build numbers, see Product release information in KB68147.

Note

Release to Support (RTS) releases are limited-availability releases intended for customers known to have issues resolved in the release. To align our release process with that of other Trellix product releases, the Trellix DLP team recommends that these packages should only be installed in lab environments or in limited numbers of production systems for verification of the fixes and making sure that there are no unexpected errors. Trellix does not recommend widely deploying RTS packages in production environments.

Note

Pre-Release or Beta builds are highly restricted releases that have been through partial / essential testing only. Such releases are intended for customers who have agreed to partner with us on the testing process in a more detailed and collaborative way to facilitate early access and a greater level of testing and feedback. These packages should only be installed in lab environments or on a limited number of endpoint systems in production environments. It is not recommended to use Trellix ePO - On-prem or other management tools, unless within a lab environment. To make sure that usage does not extend beyond these terms, Trellix also recommends these packages to be tightly controlled and not distributed to individuals other than those working directly with Trellix.

Data Loss Prevention (DLP) feature release

Trellix DLP 11.10.0 is a feature release version. New features, which include customer-raised product ideas are added only to the feature release versions. The most recent Long-Term Support release version of Trellix DLP Endpoint is 11.6.600. As such, version 11.10.0 doesn't end support for any previous release.

For more information about different kinds of releases, see KB91807.

Not supported upgrade path

Cannot upgrade from...

To

11.9.0

11.10.0

Important

To upgrade Trellix DLP Endpoint version from 11.9.0 to 11.10.0, you must first upgrade from 11.9.0 to 11.9.100 and then to 11.10.0.

Updated platform, environment, or operating system support

For additional information on supported platforms, environments, and operating systems, see KB68147.

New or changed features

This release introduces new features or improves existing features:

Regex case sensitivity — To apply case sensitivity with any regular expression, the regex pattern must begin with ?i. You can also edit the existing regex pattern and append ?i at the beginning of the pattern. To enable regex case sensitivity, select the Use default agent behavior for regex checkbox in Menu → Policy → Policy Catalog → Data Loss Prevention <version> → Windows Client Configuration → Default Windows Client Configuration → Edit → Advanced Configuration → Advanced Pattern Settings.

Hit Highlight — You can now configure match count highlighting in the Shared Storage and Evidence page of the client configuration policy in the Classification matches file field.

The match count file shows the Total Match Count and highlights the matches that are hit. The maximum number of hit highlights displayed depends on the option set in this field and shows the matches that are hit in a top-down order. If the total match count exceeds the configured value, the matches that are hit beyond the configured value aren't highlighted.

Adobe 64-bit support - Acrobat Reader DC 64-bit is now supported by Trellix DLP Endpoint.

Email recipient threshold - You can now define thresholds for the To, Cc, Bcc, Cumulative, and Cumulative (Ignored Bcc) fields to monitor and limit emails from being sent to multiple email recipients.

Threshold Violated Details - In the DLP Incident Manager, incidents triggered by threshold violations now display a count of the recipients' domains and emails that exceeded the threshold.

User notification - By using the %t and %e variables, you can now create user notification when the matched attachments or email addresses are violated.

Ignored Processes - Trellix DLP Endpoint can now exclude processes that are specific to file tracking. To ignore a process, go to Menu → Policy → Policy Catalog → Data Loss Prevention <version> → Windows Client Configuration → Default Windows Client Configuration → Edit → Content Tracking → Ignored Processes.

Valid wildcard support - You can use wildcard characters, such as ., ?,*, and + in the regex pattern to represent 0 or 1 or more characters when excluding files and folders from scanning.

Enhanced CSV file import - Trellix DLP Endpoint now supports importing user information from CSV files without including top-level domain (TLD) validation. An example for top-level domain (TLD) is .com.

PDF print protection - Trellix DLP Endpoint now monitors and prevents sensitive PDF documents from being printed from Google Chrome and Microsoft Edge.

Manifest v3 compatibility - Trellix DLP Endpoint Extension is now Manifest v3 (MV3) compatible.

Known issues

For a list of current known issues, see: Trellix Data Loss Prevention 11.x.x Known Issues (KB89301).

Resolved issues

This update resolves known issues.

For the DLP Extension related resolved issues, see the Trellix Data Loss Prevention Extension 11.10.5 Release Notes.

Vulnerability issues

Reference

Resolution

CVE-2023-0400

SB10394

The protection bypass and advance installer vulnerability in Trellix DLP Endpoint for Windows 11.9.x is fixed in this release. For more information about vulnerability and remediation, see SB10394.



Resolved issues

Reference

Resolution

DLPW-7753

Fixed an issue where emails sent are held in the Outbox.

DLPW-8055

This fix prevents file copying from PowerShell ISE to removable media devices.

DLPW-8203

This fix prevents attachments from being dragged and dropped from Microsoft Outlook to web browsers.

DLPW-8359

Fixed a false positive issue where the incidents were generated when the Application File-Access Protection rule was used in Microsoft Teams.

DLPW-8670

Fixed an issue where URL information was missing when outlook.office.com was opened in a pop-up window from Chromium browsers.

DLPW-8848

Fixed an issue where Trellix DLP web incidents report "Failure Reason: Text upload blocking is not available" when Timeout reaction is set to Block for text uploads.

DLPW-8865

Fixed an issue where Titus Classification was enabled in Microsoft Outlook that caused it to crash and the email was not saved.

DLPW-8877

Fixed an issue where Google Chrome and Microsoft Edge crashed and failed to launch after a Web Protection rule was created and assigned.