Management of Native Encryption - SaaS - Product Guide

Prev Next

Last Updated: September 17, 2023

Overview

Trellix Management of Native Encryption - SaaS is a management product that allows Trellix ePO - SaaS administrators to manage Apple FileVault and Microsoft BitLocker. These are products that provide full disk encryption on Macintosh (Mac) and Windows systems.

Note: This Product Guide contains information specific to Trellix MNE on Trellix ePO - SaaS. For information about Trellix MNE on Trellix ePO - On-prem, see the documentation for Trellix Management of Native Encryption.

With Trellix MNE - SaaS , you can perform these core functions from a central interface:

  • Manage Apple FileVault and Microsoft BitLocker

  • Report encryption status

  • Import, store, and retrieve recovery keys

Adopting Trellix MNE for BitLocker means that you no longer need to license, manage, or maintain Microsoft BitLocker Administration and Monitoring (MBAM) or its associated servers. You can consolidate servers and eliminate the related Microsoft licenses, providing significant cost savings and reduced management overhead.

Trellix MNE makes sure that you have consistent enforcement of policy and compliance across your encryption technology stack. You can also use the report-only feature of Trellix MNE without having to actively manage FileVault or BitLocker. Trellix MNE provides comprehensive reports that give you complete visibility of your organization's encryption status. Report queries can also be used as a dashboard monitor that is automatically updated every 5 minutes.

Note: We provide support only for the Trellix MNE management solution, and not the underlying FileVault or BitLocker encryption technology. If you encounter any issues with FileVault or BitLocker technology, contact Apple for FileVault support and Microsoft for BitLocker support.

Key features

You can manage FileVault or BitLocker through Trellix MNE.

  • Manage FileVault on any Mac hardware that can run macOS directly from Trellix ePO - SaaS. For a list of supported macOS versions, see KB91980.

  • Manage BitLocker on Windows systems directly from Trellix ePO - SaaS, without the need for a separate Microsoft BitLocker Administration and Monitoring (MBAM) server. For a list of supported Windows versions, see KB91980.

  • Report compliance in various reports and dashboards.

  • Configure BitLocker To Go to manage removable media on BitLocker encrypted client systems.

  • Support FileVault and BitLocker recovery by using administrative recovery through the Trellix ePO - SaaS console.

  • Rotate recovery keys periodically, or after a recovery workflow occurs in Trellix ePO - SaaS.

  • Make sure that on Windows systems, when taking over BitLocker management, only Trellix MNE-managed keys remain, to avoid older (insecure) keys being accessible on the system.

  • Import recovery keys manually. This is needed for FileVault. (Mac systems only).

  • Report status on Trellix Endpoint Security (ENS) for Mac console (Mac systems only).

  • Protect and own your data by using your own AWS Customer Master Key (CMK) in Trellix ePO - SaaS.

How it works

Trellix MNE provides components that are installed on Trellix ePO - SaaS, and on all Microsoft Windows and Mac computers that you want Trellix MNE to manage.

The diagram shows Trellix MNE components and workflows that manage and report on encryption status for endpoints using BitLocker or FileVault.

  1. The Trellix ePO - SaaS administrator configures Trellix ePO - SaaS policies, runs Trellix ePO - SaaS queries and reports, and verifies the status of Trellix ePO - SaaS managed endpoints.

  2. The Trellix Agent package is deployed to the client systems. Trellix MNE is installed and activated on the endpoint. Policies are assigned to the client system.

  3. After successful Trellix MNE activation, the endpoint is protected by BitLocker, according to the applied authentication policy. Trusted Platform Module (TPM) provides platform authentication support, without the need for preboot authentication (PBA). All chosen authentication methods other than TPM require the user to authenticate before restarting the endpoint.

  4. Trellix MNE obtains the recovery key of the system and sends it to Trellix ePO - SaaS. This recovery key is needed to recover the system in situations where the system crashes, malfunctions, or has accessibility issues.

Product components

The Trellix MNE software packages are available on Trellix ePO - SaaS, if you have an Trellix MNE license. This allows Trellix MNE to be installed on client systems where you can apply policies received from Trellix ePO - SaaS.

Getting started with Trellix MNE on Trellix ePO - SaaS

To start using Trellix MNE on Trellix ePO - SaaS, you must first sign up for an Trellix ePO - SaaS account and activate it. For more information about creating an Trellix ePO - SaaS account, see Getting Started with Trellix ePO - SaaS

Once you log on to Trellix ePO - SaaS, you can access Trellix MNE if you have purchased an Trellix MNE license.

Migrating Trellix MNE to Trellix ePO - SaaS

You can migrate Trellix MNE 4.x and later from Trellix ePO - On-prem to Trellix ePO - SaaS.

Trellix Preboot and Network Unlock features are not supported in Trellix ePO - SaaS. During migration, if a node is protected by either Trellix Preboot or Network Unlock, the authentication type of that system changes in accordance to the configured policy. That is, the next available authentication type in the precedence order is enforced.

For example, consider that a system is configured using an on-premises policy with the authentication type Preboot TPM Password. After migration to Trellix ePO - SaaS, this changes to TPM Password. So, if an endpoint is protected by Preboot, you can see that the system after migration is protected by TPM.

The following options are available if your endpoints are protected either by Trellix Preboot or Network Unlock.

  • Replace Preboot and Network Unlock authentication with one of the authentication methods that is supported by Trellix ePO - SaaS. For example, TPM and PIN.

  • Migrate the endpoint as is, but expect that protection might be disabled on the first policy enforcement while the new authentication options are configured. In addition, users might be prompted to enter a password or PIN in accordance with the policy.

Note: Drive Encryption Go (DEGO) is not supported in Trellix ePO - SaaS. Make sure that DEGO is uninstalled from all endpoints before attempting migration.

Invite users to manage Trellix MNE (for use with Trellix ePO - SaaS)

As an administrator, you can add users and assign specific roles to them for using Trellix MNE.

Before you begin

Make sure that you have administrator permissions to use Trellix ePO - SaaS.

Task

  1. Log on to Trellix ePO - SaaS as an administrator.
  2. Select Menu → Configuration → Users & Roles.
  3. On the Users & Roles page, click Invite User.
  4. On the Invite new user page, type the first name, last name, and the email address of the user you want to invite.
  5. Click Invite.

Results

An invitation email is sent to the user with activation instructions. This email is valid for 7 days. Once you add the user, their names appear on the Users panel.

Assign roles to users (for use with Trellix ePO - SaaS)

You can limit or extend users' access to Trellix MNE by assigning or unassigning roles. All roles have specific permission sets. You can't assign or unassign roles for your own account.

Before you begin

Make sure that you have administrator permissions to use Trellix ePO - SaaS.

Task

  1. Log on to Trellix ePO - SaaS as an administrator.
  2. Select Menu → Configuration → Users & Roles.
  3. On the Users & Roles page, select a user from the Users panel.

The user details, assigned roles, and unassigned roles for the selected user appears on the right pane.

Select the required roles from the Unassigned Roles list.

The Roles panel lists the default roles.

  • Key Service: Manage master key registrations — Allows the user to manage and view master key registrations.

  • Key Service: View master key registrations — Allows the user to only view master key registrations.

  • Trellix Cloud Account Administrator — Allows the user to view, create, and change users and roles; user can also view subscriptions and update customer profiles. This role does not include the Key Service roles.

  • Trellix ePO - SaaS Administrator — Provides administrator permissions for Trellix ePO - SaaS and allows the user to:

    • View Automatic Responses and view response results in Server Task Log.

    • View Server Tasks and task results in Server Task Log.

      • View client tasks and policies in Trellix Agent.

      • View policies in McAfee® Data Exchange Layer (DXL).

      • View policies and change policies in Trellix Management of Native Encryption.

      • View Policy Assignment Rules.

      • View reports in Trellix Management of Native Encryption.

      • View Audit Log, Client Tasks, Dashboards, Queries & Reports, and Threat Event Log.

      • View properties, search, and import recovery keys in Trellix Management of Native Encryption.

      • View System Tree and Systems.

Click Save Changes.

Results

The selected roles now appear in the Assigned Roles list.

Create a role (for use with Trellix ePO - SaaS)

You can use the default permissions for key service and Trellix ePO - SaaS to create a customized role for your user.

Before you begin

Make sure that you have administrator permissions for Trellix ePO - SaaS.

Task

  1. Log on to Trellix ePO - SaaS as an administrator.
  2. Select Menu → Configuration → Users & Roles.
  3. On the Users & Roles page, click Add Role.
  4. Enter a name for the role.
  5. From the Key Services and Trellix ePO - SaaS drop-down lists, select the required permissions.

The selected permissions now appear in Assigned Permissions.

Click Save Changes.

Results

The newly created role appears in the Roles panel. You can now assign this role to selected users.

Delete users and roles (for use with Trellix ePO - SaaS)

You can remove all roles and users when they are no longer in use. The default roles can't be deleted.

Before you begin

Make sure that you have administrator permissions to use Trellix ePO - SaaS.

Task

  1. Log on to Trellix ePO - SaaS as an administrator.
  2. Select Menu → Configuration → Users & Roles.
  3. On the Users & Roles page, select the user or role that you want to delete.
  4. Click Delete, then click Confirm.

Results

The user or role is removed from the Users or Roles list.

Duplicate a role (for use with Trellix ePO - SaaS)

You can create a copy of an existing role and customize it as needed.

Before you begin

Make sure that you have administrator permissions to use Trellix ePO - SaaS.

Task

  1. Log on to Trellix ePO - SaaS as an administrator.
  2. Select Menu → Configuration → Users & Roles.
  3. On the Users & Roles page, select the role that you want to copy.
  4. Click Duplicate.

Results

A copy of the existing role is created. You can edit the role name, assign or unassign permissions, and save the role.

Managing master keys (for use with Trellix ePO - SaaS)

Trellix MNE supports data protection through a hierarchical key structure. Encryption keys are protected at the root level by a master key that is controlled by the customer and protected by customer credentials.

Note: This topic is only applicable for Trellix MNE on Trellix ePO - SaaS.

Trellix MNE works with several services to create a master key to protect your data.

  • Tenant Key Service (TKS) — An encryption key service on Trellix ePO - SaaS that provides a key to encrypt or decrypt data that can be protected using the Customer Master Key (CMK).

  • Amazon Web Services (AWS) — A cloud computing service from Amazon that provides on-demand computing platforms for individuals and organizations.

  • AWS Key Management Service (KMS) — An AWS-managed service that allows you to create customer master keys that can be used to protect your data.

  • AWS Customer Master Key (CMK) — An encryption key created by AWS Key Management Service (KMS).

How master keys work

Trellix MNE on Trellix ePO - SaaS is preconfigured with a default Trellix master key for encryption and decryption services to work with zero setup.

Trellix owns the AWS KMS where the default master key is provisioned and the same master key is shared among all customers.

Important: We recommend that you configure TKS with your own master key to enforce strict cryptographic separation between your data and the data of other Trellix customers. Using your own master key allows you to stay in full control of your data with the ability to revoke access at a moment's notice.

For information about creating your own master key, see Amazon Web Services documentation at: https://docs.aws.amazon.com/kms/latest/developerguide/create-keys.html

Create a Customer Master Key on AWS (for use with Trellix ePO - SaaS)

Creating your own Customer Master Key (CMK) on Amazon Web Services (AWS) gives you more control in keeping your data secure.

Before you begin

Make sure that you have an AWS account and a user account with appropriate permissions.

For more information about creating an AWS account, or about creating keys and users on AWS, see the AWS documentation.

Task
  1. Log on to the AWS Management Console.

  2. Select the required AWS region from the Region drop-down list.

  3. On the AWS Management Console homepage, use the Find Services field to search for and select the Key Management Service link.

  4. On the navigation pane, select Customer managed keys, then click Create Key.

  5. Add an alias and description for the key and click Next.

  6. [Optional] Add a tag key and a tag value to identify your CMK, then click Next.

Tags are key value pairs that identify and group resources in your AWS account. You can add any tags you think are useful.

  1. On the Define key administrative permissions page, specify any users who should have administrative permissions to the key and click Next.

Note: To prevent the selected administrators from deleting this CMK, deselect Allow key administrators to delete this key in the Key deletion section at the bottom of the page.

  1. On the Define key usage permissions page, do not define any key user permissions and click Next.

The access permissions for Trellix are set up through an assumable role. See Create an assumable role on AWS.

  1. To define key users and roles, select the Identity Access Management (IAM) users who are using this account, and click

Next.

10. Review or edit the policy and click Finish.

When the key is created, it appears in the Customer managed keys list.

What to do next

Before you can register your master key on Trellix ePO - SaaS, you must have your key ARN and create an assumable role.

  • On the Customer managed keys page, click Key ID or Alias to open the Key Details page. In the General Configuration section, make a note of the Amazon Resource Name (ARN) value displayed. ARN value is needed when registering your CMK on Trellix ePO - SaaS.

A sample ARN value looks like this: arn:aws:kms:eu-west-2:<account_id>:<key_id>. For example: arn:aws:us-east-1:123456789012:key/12345678-1234-1234-1234-123456789012

  • Create an assumable role on AWS.

Create an assumable role on AWS (for use with Trellix ePO - SaaS)

An assumable role is an Identity Access Management (IAM) identity that is used by a trusted identity such as Trellix. Trellix uses this role to access resources in your AWS account (for example, the CMK that you created on AWS). You must create an IAM role with permissions to access your CMK that Trellix can assume to protect your data before you register your CMK on Trellix ePO - SaaS.

Before you begin

    • You must have your CMK created on AWS.

    • You must have your Trellix ePO - SaaS tenant ID. This is included in the Welcome to Trellix email.

Task

  1. Log on to the AWS Management Console.
  2. Select Services → IAM.
  3. From the navigation pane, select Roles, then click Create role.
  4. On the Select type of trusted entity page, select Another AWS account and enter 307653271100 as the account ID of the Trellix AWS account.
  5. [Mandatory] Select Require external ID to add extra security to your role, and click Next: Permissions.

You must add your tenant ID as the external ID.

Important: When Trellix tries to assume the role, Trellix passes your tenant ID as the external ID. If you have entered an external ID that is different to your tenant ID, Trellix can't register your CMK with Trellix ePO - SaaS.

On the Attach permissions policies page, click Create policy, then select the JSON tab and paste the following snippet (replace <your_key_arn> with the ARN of the CMK that you created earlier):

{

"Version": "2012-10-17",

"Statement": [

{

"Action": [ "kms:Encrypt", "kms:Decrypt", "kms:ReEncrypt*", "kms:GenerateDataKey*", "kms:DescribeKey"

],

"Resource": "<your_key_arn>",

"Effect": "Allow"

}

]

}

Note: These permissions allow Trellix to encrypt and decrypt data using your CMK, but not provide permissions to add new keys or delete keys.

Click Review policy, then enter a policy name and click Create policy.

This navigates back to the list of all policies in IAM. You can search for the name of your policy to make sure it was created successfully.

Select the Create role tab.
On the Attach permissions policies page, choose the policy to attach to your new role and click Next:Tags.
[Optional] Add a tag key and a tag value to identify your CMK, then click Next: Review.

Tags are key value pairs that identify and group resources in your AWS account. You can add any tags you think are useful.

On the Review page, enter a name for the role and click Create Role.

This navigates back to the list of roles in IAM. You can refresh the list and search for the name of your policy to make sure it is created successfully.

What to do next

From the list of roles in IAM, search and select your role. On the Summary page of the role, make a note of Role ARN. This is needed while configuring your CMK on Trellix ePO - SaaS.

Register your master key (for use with Trellix ePO - SaaS)

To enable use of your AWS Customer Master Key (CMK) by Trellix MNE, you must first register your master key with Trellix ePO - SaaS.

Before you begin

Make sure that you have:

  • Key ARN for your master key on AWS.

  • Role ARN for the assumable role that you created on AWS.

Note: Trellix MNE uses a default key provided by Trellix until you configure your own master key.

Task

  1. Log on to Trellix ePO - SaaS as an administrator.
  2. Select Menu → Configuration → Settings.
  3. From the navigation pane, select Master Keys.
  4. Click Edit.
  5. On the Edit Master Keys page, select Actions → Register master key.
  6. On the Register master key dialog box, enter your Key ARN, Role ARN, and an optional description.
  7. Click OK.

Results

Your master key is now registered and appears in the list of keys together with the default Trellix key. To start using your master key to protect your data, you must now activate it.

Activate your master key (for use with Trellix ePO - SaaS)

Unless otherwise configured, data is encrypted by the Trellix default key. You must activate your master key in order to change the encryption key to your own master key.

Before you begin

Make sure that you have registered your master key on Trellix ePO - SaaS.

Task

  1. Log on to Trellix ePO - SaaS as an administrator.
  2. Select Menu → Configuration → Settings.
  3. From the navigation pane, select Master Keys.
  4. Click Edit.
  5. On the Edit Master Keys page, select Actions → Set master key as active.

Results

The Status column for the master key now shows Active.

Revoke master keys (for use with Trellix ePO - SaaS)

You can remove a master key from the Server Settings page if it's no longer needed.

Before you begin

Make sure that your registered AWS master key on Trellix ePO - SaaS is not active.

Note

The key can't be revoked if it is in the active state. The default Trellix key also can't be revoked.

Task

  1. Log on to Trellix ePO - SaaS as an administrator.
  2. Select Menu → Configuration → Settings.
  3. From the navigation pane, select Master Keys.
  4. Click Edit.
  5. On the Edit Master keys page, select the checkbox next to the AWS master key.
  6. Select Actions → Revoke master key.

Results

The revoked master key is removed from the master keys list.

Master key settings (for use with Trellix ePO - SaaS)

You can access the Master keys page from Configuration Settings. Option definitions

Option

Definitions

Time to live

The maximum time that Trellix can decrypt your data without accessing your master key.

Changing this value improves performance and reduces your AWS costs, because Trellix will access your AWS CMK less often. But, this can also affect your security profile because there will be a period after restricting access to your AWS CMK, when Trellix can still decrypt your data.

Register master key

Registers your master key on Trellix ePO - SaaS.

  • Key ARN — The Amazon Resource Name (ARN) of a master key in your AWS KMS. For example, arn:aws:kms:   us-east–1:123456789012:key/

    12345678–1234-1234-1234–123456789012

    • Role ARN —The ARN of an Assumable Role in your AWS account, which grants access to your master key.

    For example, arn:aws:iam::123456789012:role/ MyAssumableRole

    • Description — An optional description for the

    key.

Revoke master key

Removes an inactive master key from the Master keys page.

Set master key as active

Sets the selected master key as the active key.

Note: Trellix master key is the default active key.

Managing policies

You can manage the Trellix MNE client systems from Trellix ePO - SaaS through a combination of product policies. Assign policies to the required client systems to make sure that systems are managed and function as specified.

What is a policy?

A policy is a collection of settings that you create in Trellix ePO - SaaS and assign to the required Trellix MNE client to configure client systems.

When configuring policies for the first time:

  1. Plan product policies for different segments of your System Tree.

  2. Create and assign policies to groups and systems.

To create, edit, and assign policies to systems or groups, see the product documentation for Trellix ePO - SaaS.

Product policies

On the Policy Catalog page, the Trellix MNE policies appear under the FileVault Product Settings, BitLocker Product Settings, and Security Posture Report Settings categories.

FileVault Product Settings

Settings

Description

FileVault Management

Manage FileVault — Allows you to manage FileVault and receive reports from the client system.

  • Turn On (Enable) FileVault — When enforced, turns on FileVault on client systems if not already enabled and then manage accordingly. The client systems also report the status to Trellix ePO - SaaS.

When you turn on FileVault and enforce this

policy on the required client systems, users see a pop-up window on their client systems requesting that they restart the system. The user must restart the system to enable FileVault to encrypt the system managed by Trellix ePO - SaaS, or choose to postpone the restart until a more convenient time.

  • Destroy FileVault key in standby mode — The FileVault recovery key is removed from memory when a system goes into a standby mode. This defends against memory-related attacks during various sleep states. Resuming from sleep mode forces a user authentication to bring the key back into memory.

  • Generate a new FileVault key in days (1-360) — Enable this option and

specify how frequently the recovery key is to be rotated. This improves security by reducing the validity period of each individual recovery key.

  • Allows users to import recovery key

on client — Enable this option to allow users to import the recovery key on client systems. This is useful if end users use the FileVault application to generate new recovery keys.

  • Prompt user to create a new

recovery key on already enabled systems — If FileVault is already enabled by the user when Trellix MNE policy is enforced, the client system prompts the user to authenticate using their FileVault password. Once authenticated, the client system recovery key can be queried from FileVault and is escrowed to the Trellix ePO - SaaS database.

Note: If users ignore this request, system recovery cannot be achieved as no recovery key can be escrowed to Trellix ePO - SaaS; FileVault only releases the current recovery key if authentication is provided.

Note:

  • Restart timeout period in minutes (1-60) — Defines the length of the restart timeout period.

  • Turn Off (Disable) FileVault — When enforced, this turns off FileVault on client systems. Client systems status remains reported in Trellix ePO - SaaS.

Note: On enabling this option, the Password Settings and Client Messaging functions are disabled.

Note:

Do not manage FileVault — When enforced, Trellix MNE does not manage FileVault.

  • Report client system status — When enforced, Trellix MNE does not manage FileVault, but reports FileVault status and security posture data to Trellix ePO - SaaS, allowing you to manage FileVault with a third-party management tool, yet report status in Trellix ePO - SaaS. This can be useful to report on BYOD (Bring Your Own Device) or contractor laptops to monitor compliance to company encryption policies.

If Trellix MNE manages FileVault, or if report-only mode is selected, the client system reports the following information to Trellix ePO - SaaS:

  • FileVault status

  • FileVault mode

  • System information

  • System encryption status

  • FIPS status

Settings

Description

Password Settings

Apply password content rules — Allows you to set password settings on macOS, which enforces these password settings on the client system.

  • Minimum length (4-40) — The user must create a password of the specified minimum length.

  • Maximum length (4-255) — The user must create a password of the specified maximum length.

  • Require at least one alphabetical character in password — The user must include at least one alphabetic character in creating the password.

  • Require at least one numeric character in password — The user must include at least one numeric character in creating the password.

  • Require password change after days (1-180) — The user must change the

password after the specified number of days.

  • Do not apply password content rules to these users (separate users with a semi-colon, for example, user1; user2) — Type the user name (short name) of users to make sure the password settings do not apply to the specified users.

Client Messaging

Display the following message, instead of the default, when enabling FileVault — The user receives this message when FileVault is enabled. If left empty, a default message is provided.

Display the following login banner — Enable this option and provide a logon banner after FileVault authentication.

Display the following message, instead of the default, when a third party application or user disables FileVault — The user receives this message if FileVault is disabled by anything other than Trellix MNE. If left empty, a default message is provided.

BitLocker Product Settings

Settings

Description

Show/Hide Advanced

Click to show or hide advanced settings within the policy page. All policy options have suitable defaults if you do not want to define advanced settings.

BitLocker management

  • Manage BitLocker — Allows you to manage BitLocker and receive reports from the client system.

    • Turn On (Enable) BitLocker — When enforced, turns on BitLocker on client systems and manages accordingly. The client systems also report the status to Trellix ePO - SaaS.

Note: Make sure to note that the encryption strength cannot be changed on a previously encrypted client. To change the encryption strength, BitLocker needs to be decrypted, disabled, and then re-enabled by Trellix MNE.

Note:

  • AES-128 — Configures BitLocker on client systems to use AES-128 algorithm for encryption.

  • AES-256 — Configures

    BitLocker on client systems to use AES-256 algorithm for encryption.

Settings

Description

  • XTS-AES-128 — Configures BitLocker on client systems to use XTS-AES-128 algorithm for encryption.

Note: This algorithm is supported on Windows 10 version 1511 and above systems only. Older systems fall back to the AES-128 algorithm.

Note:

  • XTS-AES-256 — Configures BitLocker on client systems to use XTS-AES-256 algorithm for encryption.

Note: This algorithm is supported on Windows 10 version 1511 and above systems only. Older systems fall back to the AES-256 algorithm.

  • Rotate recovery keys after a specified number of days

    (1-360) — Enable this option and specify how frequently the recovery key is to be rotated. This improves security by reducing the validity period of each individual recovery key.

  • Remove keys not added by Management of Native Encryption — Enable this option to remove any pre-existing keys for better security when Trellix MNE takes over management. This is useful for BYOD (Bring your Own Device)

Settings

Description

systems to make sure that any pre-existing non-Trellix MNE recovery keys are removed.

  • Turn Off (Disable) BitLocker — When enforced, turns off BitLocker and decrypts client systems. The client systems report the status to Trellix ePO - SaaS.

  • Do not manage BitLocker — When enforced,

Trellix MNE does not manage BitLocker.

  • Report client system status — When enforced, Trellix MNE does not manage BitLocker, but reports BitLocker status and security posture data to Trellix ePO - SaaS, allowing you to manage BitLocker with a third-party management tool, yet report status within Trellix ePO - SaaS. This can be useful to report on BYOD (Bring Your Own Device) or contractor laptops to monitor compliance to company encryption policies.

If Trellix MNE manages BitLocker, or report-only mode is enabled, the client system reports the following information to Trellix ePO - SaaS:

  • BitLocker status

  • BitLocker protection status

Settings

Description

Note: BitLocker protection is suspended when the administrator changes the policy to change protector on operating system drive during the switch-over period. Otherwise, if switching authentication method, the endpoint is unprotected until the new authentication method is fully applied.

Note:

  • BitLocker mode

  • System information

  • System encryption status

  • FIPS status

System authentication

  • System authentication

  • Keep existing non-MNE authentication protector — Enabling this option prevents Trellix MNE from replacing an existing BitLocker authentication protector. It is recommended to set this if BitLocker is configured in advance of deploying Trellix MNE to the endpoint, and you want to suppress password or PIN prompts from being presented to the end user.

  • TPM — Allows you to use the TPM authentication method to protect the operating system volume for TPM supported client systems. A password or PIN is not required to boot Windows.

  • TPM and PIN — Allows you to use TPM

authentication and a PIN as additional security for TPM supported client systems.

  • TPM and enhanced PIN — Allows you to use

an enhanced PIN number as an additional security for TPM supported client systems.

Settings

Description

Note: It is recommended to enable the hardware test option under BitLocker advanced settings to make sure pre-boot supports enhanced PINs.

Note:

  • Password (Windows 8 and above) — Allows you to use password authentication to protect the operating system volume for Windows client systems.

  • System authentication (legacy) — These options apply to version 4.x clients.

    • Use Trusted Platform Module (TPM)

      • Allows you to use the TPM authentication method to protect the operating system volume for TPM supported client systems.

        • Also use PIN — Allows you to use a PIN as an additional security for TPM supported client systems.

        • Use enhanced PIN if

supported — Allows you to use an enhanced PIN as additional security for TPM supported client systems.

Note: It is recommended to enable the hardware test option under BitLocker advanced settings to make sure pre-boot supports enhanced PINs.

Note:

  • Fall back to Password if no TPM is available (Windows 8 and above) — Allows you to use password authentication for client systems that do not

Settings

Description

support TPM.

Note: If the Use Trusted Platform Module (TPM), Also use PIN, and Fall back to Password if no TPM is available (Windows 8 and above) options are all enabled and the current protector is the passphrase protector, then the client system is compliant to the policy.

Note:

  • Password (Windows 8 and above) — Allows you to use password authentication to protect the operating system volume for client systems that are installed with Windows 8 or above.

Note: If you enable this option, Windows 7 systems automatically fall back to using TPM with PIN, as password is not supported for Windows 7 systems.

Authentication Settings

Maximum number of times user can postpone activation (1-10) — Enable this option and enter the maximum number of times from 1 to 10 to postpone activation.

Click Show Advanced to access this setting.

BitLocker advanced settings

You can choose to enable, disable, or not manage the following options:

  • Enable hardware test (requires reboot before encryption) — Enable this option to perform hardware test for the required client systems before BitLocker starts protecting the system.

  • Activate on platforms (for example slates/

Settings

Description

tablets) that indicate no pre-boot input support (use with caution) — Enable this option to allow activation on tablets.

  • Only encrypt used space during initial encryption of volumes (Windows 8 and above) — Allows you to encrypt only the used space of the volumes for client systems,

significantly speeding up initial encryption. This is applicable for systems installed with Windows 8 or above.

Note: Sensitive data that was previously deleted from the file system might not be protected, as not all sectors are protected.

  • Reduce restart delays by preventing memory overwrite of BitLocker secrets during shutdown (use with caution) — Improves restart performance by skipping key-zeroization during the restart process. This leaves systems more vulnerable to very sophisticated memory attacks.

  • Re-measure TPM validation data after a BitLocker recovery, to reduce the chances of further recoveries (Windows 8 and above) — After a BitLocker recovery, the system boot is remeasured using the TPM to ensure that it is current. This reduces the risk of recurrence of a recovery scenario caused by a boot measurement change.

  • Allow use of BitLocker To Go (Windows 8 and above) — Allows you to encrypt removable media. This option is automatically enabled.

  • Deny write access to fixed data volumes not protected by BitLocker — Enable this option to deny write access to fixed volumes for client systems that are not protected by BitLocker. This prevents users from writing

Settings

Description

data to unprotected volumes until they are fully protected, thus improving data security.

  • Require hardware-based encryption

(Windows 8 and above) — Enable this option to ensure that BitLocker only activates with self-encrypting drives.

Note: From Windows 10 Build 18317, software-based encryption is the BitLocker default. See https://bit-tech.net/ news/tech/software/microsoft-flips-bitlocker-encryption-default/1/

    • Fallback to software-based encryption if hardware-based encryption is not supported — Enable this option to allow BitLocker to use software encryption if a self-encrypting drive is not available. Used with the parent option, this allows a preference to be stated for self-encrypting drives.

Security Posture Report Settings

Security posture reporting allows you to report the endpoints that meet your required security posture settings for your organization, and those that do not.

The security posture report settings allow you to define the criteria for securing endpoints. This policy has no effect on the management of the endpoint; it simply defines the tests that the endpoints should run to assure its data protection security posture.

Each specific posture test passes unless there is a specific reason for failing. For example, a system without data volumes passes all data volume tests, since there are no data volumes to fail. In other words, this reporting is primarily designed to report failures against specific criteria.

Note: You can view the overall result of security posture reporting tests by navigating through Menu Systems System Tree

Systems tab, selecting the required system, and then clicking Native Encryption Security posture reporting.

Settings

Description

Security posture reports apply to:

  • OS Volume — Enable this option to test the OS volume against the selected criteria.

  • Data Volume(s) — Enable this option to test data volumes against the selected criteria.

Note: If the system doesn't have data volumes, the data volume tests pass each of the posture tests.

Security posture reporting:

  • Used space on selected volumes(s) should be fully encrypted (recommended) — Enable this option to report that the system is secure, only if the used space on the selected volume types is fully encrypted.

  • Selected volumes(s) require authentication

— Enable this option to report that the system is secure only if the selected volume types require user authentication or TPM authentication.

  • Selected volume(s) should use a minimum

encryption strength of: — Enable this option to report that the system is secure only if the selected volume types use at least:

    • AES-128 128 bit — Can use AES-128 or AES-256.

Note: Systems that are activated with higher strength Algorithm AES-256 and Security Posture set to Algorithm AES-128 displays as pass.

  • AES-256 256 bit — Must use AES-256.

  • Selected volumes should be FIPS compliant

— Enable this option to report that the system is secure only if the selected volume types are FIPS compliant.

Note: Systems that are activated before they are managed by Trellix MNE cannot be verified as FIPs compliant

Enforce Trellix MNE policies on a system

Enable or disable policy enforcement on a client system. Policy enforcement is enabled by default, and is inherited in the System Tree.

For more information about performing this task, see the product documentation for Trellix ePO - SaaS.

Task

  1. Log on to Trellix ePO - SaaS as an administrator.
  2. Select Menu → Systems → System Tree → Systems tab, then under System Tree, select the group where the system belongs. The list of systems belonging to this group appears in the details pane.
  3. Select a system, then click Actions → Agent → Modify Policies on a Single System.
  4. Select Management of Native Encryption, then click Enforcing next to Enforcement status.
  5. Select Break inheritance and assign the policy and settings below to change the enforcement status.
  6. Next to Enforcement status, select Enforcing, then click Save.

Results

After restarting, the client system communicates with Trellix ePO - SaaS and pulls down the assigned Trellix MNE policies and encrypts the system according to the defined policies.

Enforce policies to a group

Enable or disable policy enforcement for a product on a System Tree group. Policy enforcement is enabled by default, and is inherited in the System Tree.

Task

  1. Log on to Trellix ePO - SaaS as an administrator.
  2. Select Menu → Systems → System Tree → Assigned Policies, then select a group in the System Tree.
  3. From the Product drop-down list, select Management of Native Encryption, then click Enforcing next to Enforcement
  4. Status.
  5. To change the enforcement status, select Break inheritance and assign the policy and settings below.
  6. Next to Enforcement status, select Enforcing.
  7. Select whether to lock policy inheritance so that groups and systems that inherit this policy can't break enforcement, then click Save.

Retain non-MNE authentication protectors on endpoints

You can configure the Trellix MNE policy so that the existing non-Trellix MNE authentication protectors configured on endpoints are retained.

Task

  1. Log on to Trellix ePO - SaaS as an administrator.
  2. Select Policy → Policy Catalog.
  3. From the Products pane, select Management of Native Encryption, then under BitLocker Product Settings, select a policy to edit.
  4. In the System Authentication tab, select Keep existing non-MNE authentication protector.
  5. Click Save.

Results

The selected Trellix MNE authentication protectors are ignored for endpoints that have an active non-Trellix MNE authentication protector. If none of the Trellix MNE authentication protectors are selected and the Keep existing non-MNE authentication protector is selected, then only systems with non-Trellix MNE authentication protectors are secured.

Managing client systems

System management allows you to import system information into Trellix ePO - SaaS. This is useful in the process of installing

Trellix MNE and viewing the list of FileVault or BitLocker users.

Trellix ePO - SaaS manages client systems through a combination of product policies. You can identify systems that require the same policy settings, and place them in a system group. This grouping allows you to update the policy settings to all systems in that group at the same time.

Customize the installation URL and send it to users

You can send the installation URL (also called the Agent Deployment URL) to all users whose systems you want to manage with

Trellix ePO - SaaS.

After you send the installation URL to the endpoint users in your network, they use a browser to access the installation URL and open the Trellix Smart Installer. The Trellix Smart Installer starts this process:

  1. The Trellix Agent is downloaded to the system.

  2. The system communicates back to Trellix ePO - SaaS and adds the system to the default group, My Group, in the System Tree.

  3. After these communications, the system appears in the System Tree as Managed.

  4. After the Trellix Agent is installed, it downloads the product software you selected when you created the installation URL.

Task

  1. Log on to Trellix ePO - SaaS as an administrator.
  2. Select Menu → Software → Product Deployment.
  3. Enter a group name, select the platform type, then select the type of endpoint protection to deploy.
  4. Click Save.
  5. The Install Protection on Other Computers dialog box displays the installation URL.

  6. Copy the URL to your clipboard.
  7. Email or copy the URL to the systems that you want to manage.
  8. Ask the endpoint users to perform the installation steps for their operating system:
    • Windows

    • macOS

Results

Once your endpoint users have installed the Trellix Agent on their systems, the Trellix Agent communicates with Trellix ePO - SaaS, downloads the product software, and brings these systems under Trellix ePO - SaaS management.

Move systems between groups

You can move systems from one group to another in the System Tree. You can also move systems from any page that displays a table of systems, including the results of a query.

Note: In addition to the steps below, you can also drag and drop systems from the Systems table to any group in the System Tree.

Even if you have a perfectly organized System Tree that mirrors your network hierarchy and uses automated tasks and tools to regularly synchronize your System Tree, you might need to move systems manually between groups. For instance, you might need to periodically move systems from the Lost&Found group.

Task

  1. Log on to Trellix ePO - SaaS as an administrator.
  2. Select Menu → Systems → System Tree → Systems, then browse and select the systems.
  3. Click Actions → Directory Management → Move Systems.
  4. Select whether to enable or disable, or to not change the System Tree sorting on the selected systems when they are moved.
  5. Select the group where you want to place the systems, then click OK.

Using the System Tree options to recover a system

Viewing a compliance report, importing a recovery key, or recovering a system can be done from System Tree.

When you navigate to Menu Systems System Tree, select the required system, then click Actions Trellix Management of Native Encryption, the following options are displayed:

  • Compliance report — Allows you to view the report, system, and native encryption properties for the selected system and to verify if the system is compliant with the configured policies.

  • Import FileVault recovery key — Allows you to manually import the recovery key of the Mac systems to the Trellix ePO - SaaS database using the Import FileVault recovery key by Machine Node page.

  • Trellix Management of Native Encryption Recovery — Allows you to recover a system, if a user reports accessibility issues to that system. To recover a system, select the required system in the System Tree, then click Actions Trellix Management of Native Encryption Trellix Management of Native Encryption Recovery to open the recovery key for that system. You must securely pass that recovery key to the user, so that the user can recover the system.

Maintenance mode on BitLocker systems

This feature allows you to temporarily disable preboot authentication on BitLocker systems, to roll out Windows or software

updates that might require a system reboot. To use this feature, the maintenancemode-x.x.x.x.exe file must be copied to the system, and executed with command-line parameters within the roll-out scripts.

Maintenance mode disables BitLocker protection and all subsequent enforcement of Trellix MNE policy, until the specified number of reboots have occurred, or maintenance mode is explicitly cleared. Once cleared, system protection is restored to its original state on next local policy enforcement.

An API version is used to verify whether the maintenance mode executable is compatible with the installed version of Trellix MNE. To test for compatibility, run the command maintenancemode-x.x.x.x.exe --version and verify the output.

Note: The maintenance mode executable requires administrator rights to run.

To restore BitLocker protection immediately, you can trigger a local policy enforcement from the Trellix Agent by calling

CmdAgent.exe, within your scripts. For more information about using command-line switches with CmdAgent, see KB52707.

Examples

For command-line options, run maintenancemode-x.x.x.x.exe --help.

  • Enter maintenance mode, allowing for 3 reboots before maintenance mode is cleared: maintenancemode-x.x.x.x.exe --number-of-reboots 3

  • Clear the maintenance mode: maintenancemode-x.x.x.x.exe --clear

  • Obtain the version of the maintenance mode executable, and API versions: maintenancemode-x.x.x.x.exe --version

Managing Trellix MNE reports

Trellix MNE queries are configurable objects that retrieve and display data from the database. These queries can be displayed in charts and tables.

Any query results can be exported to a variety of formats, any of which can be downloaded or sent as an attachment to an email message. Most queries can be used as a dashboard monitor.

Queries as dashboard monitors

Most queries can be used as a dashboard monitor (except those using a table to display the initial results). Dashboard monitors are refreshed automatically on a user‑configured interval (five minutes by default).

Exported results

Trellix MNE query results can be exported to four different formats. Exported results are historical data and are not refreshed like other monitors when used as dashboard monitors. Like query results and query-based monitors displayed in the console, you can drill down into the HTML exports for more detailed information.

Reports are available in several formats:

  • CSV — Use the data in a spreadsheet application (for example, Microsoft Excel).

  • XML — Transform the data for other purposes.

  • HTML — View the exported results as a web page.

  • PDF — Print the results.

View the standard Trellix MNE reports

You can run and view the standard Trellix MNE reports from the Queries & Reports page.

Task

  1. Log on to Trellix ePO - SaaS as an administrator.
  2. Select Menu → Reporting → Queries & Reports.
  3. On the Groups pane, under the Trellix Groups category, select Trellix Management of Native Encryption.

You can view these standard reports:

Query

Description

Activation Failures

Displays the list of systems that have failed activation.

Report data protection security posture

Displays the results of the data protection security posture check on Trellix MNE systems. This report can be used to identify and report those systems that do not meet the definition of a secure system.

Report native encryption status

Displays the Trellix MNE status of the client systems.

Report overall encryption status

Displays the encryption status of the client systems.

Important: When a volume is locked by BitLocker, the message "Unable to determine status" is displayed for the system overall encryption status. This is because BitLocker doesn't release any information for a locked volume. This is expected behavior.

Report policy compliance

Reports the level of policy compliance of Trellix MNE systems. This report can be used to identify systems that can't or have not enforced the Trellix ePO - SaaS policy correctly. For example, a system previously encrypted with AES-128 with an AES-256 policy can't transition to AES-256, so it is out of compliance with the Trellix ePO - SaaS policy.

Report recovery keys

Displays the list of client systems with recovery information.

Reports users per system

Displays the list of users assigned to a Mac client system, or who have logged on to Windows systems.

Query

Description

Report systems in maintenance mode

Displays the systems currently in maintenance mode, where BitLocker protection has been disabled.

Report systems pending key rotation

Displays the systems where key rotation is pending after a recovery has been performed on the system through Trellix MNE recovery pages .

Report authentication types for MNE systems

Displays a pie chart showing authentication types for Trellix MNE systems.

From the Queries list, select the needed query.
Click Actions → Run. The query results appear.

You can also edit or duplicate the query, and view the details.

Click Options → Export Data, make the needed selections, then click Export to export the query data.
Click Close.

Create Trellix MNE custom queries

You can create queries that retrieve and display the details like disk status, users, and product client events for Trellix MNE. With this wizard you can configure which data is retrieved and displayed, and how it is displayed.

Task

  1. Log on to Trellix ePO - SaaS as an administrator.
  2. Select Menu → Reporting → Queries & Reports, then click Actions → New.
  3. On the Feature Group pane, select Management of Native Encryption.
  4. On the Result Types page, select the required query type, then click Next.
  5. On the Chart page, from the Display Result As pane, select the type of chart or table to display the primary results of the query, then click Next.

If you select Boolean Pie Chart, you must configure the criteria to include in the query.

On the Columns page, from the Available Columns pane, select the columns to be included in the query, then click Next.

If you had selected Table on the Chart page, the columns you select here are the columns of that table. Otherwise, these are the columns that make up the query details table.

On the Filter page, from the Available Properties pane, select the required properties to narrow the search results, then click Run. The Unsaved Query page displays the results of the query, which is actionable, so you can take any
available actions on items in any tables or drill-down tables.

Selected properties appear in the content pane with operators that can specify criteria used to narrow the data that is returned for that property.

  • If the query didn’t appear to return the expected results, click Edit Query to go back to the Query Builder and edit the details of this query.

  • If you don’t need to save the query, click Close.

  • If this is a query you want to use again, click Save and continue to the next step.

On the Save Query page, type a name for the query, add any notes, and select one:
  • New Group — Type the new group name and select one:

Private (Private Groups)
Public (Shared Groups)
  • Existing Group — Select the group from the list of Shared Groups.

Click Save.

View the standard dashboard

You can view the standard reports from the MNE Dashboard page.

Task

Log on to Trellix ePO - SaaS as an administrator.
Select Reporting → Dashboards and select MNE Dashboard from the drop-down list.

Results

You can view the Trellix MNE dashboard.

Find systems by user name

You can view the Find MNE systems by user name dashboard on the Trellix MNE Dashboards page.

The Find MNE systems by user name dashboard allows the administrator to enter a user name that reports all systems associated with that user.

Task

Log on to Trellix ePO - SaaS as an administrator.
From the Dashboard drop-down list, select MNE Dashboard.
Type the name of the user in the text box and click Go.

Results

The administrator can now view all systems associated with that user.

Create custom Trellix MNE dashboard

Dashboards are collections of user-selected and configured monitors that provide current data about your environment. You can create your own dashboards from query results or use Trellix ePO - SaaS default dashboards.

Task

Log on to Trellix ePO - SaaS as an administrator.
From the Dashboard Actions drop-down list, select New.
Next to Dashboard Name, type a name for the dashboard.
Next to Dashboard Visibility, select one of these options, as needed:
  • Private — To make the dashboard visible to a specific set of users.

  • Public — To make the dashboard visible to all users.

  • Shared with the following permission set(s) — To make the dashboard visible to the specified permission sets.

Click OK.
Click Add Monitor, select the MNE query, and drag and drop to the MNE dashboard.

Trellix MNE client events

While implementing and enforcing the Trellix MNE policies that control how sensitive data is encrypted, you can monitor real‑time client events and generate reports using the Trellix MNE client events query.

Event ID

Event Description

Event Type

35203

This event is reported in Trellix ePO - SaaS when the FileVault activation fails with an error message macOS recovery partition is not found.

Critical

35204

This event is reported in Trellix ePO - SaaS when an incompatible product is found. For example, Trellix Drive Encryption .

Informational

Event ID

Event Description

Event Type

35205

This event is reported in Trellix ePO - SaaS when FileVault or BitLocker activation is successful.

Informational

35206

This event is reported in Trellix ePO - SaaS when the restart prompt appears on the client system.

Informational

35207

This event is reported in Trellix ePO - SaaS when the FileVault or BitLocker activation fails with an error message Unsupported operating system found.

Critical

35208

This event is reported in Trellix ePO - SaaS when FileVault activation fails with an error message EEMac is active.

Informational

35209

This event is reported in Trellix ePO - SaaS when FileVault or BitLocker is already turned on in the client system.

Informational

35210

This event is reported in Trellix ePO - SaaS when FileVault activation fails with an error message Unable to retrieve the recovery key from FileVault.

Error

35211

This event is reported in Trellix ePO - SaaS when FileVault or BitLocker activation fails with an error message Unknown exception occurred.

Error

35212

This event is reported in Trellix ePO - SaaS when the recovery

Informational

Event ID

Event Description

Event Type

key is sent to the Trellix ePO - SaaS database successfully.

35213

This event is reported in Trellix ePO - SaaS when the user is waiting for system to restart.

Informational

35214

This event is reported in Trellix ePO - SaaS when Trellix MNE is running in Report and Manage mode.

Informational

35215

This event is reported in Trellix ePO - SaaS when Trellix MNE is running in Report only mode.

Informational

35216

This event is reported in Trellix ePO - SaaS when Trellix MNE is disabled.

High

35217

This event is reported in Trellix ePO - SaaS when macOS logon banner is applied.

Informational

35218

This event is reported in Trellix ePO - SaaS when macOS logon banner is removed.

Informational

35219

This event is reported in Trellix ePO - SaaS when macOS password settings are applied.

Informational

35220

This event is reported in Trellix ePO - SaaS when macOS password settings are disabled.

Critical

35221

This event is reported in Trellix ePO - SaaS when disabling

Error

Event ID

Event Description

Event Type

FileVault fails because the recovery key is invalid, and the user must manually disable FileVault.

35222

This event is reported in Trellix ePO - SaaS when disabling FileVault fails because the recovery key is unavailable, and the user must manually disable FileVault.

Error

35223

This event is reported in Trellix ePO - SaaS when the Mac serial number is not found.

Error

35224

This event is reported in Trellix ePO - SaaS when the volume information is not available.

Error

35225

This event is reported in Trellix ePO - SaaS when FileVault user information is sent.

Informational

35226

This event is reported in Trellix ePO - SaaS when FileVault is disabled by third-party application or user.

Critical

35227

This event is reported in Trellix ePO - SaaS when the encryption is started.

Informational

35228

This event is reported in Trellix ePO - SaaS when the encryption is completed.

Informational

35229

This event is reported in Trellix

Informational

Event ID

Event Description

Event Type

ePO - SaaS when the decryption is started.

35230

This event is reported in Trellix ePO - SaaS when the decryption is completed, and FileVault or BitLocker is disabled.

Informational

35231

This event is reported in Trellix ePO - SaaS when the restart prompt fails to appear.

Error

35232

This event is reported in Trellix ePO - SaaS when disabling FileVault or BitLocker fails.

Error

35233

This event is reported in Trellix ePO - SaaS when a user is removed from FileVault.

Informational

35234

This event is reported in Trellix ePO - SaaS when removing a user from FileVault fails.

Error

35235

This event is reported in Trellix ePO - SaaS when the user imports a FileVault recovery key.

Informational

35236

This event is reported in Trellix ePO - SaaS when the user fails to import a FileVault recovery key since the key is invalid.

Informational

35238

This event is reported in Trellix ePO - SaaS when the system is not compliant with Trellix MNE policy as the local policy changes have been made.

Critical

Event ID

Event Description

Event Type

35239

This event is reported in Trellix ePO - SaaS when the BitLocker GPO policy is overriding the Trellix MNE policy.

Critical

35240

This event is reported in Trellix ePO - SaaS when BitLocker fails to activate as TPM is not available, or when changing from password to TPM policy, if TPM is not available, leaving the system in an unprotected state.

Error

35241

This event is reported in Trellix ePO - SaaS when BitLocker fails to activate as TPM is not available and fails to fall back to password authentication on Windows 7 systems that do not support the password encryption method.

Error

35242

This event is reported in Trellix ePO - SaaS when BitLocker fails to activate as the password policy is not supported on Windows 7 systems.

Error

35243

This event is reported in Trellix ePO - SaaS when BitLocker fails to activate as TPMs PIN policy is not supported on Windows 7 systems.

Error

35244

This event is reported in Trellix ePO - SaaS when the encryption algorithm strength used to encrypt the disk is weaker than the strength specified in the policy.

Warning

Event ID

Event Description

Event Type

35245

This event is reported in Trellix ePO - SaaS when the encryption algorithm strength used to encrypt the disk is stronger than the strength specified in the policy.

Warning

35246

This event is reported in Trellix ePO - SaaS when TPM is not available and the client system has fallen back to password encryption method for authentication.

Informational

35247

This event is reported in Trellix ePO - SaaS when the client system has more than one user on the system while activating FileVault.

Informational

35248

This event is reported in Trellix ePO - SaaS when the FileVault users have been successfully excluded from inheriting the password policy.

Informational

35249

This event is reported in Trellix ePO - SaaS when excluding FileVault users fails from inheriting the password policy.

Error

35250

This event is reported in Trellix ePO - SaaS when the recovery key is successfully regenerated on the client system.

Informational

35251

This event is reported in Trellix ePO - SaaS when the recovery key fails to regenerate on the

Critical

Event ID

Event Description

Event Type

client system.

35252

This event is reported in Trellix ePO - SaaS when BitLocker activation fails as SafeBoot or Trellix Drive Encryption is installed.

Critical

35253

This event is reported in Trellix ePO - SaaS when FIPS mode activation fails on Windows 8 systems.

Critical

35254

This event is reported in Trellix ePO - SaaS when password authentication is not supported on Windows 7 systems and falls back to TPM and PIN authentication method.

Informational

35255

This event is reported in Trellix ePO - SaaS when Trellix MNE activation is refused due to failed hardware test.

Critical

35256

This event is reported in Trellix ePO - SaaS when the hardware test is ignored as FIPS is enabled.

Critical

35257

This event is reported in Trellix ePO - SaaS when the key rotation is successful.

Informational

35258

This event is reported in Trellix ePO - SaaS when key rotation fails because one or more keys failed to rotate.

Major

Event ID

Event Description

Event Type

35259

This event is reported in Trellix ePO - SaaS when the calculation of compliance to policy fails. For more information, refer to the client logs.

Critical

35260

This event is reported in Trellix ePO - SaaS when there are no supported BitLocker volumes. For more information, see KB83141.

Major

35261

This event is reported in Trellix ePO - SaaS when a keyboard is not detected for use in preboot environment for tablets/slates and the activation fails.

Major

35262

This event is reported in Trellix ePO - SaaS when the non-Trellix MNE recovery keys have been removed.

Informational

35263

This event is reported in Trellix ePO - SaaS when the system fails to remove the non-Trellix MNE recovery keys.

Major

35264

This event is reported in Trellix ePO - SaaS when key rotation is requested by Trellix ePO - SaaS from the client system.

Informational

35265

This event is reported in Trellix ePO - SaaS when the maintenance mode has been disabled successfully.

Informational

35266

This event is reported in Trellix ePO - SaaS when the

Informational

Event ID

Event Description

Event Type

maintenance mode is active.

35267

This event is reported in Trellix ePO - SaaS when the maintenance mode fails to activate.

Major

35268

This event is reported in Trellix ePO - SaaS when the maintenance mode has ended after the specified number of reboots.

Informational

35269

This event is reported in Trellix ePO - SaaS when key rotation was only partially successful (some keys failed to rotate).

Informational

35274

This event is reported in Trellix ePO - SaaS when a user successfully changed their password through the Trellix MNE user interface.

Informational

35275

This event is reported in Trellix ePO - SaaS when a user successfully changed their PIN through the Trellix MNE user interface.

Informational

35276

Activation failed: Hardware encryption is required but not supported.

Informational

35277

Hardware encryption is required but drive is already encrypted with software.

Informational

Event ID

Event Description

Event Type

35278

Failed to disable FileVault due to empty UUID.

Error

35279

Successfully applied password authentication.

Informational

35280

Failed to apply password authentication.

Error

35281

Successfully applied TPM authentication.

Informational

35282

Failed to apply TPM authentication.

Error

35283

Successfully applied TPM and standard PIN authentication.

Informational

35284

Failed to apply TPM and standard PIN authentication.

Error

35285

Successfully applied TPM and enhanced PIN authentication.

Informational

35286

Failed to apply TPM and enhanced PIN authentication.

Error

35291

Information

Informational

35292

Error

Error

35293

Failed to apply any of the authentication methods specified in the policy.

Critical

35299

An error occurs while reading Boot Configuration Data.

Error

Event ID

Event Description

Event Type

40200

An error occurs while reading or writing UEFI variables.

Error

Recovering systems

System recovery is a process of recovering a user's system from system crashes, system malfunctions, accessibility issues, and more. If a user reports any such problems, you must provide the recovery key of the system to the user for the user to recover the system using FileVault recovery tools provided by Apple or BitLocker recovery tools provided by Microsoft.

Note: We don't provide support for FileVault or BitLocker recovery tools. If you encounter any problems with this recovery process, we recommend that you contact Apple or Microsoft Support as appropriate.

How is the key escrowed in the Trellix ePO - SaaS database?

The recovery key can be escrowed in two ways:

  • When enabling FileVault or BitLocker on a client system using Trellix MNE, Trellix MNE obtains the recovery key of the system automatically and sends it to the Trellix ePO - SaaS database.

  • If the user has previously enabled FileVault at the point when Trellix MNE is installed on the client system, then one of the following options is applicable:

    • The system user must enter their FileVault password when prompted to grant Trellix MNE the right to the recovery key

    • The system user must import their FileVault recovery key on the system

    • The administrator must import the recovery key of the system manually into the Trellix ePO - SaaS database for the recovery feature to be available for that system.

If none of these actions are taken, recovery is not possible.

Note: You can obtain the recovery key of a client system only if Trellix MNE manages FileVault or BitLocker.

Obtaining the serial number of a Mac system

The serial number of the Mac system can be obtained in two ways:

  • At the back/side/bottom of your Mac hardware, the serial number of the system is displayed.

  • When you click the About this Mac option, the serial number of the system is displayed.

Import the recovery key

You might need to manually import the recovery key of a Mac client system to the Trellix ePO - SaaS database using the System Tree or Data Protection menu. The client user can also import the recovery key to the Trellix ePO - SaaS database from the client system.

These tasks must be performed only if the user has previously enabled FileVault.

Note: This is required only for FileVault systems.

Import the recovery key using System Tree

You must manually import the recovery key of the client system to the Trellix ePO - SaaS database using the Import FileVault recovery key by Machine Node page.

Task

  1. Log on to Trellix ePO - SaaS as an administrator.
  2. Select Menu → Systems → System Tree → Systems tab, select the required system, then click Actions → Trellix Management of Native Encryption → Import FileVault recovery key to open the Import FileVault recovery key by Machine Node page.
  3. In the Enter recovery key field, type the recovery key of the system that you obtained.
  4. Click Ok.

Import the recovery key using the Data Protection menu

You must manually import the recovery key of the client system to the Trellix ePO - SaaS database using the Import FileVault recovery key by serial number page.

Task

  1. Log on to Trellix ePO - SaaS as an administrator.
  2. Select Menu → Data Protection → Import FileVault recovery key to open the Import FileVault recovery key by serial number page.
  3. In the Enter serial number field, type the serial number of the system that you received from the user.
  4. In the Enter recovery key field, type the recovery key of the system that you obtained.
  5. Click Ok.

Import the recovery key from a client system

Client users now have an option of importing the recovery key directly from the client system to the Trellix ePO - SaaS database.

Before you begin

  • This task must be performed by the client user on the client system.

  • Make sure that the administrator has enabled the FileVault policy for the client system.

  • Make sure that the administrator has enabled and enforced the Allows users to import recovery key on client policy on to the client system.

Task

Open the Trellix MNE client interface on the client system.
On the left pane, click Encryption.
Enter the new recovery key.

To generate a new recovery key, enter this command: sudo fdesetup changerecovery -personal.

Click Apply.

After the recovery key is escrowed to the Trellix ePO - SaaS database, the last key import time is displayed on the

Encryption pane.

Results

The recovery key is successfully escrowed to the Trellix ePO - SaaS database.

Import the recovery key using the Trellix MNE command-line

Client users now have an option of importing the recovery key directly from the client system, installed with Mavericks operating system or later, to the Trellix ePO - SaaS database using the Trellix MNE command line interface tool.

Before you begin

  • This task must be performed by the client user who has 'sudo' or 'root' privileges on the client system.

  • Make sure that the administrator has enabled the FileVault policy for the client system.

  • Make sure that the administrator has enabled and enforced the Allows users to import recovery key on client policy on to the client system.

Task

  1. Open the Terminal.app on the Mac client system.
  2. Run the command:
  3. sudo /usr/local/McAfee/MNE/bin/MNEMacTool -i xxxx-xxxx-xxxx-xxxx-xxxx-xxxx

Where xxxx refers to a valid recovery key for that particular client system.

Results

The recovery key is successfully escrowed to the Trellix ePO - SaaS database.

Perform system recovery using Trellix ePO - SaaS

When a system needs to be recovered, a recovery key can be obtained from Trellix ePO - SaaS. The recovery key must be passed to the user to recover their system through the Apple FileVault or Microsoft BitLocker recovery tools.

Note: FileVault provides a single recovery key per system. BitLocker provides one or more recovery keys per volume. If multiple recovery keys are available for a single volume (which might happen when Trellix MNE is installed on a previously encrypted system), then any of the recovery keys can be used to recover the volume.

Provide the recovery key to the user

You must provide the recovery key of the client system that is managed by Trellix ePO - SaaS to the user for the user to recover the system using the Apple FileVault or Microsoft BitLocker recovery tools.

Task

Log on to Trellix ePO - SaaS as an administrator.
Select Menu → Data Protection → Trellix Management of Native Encryption recovery.

Note: You can also access Management of Native Encryption recovery: select Menu Systems System Tree Systems tab, select the required system, then click Actions Trellix Management of Native Encryption recovery.

On the Enter serial number (FileVault) or recovery key ID (BitLocker) page, type the serial number for FileVault systems or recovery key ID for BitLocker systems that you received from the user, then click Next.

This step is not applicable if you access Management of Native Encryption recovery through the System Tree menu, because the serial number or recovery key ID of the system is automatically populated. In this case, multiple keys might be displayed.

The recovery key of the system appears on the Recovery key from serial number/ recovery key ID page.

Note: Provide the recovery key to the user so that the user can recover the system. For FileVault, the recovery key is always a string. For BitLocker in non-FIPS mode, the recovery key is always a string. For BitLocker in FIPS mode, the recovery key is always a file that must be downloaded and managed by Cryptographic Officers.

What to do next

Once the user has received the recovery key, we recommend the user to contact Apple or Microsoft Support for assistance in recovering the client system.

Rotate recovery keys

You can enable rotating the recovery keys when the system recovery is performed through Trellix MNE recovery pages. There might be a delay of up to an hour before the server requests that the client rotates the keys.

Task

  1. Log on to Trellix ePO - SaaS as an administrator.
  2. Select Menu → Configuration → Server Settings.
  3. In the Setting Categories pane, click Trellix Management of Native Encryption, then click Edit to open the Edit Trellix Management of Native Encryption page.
  4. Recovery is performed through MNE recovery pages — Enable this option to rotate the recovery keys when the recovery is performed through Trellix MNE recovery pages.
  5. Note: Key rotation following recovery is not available on macOS systems.
  6. Click Save.

Troubleshooting Trellix MNE on Trellix ePO - SaaS

You can troubleshoot issues related to Trellix MNE on Trellix ePO - SaaS and master keys by verifying how you configured your server settings.

AWS Customer Master Key (CMK) registration failed

The CMK registration can fail if the correct roles are not assigned for keys or if the key is disabled or deactivated. To make sure that the AWS CMK is configured correctly, follow the steps here: Create a Customer Master Key on AWS.

Key revoke failed

Revoking a key can fail if its status is active. You must first change the status of the master key to inactive before you can revoke it. Also, revoking the default Trellix key is not supported.

Key recovery failed

Make sure that the CMK or role is not changed, deleted, or disabled in the AWS console.

Key activation failed

When changing the active master key, both the existing active master key and the prospective active master key must be available for use by Trellix. The role and CMK must not be changed, deleted, or disabled in the AWS console. The role and CMK are required to decrypt your data, which is protected with the existing active master key and then to re- encrypt your data with the prospective active master key.

Issues with missing Trellix MNE policies

Contact Trellix Support or your onboarding team to verify if the Trellix ePO - SaaS account is set up correctly and whether the account has an Trellix MNE license.