The Trellix Drive Encryption - SaaS 8.1.2602 release includes new features and resolved issues.
Trellix Drive Encryption - SaaS Release details
Release date - June 1, 2026 (Republished to include a default minimum password length in the Password Content Rules)
Every update release is cumulative and includes all features and fixes from the previous release.
Trellix DE - SaaS includes the following product:
Product | Supported version |
|---|---|
Trellix DE - SaaS for Windows | 8.1.0.22 |
For more information about Trellix Drive Encryption - SaaS, see the Trellix DE - SaaS Product Guide.
For more information about release dates and build numbers, see Trellix Drive Encryption - SaaS product release information section in 000014091.
Updated platform, environment, or operating system support
For complete system requirements, see supported platforms for Trellix Drive Encryption - SaaS in 000014091.
New features and changes
This release includes support for the following enhancements and changes:
Enhancement of Trusted Platform Module (TPM) autoboot sensitivity — Trellix DE - SaaS 8.1.0 introduces the ability to select which Platform Configuration Registers (PCRs 0 to 7) that have to change before forcing the manual entry of a password. This provides greater flexibility in how the Trusted Platform Module (TPM) functions for automatic booting. This enhancement supports TPM versions 1.2 and later.
Simplified TPM autoboot upgrade and deployment — This release enables you to switch to TPM autoboot without requiring authentication during pre-boot. This allows for a frictionless upgrade across endpoints with no end-user interaction, simplifying deployment and saving time and resources by eliminating the need to educate users on pre-boot steps. For more information, see KB79784.
Addition of Threat Event for Drive Encryption Activation Failures due to insufficient space in ESP — This release introduces a Drive Encryption Threat Event that allows administrators to view Drive Encryption activation or Bootcode upgrade failures caused by insufficient space in the EFI System Partition (ESP). For more information, see KB84622.
Drive Encryption GO (DEGO) — Starting with the Trellix DE - SaaS 2412 release, DEGO is no longer supported in SaaS environments. You should not depend on the DEGO Health Check for Drive Encryption activation. For those migrating from On-Premise to SaaS, it is necessary to unlink the DEGO Health Check during activation and recommended to uninstall DEGO from all endpoints prior to migration.
Support Federal Information Processing Standards (FIPS) — Trellix DE - SaaS now supports FIPS in ePO - SaaS. For public sector customers and other regulated industries that mandate FIPS 140-2, Trellix DE - SaaS backend services use FIPS cryptographic modules. For more information, see KB83483.
Drive Encryption Recovery API support — This release introduces the Drive Encryption Recovery API, enabling administrators to securely perform API-based challenge/response recovery for end users. Integration of this API with the Trellix Developers Portal enables recovery operations for specific endpoints, eliminating the need to directly access ePO - SaaS.
For more information, see Use Drive Encryption Recovery API to recover systems in the Trellix DE - SaaS Product Guide.
Update to the default minimum password length in the Password Content Rules — The minimum password length for User Based Policies is now 7 characters (previously 3) to support an upcoming FIPS 140-3 upgrade. Existing passwords remain valid, but the new 7-character minimum will be enforced during the user's next password change.
Resolved issues
This release resolves known issues.
Category | Reference | Resolution |
|---|---|---|
User Interface | TDE-9967 | Drive Encryption Quick Settings no longer fails to open after deployment of the client package and before the system was rebooted. |
Fixes to features | TDE-10326 | Fixed an issue where Key Encryption Key (KEK) related messages were shown in the client log, even when the corresponding Product Settings policy was disabled. |
Interoperability | TDE-10345 | Fixed an issue where the EnableMPR registry key was deleted by Drive Encryption, which caused third-party software that uses this registry to fail. |
User Interface | TDE-10446 | When the accessibility and logon managed autoboot is enabled, users now hear a beep when the Pre-Boot Authentication (PBA) dialog pops up after reaching the maximum failed Windows logon attempts. For the new beep code, see KB69853. |
Interoperability and Installation | TDE-10657 | This release prevents activation on systems with Windows Fast Startup enabled to ensure a stable Drive Encryption environment. For more information, see KB77144. |
User Interface | TDE-10677 | The system beep used for accessible interface navigation in pre-boot is adjusted to provide a more gentle experience. |
Known issues
For details about Trellix Drive Encryption - SaaS known issues, see 000014092.