The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Windows Hello authentication

Prev Next

Windows Hello provides end users with simple authentication (PIN, fingerprint, face, security key, picture password). It helps to strengthen your protections against credential theft. Because an attacker must have both the device and the biometric information or PIN, it's much more difficult to gain access without the user's knowledge. For more details on Microsoft Windows Hello, see Windows Hello overview.

Drive Encryption now uses passwords and smartcards for its Windows credential provider features like Single Sign-On, password synchronization, and logon-managed autoboot. Since Windows Hello authentication mechanisms like fingerprint and PIN are not integrated into Trellix DE, its credential provider features will not function when Windows Hello is enabled for Windows logon authentication.

By default, Windows Hello authentication is allowed by the Trellix DE credential provider. But Trellix DE credential provider features like Single Sign-On, Password synchronization, or Logon-managed autoboot will not function when Windows Hello credential providers are used. If the users want the DE credential features, they can disable Windows Hello providers in Product Settings | Log On | Windows Hello authentication.