The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Configuration of Administrative Domains

Prev Next

An administrative domain, or admin domain for short, is an organizational tool used specifically to group Trellix IPS resources so you can delegate resource management to specific users. An admin domain can contain other admin domains, Devices, and Device interfaces.

Administrative domains enable enterprises to create a central authority that is responsible for the overall Trellix IPS system, and to allow the central authority to delegate day-to-day security operations to the appropriate entities, such as business units, geographic regions, and individual security personnel.

The top level admin domain is called the root admin domain. Users with Super User access to the root admin domain have complete control over the entire administrative domain and all resources within it, including any child domains, and thus all security resources in the system. To delegate management functions to entities within your organization, you would create a sub domain (of the root or other parent domain) representing each entity or department. These sub-domains are called child admin domains or child domains.

In Trellix IPS Manager, the functions that you can perform at the admin domain level are as follows:

  • Configuring and managing admin domains: enables you to view details of admin domains and create child admin domain

  • Managing users and user roles: enables the creation of users for various administrative functions

  • Viewing system information logs: enables a privileged admin to create audits and logs to view system information

  • Setting up fault notifications: allows you to send system fault information to third-party machines such as SNMP servers and Syslog servers.