The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Upgrade systems with TPM autoboot policy enabled

Prev Next

On upgrading the client to Drive Encryption 7.4.x, the user will be prompted to authenticate in preboot due to boot measurement changes caused by the upgrade process. Without intervention, the Help Desk calls may be generated as users attempt to log back onto their systems after the upgrade, as TPM autoboot users may not know their preboot usernames or passwords, or no users may be assigned to the system.

ePO - On-prem administrators should take proactive actions to mitigate the potential problem using one of the following approaches:

Method 1 — Enable normal autoboot through policy before sending the upgrade task to systems that are running with TPM autoboot policy enabled. The normal autoboot policy can be disabled/revoked by the ePO - On-prem administrator after the systems report a successful upgrade to Drive Encryption 7.4.x.

Method 2 — Enable temporary autoboot for two restarts prior to upgrading systems that are running with TPM autoboot policy enabled. This will ensure that new boot measurements are made following the upgrade, and that preboot will not be displayed.

  1. Enable temporary autoboot through policy.

  2. Enable temporary autoboot on each TPM autoboot endpoint with "--number-of-reboots 2" on an active 7.x.x client.

    Temporary autoboot is now successfully set.

    Note

    It is recommended that 2 instances of temporary autoboot are set to allow the boot code to be synced.

  3. Deploy Drive Encryption 7.x.x EEAgent and EEPC.

  4. Restart the client when prompted. (This will use insecure temporary autoboot.)

  5. On the next restart of the client, the temporary autoboot will again be exercised.

  6. For any subsequent restarts, secure TPM autoboot will be reinstated.

    Important

    Whilst temporary autoboot is enabled, the system is not secure.