The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Troubleshooting

Prev Next

The following are the troubleshooting methods for some of the commonly occurring errors:

User policy not enforced after transfer has completed

This can occur because of one of the following reasons:

  • A policy assignment rule has been defined.

  • The user was assigned to a branch that the system is a child of, however the system was not known by the destination server at the moment when the user was configured for UBP enforcement.

  • At the point when the user was configured for UBP enforcement, the system was not known to the destination server or the user was not assigned to the system.

Resolutions

  • Run the DE: Force update for UBP enforcement users from the Server Tasks page in the destination server and wait for the task to complete. Then wake up the system to obtain the latest policies.

  • It is possible to use an automatic response to trigger the DE: Force update for UBP enforcement users when {x} number of events have been received, by using the event ID 30090. For more information, see the product documentation for your version of ePO - On-prem.

    Note

    {x} must be a level that your ePO - On-prem server can handle; numbers below 200 could cause scalability issues on both ePO - On-prem and AD servers due to the number of policies that might need to be recalculated.

User cannot logon to a system that they were assigned to after transfer completes

This can occur because the transferred system user data is sent on the subsequent policy enforcement and the user has already been assigned to another system during that period in the context of the destination server.

In this scenario, the user will be treated as an uninitialized user and the default password could be used (if the user has been configured to use a password token). However, if the default password is used, the latest user data will overwrite any existing user data.

User is prompted to enter a new password

This can occur because the transferred system user has been assigned to another system before the migrated system has sent the user data to destination server and UBP has been configured to 'Do not prompt for default password'.