The Trellix Drive Encryption 8.1.1 release includes new features and resolved issues.
Every update release is cumulative and includes all features and fixes from the previous release. We recommend that you always upgrade to the latest version.
Important
Before installing the Trellix Drive Encryption 8.1.1 client package, administrators must update the Secure Boot database with "Microsoft UEFI CA 2023" and "Microsoft Option ROM UEFI CA 2023" on all Windows 10 and above systems. If the UEFI secure boot database is not updated with CA 2023 signature, the upgrade to Trellix Drive Encryption 8.1.1 will intentionally abort. For more information, see articles 000015304 and 000015311.
For customers also using Trellix Native Drive Encryption, prior to initiating any Secure Boot certificate updates, we strongly recommend that you verify that recovery keys are accessible in every system. Customers may be impacted by a known issue when a cloud native identity management system is in use on the endpoint, such as Entra ID (Azure AD). Endpoints with only Active Directory users are not affected. Key availability can be verified in ePO. For more details, see article 000015395.
Trellix Drive Encryption - On-premise release details
Release date - March 25, 2026
For more information about release dates and build numbers, see Trellix Drive Encryption product release information section in article KB79422.
Rating
The rating defines the urgency for installing this update.
Critical
This update is critical for all environments. Failure to apply critical updates might result in severe business impact.
Product compatibility
This release supports:
Trellix ePolicy Orchestrator - On-premises — 5.10.0 SP1 or later.
Trellix Agent — 5.8.0 or later.
Upgrade support
For complete system requirements, see supported platforms for Drive Encryption 8.x in article KB79422.
New features and changes
This release includes the following new features and changes:
Support for Microsoft UEFI CA 2023 and Microsoft Option ROM UEFI CA 2023 — This release enables compatibility with the Microsoft UEFI CA 2023 and Microsoft Option ROM UEFI CA 2023. As the legacy 2011 Secure Boot certificates reach their scheduled expiration in June 2026, Microsoft is transitioning to these new 2023 standards. This update ensures that Drive Encryption managed systems remain capable of verifying future Windows boot components and maintaining a supported security state. For more information, see articles 000015304 and 000015311.
Resolved issues
This release resolves known issues.
Category | Reference | Resolution |
|---|---|---|
Interoperability | TDE-10700 | Fixed an issue where Trellix Management of Native Encryption 5.2.x failed to detect an active Drive Encryption 8.x installation, causing the system to be encrypted twice. |
Fixes to feature | TDE-10988 | Fixed an issue where the Self Protection rule blocked the DEGO Service from writing to the Health registry, preventing successful Drive Encryption activation. |
Known issues
For details about Trellix Drive Encryption 8.x known issues, see article KB84502.