The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

User-based policy settings

Prev Next

The user-based policy settings are organized into these tabs: Authentication, Password, Password Content Rules, Self-Recovery, and Companion Devices.

Authentication tab

Option

Definition

Token type

The authentication token type, for example, password or smartcard.

Certificate rule

Drive Encryption enhances the use of PKI and tokens to allow users to authenticate using their certificates. You can use certificate rules to quickly make your Drive Encryption enterprise aware of all certificate-holding users, and allow them to be allocated to PCs using Drive Encryption without having to create new smart cards or other forms of token for their use.

  • Provide LDAP user certificate — This provides the latest LDAP user certificate.

  • Enforce certificate validity period on client — By default, this is enabled to enforce certificate validity period for the added certificate rule.

  • Use latest certificate — This uses the latest certificate available.

Logon Hours

The days and the hours when the user can log on to the client system. The restrictions are applied using the Apply Restrictions option.



Password tab

Option

Definition

Default password

Change default password — For new installations or duplicates of the Trellix default installation, the default password is 1234567. There is a minimum character length of 7 characters for the default password. If you are upgrading, the password remains unchanged. If the administrator changes the default password, the new password becomes the default password for this policy under the User Based Policy category.

  • Do not prompt for default password — Skips the default password entry and immediately asks the user to enter an encryption password.

Password change

  • Enable password history__changes (1-100) — This keeps track of the specified number of previous passwords set by the user and does not allow the user to set previous passwords again.

  • Prevent change — This option prevents the user from changing the password.

    • Require change after__days (1-366) — The number of days after which the system prompts the user to change the password.

    • Warn user__days before password expires (0-30) — The number of days in advance that the system prompts the user with a warning message about the number of days left for the password expiry.

Incorrect passwords

  • Timeout password entry after__invalid attempts (3-20) — The number of invalid password entries after which the system times out the password attempts.

    • Maximum disable time__minutes (1-64) — The maximum timeout duration for the timeout password entry.

  • Invalidate password after__invalid attempts (3-100) — The number of wrong attempts a user can make before the password becomes invalid.

Allow showing of password

Enable this option to display the password of the user while entering it.



Password Content Rules tab

Option

Definition

Display list of password rules

Enable this option to display the password requirements to users.

Password length

The number of characters in a user password.

  • Minimum (3-40) — The minimum number of characters for a user password.

  • Maximum (3-255) —The maximum number of characters for a user password.

Enforce password content

The number of different characters like alpha, numeric, alphanumeric, and symbols that are required to form a password.

  • Alpha — The number of letters that must be present in a user password.

  • Numeric — The number of numeric characters that must be present in a user password.

  • Alphanumeric — The number of alphanumeric characters that must be present in a user password.

  • Symbols — The number of symbols that must be present in a user password.

Password content restrictions

The password content restrictions for the user password.

  • No anagrams — A word or phrase spelled by rearranging the letters of a previous password can't be a password.

  • No palindromes — A word or phrase that reads the same backward as forward can't be a password.

  • No sequences — The new password can't be in sequence with the previous password.

  • Can't be user name — A user name can't be set as a password.

  • Simple content rules — Follow the standard Windows password content rules; a Windows password should contain at least three of the following:

    • Lowercase letters

    • Uppercase letters

    • Numbers

    • Symbols and special characters

  • No simple words — The set of words defined as simple words that cannot be used as passwords.



Self-recovery tab

Option

Definition

Enable self-recovery

Enables self-recovery for users assigned to the system.

Invalidate self-recovery after no. of invalid attempts

The number of attempts after which self-recovery is disabled.

Questions to be answered

The number of questions to be answered by the user to perform the self-recovery.

This lists the default questions for the selected language, also provides an option to add more questions.

Note

If a language does not have enough questions or includes an error, the language appears in red.

Logons before forcing user to set answers

The number of logons before forcing the user to set answers.

Questions

Allows you to select a language, set the question, and set the minimum answer length. This lists the default questions for the selected language, and provides an option to add more questions.

Note

If a language does not have enough questions or includes an error, the language appears in red.



Companion Devices tab

Option

Definition

Recovery

Enable this option to allow the user to perform system recovery through smartphone.

Note

The Companion Device application is now known as Trellix Endpoint Assistant.

Password Definition

Enable this option to create a password according to the option selected.

Note

If the user has once set a higher password definition to the system, the user cannot change the password to a lower password definition (that is less secure) even if that policy is set in Trellix ePO - On-prem.