The Trellix Drive Encryption 8.1.0 release includes new feature and resolved issues.
Every update release is cumulative and includes all features and fixes from the previous release. We recommend that you always upgrade to the latest version.
Trellix Drive Encryption Release details
Release date - August 31, 2026 (Republished to include support for GPT disks and deprecation of MBR disk layouts)
For more information about release dates and build numbers, see Trellix Drive Encryption product release information section in article KB79422.
Rating
The rating defines the urgency for installing this update.
Recommended
This update is recommended for all environments. Apply this update at the earliest convenience.
Product compatibility
This release supports:
Trellix ePolicy Orchestrator - On-premises — 5.10.0 SP1 or later.
Trellix Agent — 5.8.0 or later.
Upgrade support
For complete system requirements, see supported platforms for Drive Encryption 8.x in article KB79422.
New features and changes
This release includes support for the following enhancements and changes:
Enhancement of Trusted Platform Module (TPM) autoboot sensitivity — With Drive Encryption 8.1.0 release, you can now select or deselect Platform Configuration Registers (PCRs) from 0 to 7, for greater flexibility in how the Trusted Platform Module (TPM) functions for automatic booting. Modifying PCR settings through policy is seamless and does not trigger Pre-Boot Authentication (PBA). This enhancement supports TPM versions 1.2 and later.
Simplified TPM autoboot upgrade and deployment — You can now switch to TPM autoboot without requiring authentication during pre-boot. This includes a seamless upgrade across endpoints without end user interaction, simplifying deployment and saving time and resources by eliminating the need to educate end users on pre-boot interaction. For more information, see KB79784.
Addition of Drive Encryption Event for Activation Failures due to insufficient space in EFI System Partition — This release introduces a Drive Encryption Event that allows administrators to view Drive Encryption activation or Bootcode upgrade failures caused by insufficient space in the EFI System Partition (ESP). For more information, see KB84622.
Update to the default minimum password length in the Password Content Rules — The minimum password length for User Based Policies is now 7 characters (previously 3) to support an upcoming FIPS 140-3 upgrade. Existing passwords remain valid, but the new 7-character minimum will be enforced during the user's next password change.
Removal of support for disks with MBR disk layout — Drive Encryption 8.0.x is the first release that exclusively supports only GUID Partition Table (GPT) disks. Primary and secondary disks that use the Master Boot Record (MBR) disk layout are not supported. Convert these disks to a GPT layout before upgrading to Drive Encryption 8.x.
Resolved issues
This release resolves known issues.
Category | Reference | Resolution |
|---|---|---|
User Interface | TDE-9967 | Drive Encryption status window no longer fails to open after deployment of the client package and before the system was rebooted. |
User Interface | TDE-10126 | Fixed an issue where the Save button was disabled while adding user in the User Directory. |
Installation | TDE-10304 | Fixed an issue where the previous version of Drive Encryption Agent was listed in the ePO Products list after endpoints were upgraded from Drive Encryption 7.x to 8.x. |
Fixes to features | TDE-10310 | The obsolete UseTPM field no longer appears in the client's Save Machine Information after a fresh install or upgrade of the Drive Encryption extensions. |
Fixes to features | TDE-10326 | Fixed an issue where Key Encryption Key (KEK) related messages were shown in the client log, even when the corresponding product setting policy was disabled. |
Interoperability | TDE-10345 | Fixed an issue where the EnableMPR registry key was deleted by Drive Encryption, which caused third-party software that uses this registry to fail. |
User Interface | TDE-10446 | When the accessibility and logon managed autoboot is enabled, users now hear a beep when the Pre-Boot Authentication (PBA) dialog pops up after reaching the maximum failed Windows logon attempts. For the new beep code, see KB69853. |
Interoperability and Installation | TDE-10657 | This release prevents activation on systems with Windows Fast Startup enabled to ensure a stable Drive Encryption environment. For more information, see KB77144. |
User Interface | TDE-10677 | The system beep used for accessible interface navigation in pre-boot is adjusted to provide a more gentle experience. |
Known issues
For details about Trellix Drive Encryption 8.x known issues, see article KB84502.