The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Add Active Directory servers

Prev Next
  1. Go to, Manager → <Admin Domain Name> → Setup → Intrusion Prevention → Active Directory Servers.

  2. Click GUID-E7BA235E-C8E9-494B-A481-32F301FEAAB8-low.png.

    Add an Active Directory Server
    Add an Active Directory Server


    Note

    When the Active Directory Servers tab is accessed from child admin domains, the Inherit Settings? option is available. The GUID-E7BA235E-C8E9-494B-A481-32F301FEAAB8-low.png button is visible only if you deselect Inherit Settings?.

  3. In Add Active Directory Server window, enter the AD server details in the appropriate fields:

    Option

    Definition

    Server IP Address

    Enter the IPv4 or IPv6 address of the Active Directory server.

    DNS Domain Name

    Enter the Active Directory domain name, like Trellix.com.

    NetBIOS Domain Name

    Enter the NetBIOS domain name of the Active Directory; for example, Trellix.

    Decryption Enabled

    Select this option if you want to enable SSL connection for secure data communication.

    Server Port

    The Active Directory server port. If you select Decryption Enabled, the port automatically changes to the default value, 636. Else the default value is 389.

    Start Search from the Root of the Base Directory?

    Select this option if you want Trellix IPS to check user information from the root node of the Active Directory tree. When you select this option, the value of the next field Base DN is displayed as Root, by default.

    Base DN

    Base DN represents the intermediate node name in the Active Directory tree. If you want Trellix IPS to check user information from an intermediate node in the Active Directory tree, enter the corresponding node name in Base DN.

    User Name

    Active Directory login name for the domain.

    Password

    Password for the Active Directory login.

    Test Connection

    Click to test whether the connection with the configured Active Directory Server is working fine. If the connection is successful, a message is displayed for the same.

    Save

    Saves the configuration in the Manager database.

    The Manager attempts to verify the details that you provided before creating the record. Even if the Manager is unable to verify the details currently, you can go ahead and create the record. The added Server is listed in the Active Directory Servers list.

    Notes:

    • In Active Directory Servers list, if the configuration needs to be inherited to the child admin domains, you can optionally check Make Settings Visible to Child Admin Domains? option.

    • You are prompted to add the Active Directory server that you created to the list of trusted domain controllers automatically.

    • If you configure multiple Active Directory servers, the Manager considers them in a top-down fashion. If two servers from the same domain are listed, the second is only consulted if the one above it cannot be reached.