Release summary
This release strengthens cryptographic compliance, simplifies removable media management and fixes software issues.
Upgrades core security libraries and cryptographic modules to align with FIPS 140-3 standards when running in FIPS mode.
Enables full write access for BitLocker To Go encrypted removable media during offsite enforcement, eliminating warning pop-ups and preventing access restrictions.
Supports multi-language media insertion and recovery messages within a single Removable Media policy to minimize administrative overhead and simplify policy assignment.
Resolves software installation and upgrade issues, along with USB drive auto-unlock on Mac and automatic repair issues on Windows.
Release rating
Release rating: Recommended
This release is recommended for all environments.
What’s new
FRP transitions to FIPS 140-3 compliance — Trellix File and Removable Media Protection has updated its core security libraries and cryptographic modules to comply with FIPS 140-3 standards. FRP leverages WolfSSL and TCC AES cryptographic modules to ensure seamless operational continuity.
For more information, see FIPS mode installation in the File and Removable Media Protection Installation Guide.
Allowing write access to BitLocker encrypted Removable Media — When offsite encryption enforcement is active, you can enable "Allow write access to BitLocker To Go encrypted removable media" to grant full write access to the media. The endpoint recognizes a BitLocker-encrypted device when you insert it. This setting prevents standard Trellix File and Removable Media Protection warning pop-up windows and prevents drive access restrictions.
Note
Trellix FRP prevents the initialization of removable media on devices encrypted with BitLocker to prevent dual encryption. If you attempt to encrypt a BitLocker-encrypted device using Trellix FRP, a warning pop up appears stating that Trellix FRP might format the drive to remove BitLocker before initializing Trellix FRP, so back up all files on the drive.
For details about this option, see Removable media policy page Removable media policy page in the Interface Reference Guide.
Configure localized media insertion and recovery messages — The Custom UI tab within Removable Media policy settings allows administrators to configure custom media insertion and recovery messages in multiple languages within a single policy. This setting eliminates the need to create duplicate policies, reducing policy management overhead and simplifying assignment rules.
For details about this option, see Removable media policy page in the Interface Reference Guide.
Resolved issues
General
Issue ID | Description |
|---|---|
FRP-11293 | Non-admin users on macOS no longer need admin credentials to insert and unlock encrypted USB drives. USB Drives now unlock using the logged-in user’s credentials. |
FRP-11641 | FRP encrypted USB devices with a missing info.plist (corrupted Mac offline browser) now automatically repair on Windows machines without data loss. |
Installation
Issue ID | Description |
|---|---|
FRP-11661 | Trellix FRP installation completes without triggering the "MfeFfPostInstall.dll failed to register. HRESULT -2147418113" error caused by a program menu shortcut from an earlier software version. |
FRP-11434 | Upgrading Trellix FRP 5.4.x to later versions no longer creates duplicate entries in Trellix ePO. |
Security fixes
Issue ID | Description |
|---|---|
FRP-11457 | FRP keys assigned to a user using an OS token now load automatically during OS logon when the Windows Logon policy is enabled. Users are no longer prompted for an FRP username. |
Upgrade and installation information
Release information
Release date: 30th September, 2026
Build information:
Component | Build number |
|---|---|
FRP 5.7.0 for Windows | 5.7.0.179 |
FRP 5.7.0 for Mac | 5.7.0.44 |
FRP 5.7.0 for Extension | 5.7.0.179 |
Installation packages
Deployment type | Package |
|---|---|
Trellix FRP | Extensions:
Software package:
|
Prerequisites
Ensure the FRP extension is upgraded prior to updating the client software.
Ensure the Trellix Agent is upgraded to version 5.8.0 or later.
Upgrade impact
Component | Impact |
|---|---|
FRP Client (FIPS 140-3 Upgrade) | The client database (frpclientdb) entry storing the OS token key is deleted during the upgrade to support stronger cryptographic algorithms. End User Impact - If AD Authentication policy is enabled, users must re-authenticate with their domain password on their first login after upgrade (one-time requirement). |
BitLocker To Go Policy | Enabling this policy blocks client SaaS migration and BitLocker To Go setting migration. Policies will migrate, but BitLocker To Go settings are not visible in SaaS. |
Removable Media Policy (Custom UI Settings) |
|
User Local Keystores | Automatically upgraded to a stronger cryptographic algorithm upon the first unlock trigger. Old keystores will be backed up in the same location and cleaned up in a future release. |
Supported upgrade path
The following table lists the supported upgrade paths to the current release.
Current version | Supported upgrade path |
|---|---|
5.4.x | → |
5.5.x | → |
5.6.x | → |
Known issues
For a complete list of known issues, see Trellix File and Removable Media Protection 5.x known issues (KB85807).
Deprecated items
This release does not contain any deprecated items.
Additional information
Trellix Thrive: Access the unified portal for technical support, product downloads, support case management, diagnostic tools, knowledge base articles, product training, webinars, and community interaction.
Trellix File and Removable Media Protection Documentation: For detailed technical information, including product guides, release notes, installation instructions, and configuration guidelines of FRP, visit our documentation portal at docs.trellix.com.