Trellix Drive Encryption - SaaS 8.1.2602 Release Notes

Prev Next

The Trellix Drive Encryption - SaaS 8.1.2602 release includes new features and resolved issues.

Trellix Drive Encryption - SaaS Release details

Release date - June 1, 2026 (Republished to include a default minimum password length in the Password Content Rules)

Every update release is cumulative and includes all features and fixes from the previous release.

Trellix DE - SaaS includes the following product:

Product

Supported version

Trellix DE - SaaS for Windows

8.1.0.22

For more information about Trellix Drive Encryption - SaaS, see the Trellix DE - SaaS Product Guide.

For more information about release dates and build numbers, see Trellix Drive Encryption - SaaS product release information section in 000014091.

Updated platform, environment, or operating system support

For complete system requirements, see supported platforms for Trellix Drive Encryption - SaaS in 000014091.

New features and changes

This release includes support for the following enhancements and changes:

Enhancement of Trusted Platform Module (TPM) autoboot sensitivity — Trellix DE - SaaS 8.1.0 introduces the ability to select which Platform Configuration Registers (PCRs 0 to 7) that have to change before forcing the manual entry of a password. This provides greater flexibility in how the Trusted Platform Module (TPM) functions for automatic booting. This enhancement supports TPM versions 1.2 and later.

Simplified TPM autoboot upgrade and deployment — This release enables you to switch to TPM autoboot without requiring authentication during pre-boot. This allows for a frictionless upgrade across endpoints with no end-user interaction, simplifying deployment and saving time and resources by eliminating the need to educate users on pre-boot steps. For more information, see KB79784.


Addition of Threat Event for Drive Encryption Activation Failures due to insufficient space in ESP — This release introduces a Drive Encryption Threat Event that allows administrators to view Drive Encryption activation or Bootcode upgrade failures caused by insufficient space in the EFI System Partition (ESP). For more information, see KB84622.

Drive Encryption GO (DEGO) — Starting with the Trellix DE - SaaS 2412 release, DEGO is no longer supported in SaaS environments. You should not depend on the DEGO Health Check for Drive Encryption activation. For those migrating from On-Premise to SaaS, it is necessary to unlink the DEGO Health Check during activation and recommended to uninstall DEGO from all endpoints prior to migration.

Support Federal Information Processing Standards (FIPS) — Trellix DE - SaaS now supports FIPS in ePO - SaaS. For public sector customers and other regulated industries that mandate FIPS 140-2, Trellix DE - SaaS backend services use FIPS cryptographic modules. For more information, see KB83483.

Drive Encryption Recovery API support — This release introduces the Drive Encryption Recovery API, enabling administrators to securely perform API-based challenge/response recovery for end users. Integration of this API with the Trellix Developers Portal enables recovery operations for specific endpoints, eliminating the need to directly access ePO - SaaS.

For more information, see Use Drive Encryption Recovery API to recover systems in the Trellix DE - SaaS Product Guide.

Update to the default minimum password length in the Password Content Rules — The minimum password length for User Based Policies is now 7 characters (previously 3) to support an upcoming FIPS 140-3 upgrade. Existing passwords remain valid, but the new 7-character minimum will be enforced during the user's next password change.

Resolved issues

This release resolves known issues.

Category

Reference

Resolution

User Interface

TDE-9967

Drive Encryption Quick Settings no longer fails to open after deployment of the client package and before the system was rebooted.

Fixes to features

TDE-10326

Fixed an issue where Key Encryption Key (KEK) related messages were shown in the client log, even when the corresponding Product Settings policy was disabled.

Interoperability

TDE-10345

Fixed an issue where the EnableMPR registry key was deleted by Drive Encryption, which caused third-party software that uses this registry to fail.

User Interface

TDE-10446

When the accessibility and logon managed autoboot is enabled, users now hear a beep when the Pre-Boot Authentication (PBA) dialog pops up after reaching the maximum failed Windows logon attempts. For the new beep code, see KB69853.

Interoperability and Installation

TDE-10657

This release prevents activation on systems with Windows Fast Startup enabled to ensure a stable Drive Encryption environment. For more information, see KB77144.

User Interface

TDE-10677

The system beep used for accessible interface navigation in pre-boot is adjusted to provide a more gentle experience.


Known issues

For details about Trellix Drive Encryption - SaaS known issues, see 000014092.