The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

User management — Permission sets

Prev Next

Use this page to define the permission sets for an Drive Encryption user.

Option

Definition

Drive Encryption

Policy Options

  • No permissions — The user has no permission to view/edit the Drive Encryption settings.

  • View policy settings — The user has permission only to view the product settings and user based settings.

  • Change and view policy settings — The user has permission to view and edit the settings and to perform recovery on the server.

User Management

  • No permission to user management — The user has no permission to view/edit the user management settings.

  • View user management — The user has permission only to view the user management settings.

  • Change and view user management — The user has permission to view and edit the user management settings.

    • Allow import of v5 users — This allows the administrator to import the v5 users into ePO server.

      • To view and delete users, the user should have the permissions to view and access the System Tree.

      • To add users, the user should have the permissions to browse through the LDAP server.

    • Allow configuration of UBP enforcement — Allows the administrators specify which groups of users are allowed to use Drive Encryption policy-assignment rules, and which need to inherit the UBP assigned to a system.

Recovery Options

  • Allow clear SSO — Allows the user to clear the SSO details.

  • Allow clear and reset self-recovery — Allows the user to clear the existing self-recovery details and reset them.

  • Allow force user password change — Allows the user to edit the force user password change option.

  • Allow reset token — Allows the user to reset the token.

  • Allow viewing of user recovery information — Allows the user only to view the user recovery information.

  • Allow administrator recovery — Allows the user to perform the administrator recovery.

  • Allow export of machine recovery information — Allows the user to export the system recovery information. To allow export of the machine recovery information, the user should also have the permissions to view the System Tree tab and access the System Tree.

  • Allow machine key re-use — This option supports any additional disk of the encrypted system to remain encrypted in case the system's boot partition becomes corrupted, damaged or wiped.

  • Allow destruction of machine recovery information — Allows the user to remove the complete machine recovery information from the Trellix ePO - On-prem server.

Query Options

  • Allow deletion of migration log items — Allows the selected user to delete the migration log items.

  • Allow deletion of migration cache items — Allows the selected user to delete migration cache items.

  • Allow deletion of v5 audit items — Allows the selected user to delete the v5 audit items.

Save

Saves the permission settings.

Cancel

Navigates to the previous page.