The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Install Trellix Agent 5.8.x on Windows using Group Policy Object

Prev Next

You can configure a third-party tool such as Microsoft Group Policy Objects (GPO) to distribute the Trellix Agent installation package available on ePO - On-prem.

  1. Download Framepkg.exe from ePO - On-prem to a shared folder on a network server, where all systems have permissions.

  2. Execute this command:

    Framepkg.exe /gengpomsi /SiteInfo=<sharedpath>\Sitelist.xml /FrmInstLogLoc=<localtempDir>\<filename>.log

    The following files are extracted to your local drive.

    • MFEagent.msi

    • Sitelist.xml

    • srpubkey.bin

    • reqseckey.bin

    • agentfipsmode

    • sr2048pubkey.bin

    • req2048seckey.bin

  3. Copy the extracted files to a shared UNC location specified in siteinfo path.

  4. Create a Group Policy Object. (See Microsoft documentation for instructions).

  5. Click Computer Configuration → Policies → Software Settings.

  6. Right-click Software installation, then click New → Package.

  7. When prompted for a package, browse to the shared UNC path, then select MFEAgent.msi.

  8. Select the Deployment Method as Assigned.

Note

Trellix Agent does not support per-user installations.