Last Updated: September 17, 2023
FileVault product settings
The product policies provide you with the settings that are required for FileVault management, password settings, and client messaging.
Option definitions
Manage FileVault — Allows you to manage FileVault and receive reports from the client system.
Turn On (Enable) FileVault — When enforced, will turn on FileVault on client systems if not already enabled and then manage accordingly. The client systems also report the status to Trellix ePO - On-prem. When you turn on FileVault and enforce this policy to the required client systems, users will see a pop-up message on their client systems requesting that they restart the system. The user must restart the system to enable FileVault to encrypt the system managed by Trellix ePO - On-prem, or choose to postpone the restart until a more convenient time.
Destroy FileVault key in standby mode — The FileVault recovery key will be removed from memory when a system goes into a standby mode. This defends against memory related attacks during various sleep states. Resuming from the sleep mode will force a user authentication to bring the key back into memory.
Generate a new FileVault key in days (1-360) — Enable this option and specify how frequently the recovery key is to be rotated. This improves security by reducing the validity period of each individual recovery key.
Allows users to import recovery key on client — Enable this option to allow users to import the recovery key on client systems. This is useful if end users use the FileVault application to generate new recovery keys.
Prompt user to create a new recovery key on already enabled systems — If FileVault is already enabled by the user when MNE policy is enforced, the client system will prompt the user to authenticate using their FileVault password. Once authenticated, the recovery key of the client system can be queried from FileVault and will be escrowed to the Trellix ePO - On-prem database.
Note: If users ignore this request, then recovery of their system cannot be achieved as no recovery key can be escrowed to Trellix ePO - On-prem; FileVault will only release the current recovery key if authentication is provided.
Only enable FileVault if DEGO tests pass — If the user has installed the Drive Encryption GO (DEGO) - OSX 2.1.0.xxx on the Mac client system, then FileVault will be enabled only if DEGO tests pass.
Note: Make sure that you have already installed EEGO.zip (DEGO extension) before enabling this option. For more information about the DEGO extension, see the Trellix Drive Encryption Product Guide.
Restart timeout period in minutes (1-60) — Defines the length of the restart timeout period.
Turn Off (Disable) FileVault — When enforced, will turn off FileVault on client systems. Client systems status will continue to be reported in Trellix ePO - On-prem.
Note: On enabling this option, the Password Settings and Client Messaging functions get disabled.
Do not manage FileVault — When enforced, MNE will not manage FileVault.
Report client system status — When enforced, MNE will not manage FileVault, but will report FileVault status and security posture data to Trellix ePO - On-prem allowing you to manage FileVault with a third party management tool, yet report status within Trellix ePO - On-prem. This can be useful to report on BYOD (Bring Your Own Device) or contractor laptops to monitor compliance to company encryption policies.
If FileVault is managed by MNE, or if report-only mode is selected, the client system reports the following information to Trellix ePO - On-prem:
FileVault status
FileVault mode
System information
System encryption status
FIPS status
Apply password content rules — Allows you to set password settings on to OS X, which will enforce these password settings on the client system.
Minimum length (4-40) — The user must create a password of the specified minimum length.
Maximum length (4-255) — The user must create a password of the specified maximum length.
Require at least one alphabetic character in password — The user must include at least one alphabetic character in creating the password.
Require at least one numeric character in password — The user must include at least one numeric character in creating the password.
Require password change after days (1-180) — The user must change the password after the specified number of days.
Do not apply password content rules to these users (separate users with a semi-colon, for example, user1; user2) — Type the username (short name) of users to make sure the password settings do not apply to the specified users.
Display the following message, instead of the default, when enabling FileVault — The user receives this message when FileVault is enabled. If left empty, a default message will be provided.
Display the following login banner — Enable this option and provide a login banner for the user to receive this leogin banner after authenticating into FileVault.
Display the following message, instead of the default, when FileVault has been disabled by 3rd party tapplication or user — The user receives this message if FileVault is disabled by anything other than MNE. If left empty, a default message will be provided.
BitLocker product settings
The product policies provide you with the settings that are required for BitLocker management, operating system volume, and authentication settings.
Option definitions
Option | Definition |
Show/Hide Advanced | Clicking this will show or hide advanced settings within the policy page. All policy options have suitable defaults for those that do not want to define advanced settings. |
BitLocker management |
Note: Make sure to note that the encryption strength can't be changed on a previously encrypted client. To change the encryption strength, BitLocker needs to be decrypted, disabled, and then re-enabled by MNE.
|
BitLocker on client systems to use XTS-AES-128 algorithm for encryption. Note: This algorithm is supported on Windows 10 and above systems only. Older systems will fall back to the AES-128 algorithm.
Note: This algorithm is supported on Windows 10 and above systems only. Older systems fall back to the AES-256 algorithm.
(1-360) — Enable this option and specify how frequently the recovery key is to be rotated. This improves security by reducing the validity period of each individual recovery key.
|
Option | Definition |
If BitLocker is managed by MNE, or report-only mode is enabled, the client system reports the following information to Trellix ePO - On-prem:
Note: BitLocker protection is suspended when the administrator alters the policy to change protector on operating system drive during switch-over period. Otherwise, if switching authentication method, the endpoint is unprotected until the new authentication method is fully applied.
|
Option | Definition |
| |
System authentication |
— Allows you to use the TPM authentication method to protect the operating system volume for TPM |
Option | Definition |
supported client systems.
supported — Allows you to use an enhanced PIN as additional security for TPM supported client systems. Note: It is recommended to enable the hardware test option under BitLocker advanced settings to make sure pre-boot supports enhanced PINs.
Note: If the Use Trusted Platform Module (TPM), Also use PIN, and Fall back to Password if no TPM is available (Windows 8 and above) options are all enabled and the current protector is the passphrase protector, then the client system is compliant to the policy.
|
Option | Definition |
| |
Authentication Settings | Minimum pin length (4-20) — Enter the minimum PIN length from 4 to 20 that you would like to set for the PIN number. Minimum password length (8-99) — Enter the minimum password length from 8 to 99 that you would like to set for the password. Maximum number of times user can postpone activation (1-10) — Enable this option and enter the maximum number of times from 1 to 10 to postpone activation. |
End user messaging | Provide a custom URL for the BitLocker recovery screen in preboot (Windows 10 and above) — Enable this option to enter a custom URL that will |
Option | Definition |
appear in the pre-boot BitLocker recovery screen on Windows 10 systems. The user needs to copy this URL on a web page of another system for information about retrieving the recovery key. Recovery URL — Enter the URL that will appear in the pre-boot BitLocker recovery screen. | |
BitLocker advanced settings | You can choose to enable, disable, or not manage the following options:
Note: Make sure that the user restarts the client system after it's encrypted. The system will not start encrypting until a successful hardware test is completed. This makes sure that systems that do not support BitLocker because of hardware compatibility issues can be easily recovered after they fail to boot.
|
Option | Definition |
Note: Sensitive data that was previously deleted from the file system may not be protected, as not all sectors are protected.
|
Option | Definition |
software encryption if a self-encrypting drive is not available. Used in combination with the parent option, this allows a preference to be stated for self-encrypting drives. | |
Duplicate | Duplicates or copies the policy settings with a different name and this can be assigned to a different user. |
Save | Saves the product settings policy of MNE. |
Cancel | Exits the current page. |
Security Posture Report settings
Security posture reporting allows you to report the endpoints that meet your required security posture settings for your organization.
The security posture report settings allow you to define the criteria for securing endpoints. This policy has no effect on the management of the endpoint; it simply defines the tests that the endpoints run to assure its data protection security posture.
Each specific posture test passes unless there is a specific reason for failing. For example, a system without data volumes passes all data volume tests, because there are no data volumes to fail. This reporting is primarily designed to report failures against specific criteria.
Note: You can view the overall result of security posture reporting tests by navigating to Menu → Systems → System Tree → systems. Select the required system, then click Native Encryption → Security posture reporting.
Option definitions
OS Volume — Enable this option to test the OS volume against the selected criteria.
Data Volume(s) — Enable this option to test data volumes against the selected criteria.
Note: If the system doesn't have data volumes, the data volume tests will pass each of the posture tests.
Used space on selected volumes(s) should be fully encrypted (recommended) — Enable this option to report that the system is secure only if the used space on the selected volume types is fully encrypted.
Selected volumes require authentication (recommended) — Enable this option to report that the system is secure only if the selected volume types require user authentication, network unlock, or TPM authentication.
Selected volume(s) should use a minimum encryption strength of: — Enable this option to report that the system is secure only if the selected volume types use at least:
AES-128 — Can use AES-128 or AES-256.
Note: Systems that are activated with higher strength algorithm AES-256 and Security Posture set to Algorithm AES-128 displays as pass.
AES-256 — Must use AES-256.
Selected volume(s) should be FIPS-compliant — Enable this option to report that the system is secure only if the selected volume types are FIPS-compliant. (Note: Systems that were activated prior to being managed by MNE cannot be verified as FIPS compliant)
Duplicates - Duplicates or copies the security posture settings with a different name.
Save - Saves the security posture settings policy of MNE
Exit - Exits the current page.
System recovery
The Enter serial number (FileVault) or recovery key ID (BitLocker) pane allows you to type the serial number of the client system to receive the recovery key of that client system.
Option definitions
Option | Definition |
Serial number (FileVault) or recovery key ID (BitLocker) | Type the serial number or recovery key ID of the client system that you received from the user. |
Back | Navigates to the previous page. |
Next | Navigates to the next page. |
Cancel | Exits the current page. |
Recovery key
The Recovery key from serial number/ recovery key ID pane allows you to view the recovery key to send it to the user.
Option definitions
Option | Definition |
Recovery keys | Displays the response code and the codes are phonetically arranged in the table. |
Can't find your key? Search for it here. | Allows you to search for your key, if you are unable to find your key. |
Close | Exits the current page. |
Import recovery key
You must manually import the recovery key of the client system to the Trellix ePO - On-prem database using the Data Protection or System Tree menu.
Data Protection menu
Option | Definition |
Enter serial number | Type the serial number of the client system that you received from the user. |
Enter recovery key | Type the recovery key of the client system that you received from the user. |
Ok | Imports the recovery key of the client system to the Trellix ePO - On-prem database. |
Cancel | Exits the current page. |
System Tree menu
Option | Definition |
Enter recovery key | Type the recovery key of the client system that you had selected. |
Ok | Imports the recovery key of the client system to the Trellix ePO - On-prem database. |
Cancel | Exits the current page. |
MNE server settings
Enable rotating the recovery keys when the system recovery is performed through MNE recovery pages and DPSSP.
Option | Definition |
Recovery is performed through MNE recovery pages | Enable this option to rotate the recovery keys when the recovery is performed through MNE recovery pages. |
Recovery is performed through Data Protection Self Service Portal | Enable this option to rotate the recovery keys when the recovery is performed through DPSSP. Note: Key rotation after the recovery process is not available for Mac OS X systems. |
Revealed through web API | Enable this option to reveal the rotated recovery keys through web API. |
Automatic (network) unlock of volumes for system under | Click Edit network rule, select whether you wish to grant or deny access for systems in this branch by selecting GRANTED or DENIED respectively, then click Apply. Browse through the System Tree View, select the required system or group, and click OK. |
Add rule | Click to add the rule selected. |
Save | Saves the server settings for MNE. |
Cancel | Exits the current page. |