Last Updated: September 17, 2023
Overview
Trellix Management of Native Encryption - SaaS is a management product that allows Trellix ePO - SaaS administrators to manage Apple FileVault and Microsoft BitLocker. These are products that provide full disk encryption on Macintosh (Mac) and Windows systems.
Note: This Product Guide contains information specific to Trellix MNE on Trellix ePO - SaaS. For information about Trellix MNE on Trellix ePO - On-prem, see the documentation for Trellix Management of Native Encryption.
With Trellix MNE - SaaS , you can perform these core functions from a central interface:
Manage Apple FileVault and Microsoft BitLocker
Report encryption status
Import, store, and retrieve recovery keys
Adopting Trellix MNE for BitLocker means that you no longer need to license, manage, or maintain Microsoft BitLocker Administration and Monitoring (MBAM) or its associated servers. You can consolidate servers and eliminate the related Microsoft licenses, providing significant cost savings and reduced management overhead.
Trellix MNE makes sure that you have consistent enforcement of policy and compliance across your encryption technology stack. You can also use the report-only feature of Trellix MNE without having to actively manage FileVault or BitLocker. Trellix MNE provides comprehensive reports that give you complete visibility of your organization's encryption status. Report queries can also be used as a dashboard monitor that is automatically updated every 5 minutes.
Note: We provide support only for the Trellix MNE management solution, and not the underlying FileVault or BitLocker encryption technology. If you encounter any issues with FileVault or BitLocker technology, contact Apple for FileVault support and Microsoft for BitLocker support.
Key features
You can manage FileVault or BitLocker through Trellix MNE.
Manage FileVault on any Mac hardware that can run macOS directly from Trellix ePO - SaaS. For a list of supported macOS versions, see KB91980.
Manage BitLocker on Windows systems directly from Trellix ePO - SaaS, without the need for a separate Microsoft BitLocker Administration and Monitoring (MBAM) server. For a list of supported Windows versions, see KB91980.
Report compliance in various reports and dashboards.
Configure BitLocker To Go to manage removable media on BitLocker encrypted client systems.
Support FileVault and BitLocker recovery by using administrative recovery through the Trellix ePO - SaaS console.
Rotate recovery keys periodically, or after a recovery workflow occurs in Trellix ePO - SaaS.
Make sure that on Windows systems, when taking over BitLocker management, only Trellix MNE-managed keys remain, to avoid older (insecure) keys being accessible on the system.
Import recovery keys manually. This is needed for FileVault. (Mac systems only).
Report status on Trellix Endpoint Security (ENS) for Mac console (Mac systems only).
Protect and own your data by using your own AWS Customer Master Key (CMK) in Trellix ePO - SaaS.
How it works
Trellix MNE provides components that are installed on Trellix ePO - SaaS, and on all Microsoft Windows and Mac computers that you want Trellix MNE to manage.
The diagram shows Trellix MNE components and workflows that manage and report on encryption status for endpoints using BitLocker or FileVault.
The Trellix ePO - SaaS administrator configures Trellix ePO - SaaS policies, runs Trellix ePO - SaaS queries and reports, and verifies the status of Trellix ePO - SaaS managed endpoints.
The Trellix Agent package is deployed to the client systems. Trellix MNE is installed and activated on the endpoint. Policies are assigned to the client system.
After successful Trellix MNE activation, the endpoint is protected by BitLocker, according to the applied authentication policy. Trusted Platform Module (TPM) provides platform authentication support, without the need for preboot authentication (PBA). All chosen authentication methods other than TPM require the user to authenticate before restarting the endpoint.
Trellix MNE obtains the recovery key of the system and sends it to Trellix ePO - SaaS. This recovery key is needed to recover the system in situations where the system crashes, malfunctions, or has accessibility issues.

Product components
The Trellix MNE software packages are available on Trellix ePO - SaaS, if you have an Trellix MNE license. This allows Trellix MNE to be installed on client systems where you can apply policies received from Trellix ePO - SaaS.
Getting started with Trellix MNE on Trellix ePO - SaaS
To start using Trellix MNE on Trellix ePO - SaaS, you must first sign up for an Trellix ePO - SaaS account and activate it. For more information about creating an Trellix ePO - SaaS account, see Getting Started with Trellix ePO - SaaS
Once you log on to Trellix ePO - SaaS, you can access Trellix MNE if you have purchased an Trellix MNE license.
Migrating Trellix MNE to Trellix ePO - SaaS
You can migrate Trellix MNE 4.x and later from Trellix ePO - On-prem to Trellix ePO - SaaS.
Trellix Preboot and Network Unlock features are not supported in Trellix ePO - SaaS. During migration, if a node is protected by either Trellix Preboot or Network Unlock, the authentication type of that system changes in accordance to the configured policy. That is, the next available authentication type in the precedence order is enforced.
For example, consider that a system is configured using an on-premises policy with the authentication type Preboot → TPM → Password. After migration to Trellix ePO - SaaS, this changes to TPM → Password. So, if an endpoint is protected by Preboot, you can see that the system after migration is protected by TPM.
The following options are available if your endpoints are protected either by Trellix Preboot or Network Unlock.
Replace Preboot and Network Unlock authentication with one of the authentication methods that is supported by Trellix ePO - SaaS. For example, TPM and PIN.
Migrate the endpoint as is, but expect that protection might be disabled on the first policy enforcement while the new authentication options are configured. In addition, users might be prompted to enter a password or PIN in accordance with the policy.
Note: Drive Encryption Go (DEGO) is not supported in Trellix ePO - SaaS. Make sure that DEGO is uninstalled from all endpoints before attempting migration.
Invite users to manage Trellix MNE (for use with Trellix ePO - SaaS)
As an administrator, you can add users and assign specific roles to them for using Trellix MNE.
Before you begin
Make sure that you have administrator permissions to use Trellix ePO - SaaS.
Task
Log on to Trellix ePO - SaaS as an administrator.
Select Menu → Configuration → Users & Roles.
On the Users & Roles page, click Invite User.
On the Invite new user page, type the first name, last name, and the email address of the user you want to invite.
Click Invite.
Results
An invitation email is sent to the user with activation instructions. This email is valid for 7 days. Once you add the user, their names appear on the Users panel.
Assign roles to users (for use with Trellix ePO - SaaS)
You can limit or extend users' access to Trellix MNE by assigning or unassigning roles. All roles have specific permission sets. You can't assign or unassign roles for your own account.
Before you begin
Make sure that you have administrator permissions to use Trellix ePO - SaaS.
Task
Log on to Trellix ePO - SaaS as an administrator.
Select Menu → Configuration → Users & Roles.
On the Users & Roles page, select a user from the Users panel.
The user details, assigned roles, and unassigned roles for the selected user appears on the right pane.
Select the required roles from the Unassigned Roles list.
The Roles panel lists the default roles.
Key Service: Manage master key registrations — Allows the user to manage and view master key registrations.
Key Service: View master key registrations — Allows the user to only view master key registrations.
Trellix Cloud Account Administrator — Allows the user to view, create, and change users and roles; user can also view subscriptions and update customer profiles. This role does not include the Key Service roles.
Trellix ePO - SaaS Administrator — Provides administrator permissions for Trellix ePO - SaaS and allows the user to:
View Automatic Responses and view response results in Server Task Log.
View Server Tasks and task results in Server Task Log.
View client tasks and policies in Trellix Agent.
View policies in McAfee® Data Exchange Layer (DXL).
View policies and change policies in Trellix Management of Native Encryption.
View Policy Assignment Rules.
View reports in Trellix Management of Native Encryption.
View Audit Log, Client Tasks, Dashboards, Queries & Reports, and Threat Event Log.
View properties, search, and import recovery keys in Trellix Management of Native Encryption.
View System Tree and Systems.
Click Save Changes.
Results
The selected roles now appear in the Assigned Roles list.
Create a role (for use with Trellix ePO - SaaS)
You can use the default permissions for key service and Trellix ePO - SaaS to create a customized role for your user.
Before you begin
Make sure that you have administrator permissions for Trellix ePO - SaaS.
Task
Log on to Trellix ePO - SaaS as an administrator.
Select Menu → Configuration → Users & Roles.
On the Users & Roles page, click Add Role.
Enter a name for the role.
From the Key Services and Trellix ePO - SaaS drop-down lists, select the required permissions.
The selected permissions now appear in Assigned Permissions.
Click Save Changes.
Results
The newly created role appears in the Roles panel. You can now assign this role to selected users.
Delete users and roles (for use with Trellix ePO - SaaS)
You can remove all roles and users when they are no longer in use. The default roles can't be deleted.
Before you begin
Make sure that you have administrator permissions to use Trellix ePO - SaaS.
Task
Log on to Trellix ePO - SaaS as an administrator.
Select Menu → Configuration → Users & Roles.
On the Users & Roles page, select the user or role that you want to delete.
Click Delete, then click Confirm.
Results
The user or role is removed from the Users or Roles list.
Duplicate a role (for use with Trellix ePO - SaaS)
You can create a copy of an existing role and customize it as needed.
Before you begin
Make sure that you have administrator permissions to use Trellix ePO - SaaS.
Task
Log on to Trellix ePO - SaaS as an administrator.
Select Menu → Configuration → Users & Roles.
On the Users & Roles page, select the role that you want to copy.
Click Duplicate.
Results
A copy of the existing role is created. You can edit the role name, assign or unassign permissions, and save the role.
Managing master keys (for use with Trellix ePO - SaaS)
Trellix MNE supports data protection through a hierarchical key structure. Encryption keys are protected at the root level by a master key that is controlled by the customer and protected by customer credentials.
Note: This topic is only applicable for Trellix MNE on Trellix ePO - SaaS.
Trellix MNE works with several services to create a master key to protect your data.
Tenant Key Service (TKS) — An encryption key service on Trellix ePO - SaaS that provides a key to encrypt or decrypt data that can be protected using the Customer Master Key (CMK).
Amazon Web Services (AWS) — A cloud computing service from Amazon that provides on-demand computing platforms for individuals and organizations.
AWS Key Management Service (KMS) — An AWS-managed service that allows you to create customer master keys that can be used to protect your data.
AWS Customer Master Key (CMK) — An encryption key created by AWS Key Management Service (KMS).
How master keys work
Trellix MNE on Trellix ePO - SaaS is preconfigured with a default Trellix master key for encryption and decryption services to work with zero setup.
Trellix owns the AWS KMS where the default master key is provisioned and the same master key is shared among all customers.
Important: We recommend that you configure TKS with your own master key to enforce strict cryptographic separation between your data and the data of other Trellix customers. Using your own master key allows you to stay in full control of your data with the ability to revoke access at a moment's notice.
For information about creating your own master key, see Amazon Web Services documentation at: https://docs.aws.amazon.com/kms/latest/developerguide/create-keys.html
Create a Customer Master Key on AWS (for use with Trellix ePO - SaaS)
Creating your own Customer Master Key (CMK) on Amazon Web Services (AWS) gives you more control in keeping your data secure.
Before you begin
Make sure that you have an AWS account and a user account with appropriate permissions.
For more information about creating an AWS account, or about creating keys and users on AWS, see the AWS documentation.
Task
Log on to the AWS Management Console.
Select the required AWS region from the Region drop-down list.
On the AWS Management Console homepage, use the Find Services field to search for and select the Key Management Service link.
On the navigation pane, select Customer managed keys, then click Create Key.
Add an alias and description for the key and click Next.
[Optional] Add a tag key and a tag value to identify your CMK, then click Next.
Tags are key value pairs that identify and group resources in your AWS account. You can add any tags you think are useful.
On the Define key administrative permissions page, specify any users who should have administrative permissions to the key and click Next.
Note: To prevent the selected administrators from deleting this CMK, deselect Allow key administrators to delete this key in the Key deletion section at the bottom of the page.
On the Define key usage permissions page, do not define any key user permissions and click Next.
The access permissions for Trellix are set up through an assumable role. See Create an assumable role on AWS.
To define key users and roles, select the Identity Access Management (IAM) users who are using this account, and click
Next.
10. Review or edit the policy and click Finish.
When the key is created, it appears in the Customer managed keys list.
What to do next
Before you can register your master key on Trellix ePO - SaaS, you must have your key ARN and create an assumable role.
On the Customer managed keys page, click Key ID or Alias to open the Key Details page. In the General Configuration section, make a note of the Amazon Resource Name (ARN) value displayed. ARN value is needed when registering your CMK on Trellix ePO - SaaS.
A sample ARN value looks like this: arn:aws:kms:eu-west-2:<account_id>:<key_id>. For example: arn:aws:us-east-1:123456789012:key/12345678-1234-1234-1234-123456789012
Create an assumable role on AWS.
Create an assumable role on AWS (for use with Trellix ePO - SaaS)
An assumable role is an Identity Access Management (IAM) identity that is used by a trusted identity such as Trellix. Trellix uses this role to access resources in your AWS account (for example, the CMK that you created on AWS). You must create an IAM role with permissions to access your CMK that Trellix can assume to protect your data before you register your CMK on Trellix ePO - SaaS.
Before you begin
You must have your CMK created on AWS.
You must have your Trellix ePO - SaaS tenant ID. This is included in the Welcome to Trellix email.
Task
Log on to the AWS Management Console.
Select Services → IAM.
From the navigation pane, select Roles, then click Create role.
On the Select type of trusted entity page, select Another AWS account and enter 307653271100 as the account ID of the Trellix AWS account.
[Mandatory] Select Require external ID to add extra security to your role, and click Next: Permissions.
You must add your tenant ID as the external ID.
Important: When Trellix tries to assume the role, Trellix passes your tenant ID as the external ID. If you have entered an external ID that is different to your tenant ID, Trellix can't register your CMK with Trellix ePO - SaaS.
On the Attach permissions policies page, click Create policy, then select the JSON tab and paste the following snippet (replace <your_key_arn> with the ARN of the CMK that you created earlier):
{
"Version": "2012-10-17",
"Statement": [
{
"Action": [ "kms:Encrypt", "kms:Decrypt", "kms:ReEncrypt*", "kms:GenerateDataKey*", "kms:DescribeKey"
],
"Resource": "<your_key_arn>",

"Effect": "Allow"
}
]
}
Note: These permissions allow Trellix to encrypt and decrypt data using your CMK, but not provide permissions to add new keys or delete keys.
Click Review policy, then enter a policy name and click Create policy.
This navigates back to the list of all policies in IAM. You can search for the name of your policy to make sure it was created successfully.
Select the Create role tab.
On the Attach permissions policies page, choose the policy to attach to your new role and click Next:Tags.
[Optional] Add a tag key and a tag value to identify your CMK, then click Next: Review.
Tags are key value pairs that identify and group resources in your AWS account. You can add any tags you think are useful.
On the Review page, enter a name for the role and click Create Role.
This navigates back to the list of roles in IAM. You can refresh the list and search for the name of your policy to make sure it is created successfully.
What to do next
From the list of roles in IAM, search and select your role. On the Summary page of the role, make a note of Role ARN. This is needed while configuring your CMK on Trellix ePO - SaaS.
Register your master key (for use with Trellix ePO - SaaS)
To enable use of your AWS Customer Master Key (CMK) by Trellix MNE, you must first register your master key with Trellix ePO - SaaS.
Before you begin
Make sure that you have:
Key ARN for your master key on AWS.
Role ARN for the assumable role that you created on AWS.
Note: Trellix MNE uses a default key provided by Trellix until you configure your own master key.
Task
Log on to Trellix ePO - SaaS as an administrator.
Select Menu → Configuration → Settings.
From the navigation pane, select Master Keys.
Click Edit.
On the Edit Master Keys page, select Actions → Register master key.
On the Register master key dialog box, enter your Key ARN, Role ARN, and an optional description.
Click OK.
Results
Your master key is now registered and appears in the list of keys together with the default Trellix key. To start using your master key to protect your data, you must now activate it.
Activate your master key (for use with Trellix ePO - SaaS)
Unless otherwise configured, data is encrypted by the Trellix default key. You must activate your master key in order to change the encryption key to your own master key.
Before you begin
Make sure that you have registered your master key on Trellix ePO - SaaS.
Task
Log on to Trellix ePO - SaaS as an administrator.
Select Menu → Configuration → Settings.
From the navigation pane, select Master Keys.
Click Edit.
On the Edit Master Keys page, select Actions → Set master key as active.
Results
The Status column for the master key now shows Active.
Revoke master keys (for use with Trellix ePO - SaaS)
You can remove a master key from the Server Settings page if it's no longer needed.
Before you begin
Make sure that your registered AWS master key on Trellix ePO - SaaS is not active.
Note
The key can't be revoked if it is in the active state. The default Trellix key also can't be revoked.
Task
Log on to Trellix ePO - SaaS as an administrator.
Select Menu → Configuration → Settings.
From the navigation pane, select Master Keys.
Click Edit.
On the Edit Master keys page, select the checkbox next to the AWS master key.
Select Actions → Revoke master key.
Results
The revoked master key is removed from the master keys list.
Master key settings (for use with Trellix ePO - SaaS)
You can access the Master keys page from Configuration → Settings. Option definitions
Option | Definitions |
Time to live | The maximum time that Trellix can decrypt your data without accessing your master key. Changing this value improves performance and reduces your AWS costs, because Trellix will access your AWS CMK less often. But, this can also affect your security profile because there will be a period after restricting access to your AWS CMK, when Trellix can still decrypt your data. |
Register master key | Registers your master key on Trellix ePO - SaaS.
|
Revoke master key | Removes an inactive master key from the Master keys page. |
Set master key as active | Sets the selected master key as the active key. Note: Trellix master key is the default active key. |
Managing policies
You can manage the Trellix MNE client systems from Trellix ePO - SaaS through a combination of product policies. Assign policies to the required client systems to make sure that systems are managed and function as specified.
What is a policy?
A policy is a collection of settings that you create in Trellix ePO - SaaS and assign to the required Trellix MNE client to configure client systems.
When configuring policies for the first time:
Plan product policies for different segments of your System Tree.
Create and assign policies to groups and systems.
To create, edit, and assign policies to systems or groups, see the product documentation for Trellix ePO - SaaS.
Product policies
On the Policy Catalog page, the Trellix MNE policies appear under the FileVault Product Settings, BitLocker Product Settings, and Security Posture Report Settings categories.
FileVault Product Settings
Settings | Description |
FileVault Management | Manage FileVault — Allows you to manage FileVault and receive reports from the client system.
When you turn on FileVault and enforce this policy on the required client systems, users see a pop-up window on their client systems requesting that they restart the system. The user must restart the system to enable FileVault to encrypt the system managed by Trellix ePO - SaaS, or choose to postpone the restart until a more convenient time.
specify how frequently the recovery key is to be rotated. This improves security by reducing the validity period of each individual recovery key.
on client — Enable this option to allow users to import the recovery key on client systems. This is useful if end users use the FileVault application to generate new recovery keys.
recovery key on already enabled systems — If FileVault is already enabled by the user when Trellix MNE policy is enforced, the client system prompts the user to authenticate using their FileVault password. Once authenticated, the client system recovery key can be queried from FileVault and is escrowed to the Trellix ePO - SaaS database. Note: If users ignore this request, system recovery cannot be achieved as no recovery key can be escrowed to Trellix ePO - SaaS; FileVault only releases the current recovery key if authentication is provided. Note:
Note: On enabling this option, the Password Settings and Client Messaging functions are disabled. Note: Do not manage FileVault — When enforced, Trellix MNE does not manage FileVault.
If Trellix MNE manages FileVault, or if report-only mode is selected, the client system reports the following information to Trellix ePO - SaaS:
|
Settings | Description |
Password Settings | Apply password content rules — Allows you to set password settings on macOS, which enforces these password settings on the client system.
password after the specified number of days.
|
Client Messaging | Display the following message, instead of the default, when enabling FileVault — The user receives this message when FileVault is enabled. If left empty, a default message is provided. Display the following login banner — Enable this option and provide a logon banner after FileVault authentication. Display the following message, instead of the default, when a third party application or user disables FileVault — The user receives this message if FileVault is disabled by anything other than Trellix MNE. If left empty, a default message is provided. |
BitLocker Product Settings
Settings | Description |
Show/Hide Advanced | Click to show or hide advanced settings within the policy page. All policy options have suitable defaults if you do not want to define advanced settings. |
BitLocker management |
Note: Make sure to note that the encryption strength cannot be changed on a previously encrypted client. To change the encryption strength, BitLocker needs to be decrypted, disabled, and then re-enabled by Trellix MNE. Note:
|
Settings | Description |
Note: This algorithm is supported on Windows 10 version 1511 and above systems only. Older systems fall back to the AES-128 algorithm. Note:
Note: This algorithm is supported on Windows 10 version 1511 and above systems only. Older systems fall back to the AES-256 algorithm.
|
Settings | Description |
systems to make sure that any pre-existing non-Trellix MNE recovery keys are removed.
Trellix MNE does not manage BitLocker.
If Trellix MNE manages BitLocker, or report-only mode is enabled, the client system reports the following information to Trellix ePO - SaaS:
|
Settings | Description |
Note: BitLocker protection is suspended when the administrator changes the policy to change protector on operating system drive during the switch-over period. Otherwise, if switching authentication method, the endpoint is unprotected until the new authentication method is fully applied. Note:
| |
System authentication |
authentication and a PIN as additional security for TPM supported client systems.
an enhanced PIN number as an additional security for TPM supported client systems. |
Settings | Description |
Note: It is recommended to enable the hardware test option under BitLocker advanced settings to make sure pre-boot supports enhanced PINs. Note:
supported — Allows you to use an enhanced PIN as additional security for TPM supported client systems. Note: It is recommended to enable the hardware test option under BitLocker advanced settings to make sure pre-boot supports enhanced PINs. Note:
|
Settings | Description |
support TPM. Note: If the Use Trusted Platform Module (TPM), Also use PIN, and Fall back to Password if no TPM is available (Windows 8 and above) options are all enabled and the current protector is the passphrase protector, then the client system is compliant to the policy. Note:
Note: If you enable this option, Windows 7 systems automatically fall back to using TPM with PIN, as password is not supported for Windows 7 systems. | |
Authentication Settings | Maximum number of times user can postpone activation (1-10) — Enable this option and enter the maximum number of times from 1 to 10 to postpone activation. Click Show Advanced to access this setting. |
BitLocker advanced settings | You can choose to enable, disable, or not manage the following options:
|
Settings | Description |
tablets) that indicate no pre-boot input support (use with caution) — Enable this option to allow activation on tablets.
significantly speeding up initial encryption. This is applicable for systems installed with Windows 8 or above. Note: Sensitive data that was previously deleted from the file system might not be protected, as not all sectors are protected.
|
Settings | Description |
data to unprotected volumes until they are fully protected, thus improving data security.
(Windows 8 and above) — Enable this option to ensure that BitLocker only activates with self-encrypting drives. Note: From Windows 10 Build 18317, software-based encryption is the BitLocker default. See https://bit-tech.net/ news/tech/software/microsoft-flips-bitlocker-encryption-default/1/
|
Security Posture Report Settings
Security posture reporting allows you to report the endpoints that meet your required security posture settings for your organization, and those that do not.
The security posture report settings allow you to define the criteria for securing endpoints. This policy has no effect on the management of the endpoint; it simply defines the tests that the endpoints should run to assure its data protection security posture.
Each specific posture test passes unless there is a specific reason for failing. For example, a system without data volumes passes all data volume tests, since there are no data volumes to fail. In other words, this reporting is primarily designed to report failures against specific criteria.
Note: You can view the overall result of security posture reporting tests by navigating through Menu → Systems → System Tree →
Systems tab, selecting the required system, and then clicking Native Encryption → Security posture reporting.
Settings | Description |
Security posture reports apply to: |
Note: If the system doesn't have data volumes, the data volume tests pass each of the posture tests. |
Security posture reporting: |
— Enable this option to report that the system is secure only if the selected volume types require user authentication or TPM authentication.
encryption strength of: — Enable this option to report that the system is secure only if the selected volume types use at least:
Note: Systems that are activated with higher strength Algorithm AES-256 and Security Posture set to Algorithm AES-128 displays as pass.
— Enable this option to report that the system is secure only if the selected volume types are FIPS compliant. Note: Systems that are activated before they are managed by Trellix MNE cannot be verified as FIPs compliant |
Enforce Trellix MNE policies on a system
Enable or disable policy enforcement on a client system. Policy enforcement is enabled by default, and is inherited in the System Tree.
For more information about performing this task, see the product documentation for Trellix ePO - SaaS.
Task
Log on to Trellix ePO - SaaS as an administrator.
Select Menu → Systems → System Tree → Systems tab, then under System Tree, select the group where the system belongs. The list of systems belonging to this group appears in the details pane.
Select a system, then click Actions → Agent → Modify Policies on a Single System.
Select Management of Native Encryption, then click Enforcing next to Enforcement status.
Select Break inheritance and assign the policy and settings below to change the enforcement status.
Next to Enforcement status, select Enforcing, then click Save.
Results
After restarting, the client system communicates with Trellix ePO - SaaS and pulls down the assigned Trellix MNE policies and encrypts the system according to the defined policies.
Enforce policies to a group
Enable or disable policy enforcement for a product on a System Tree group. Policy enforcement is enabled by default, and is inherited in the System Tree.
Task
Log on to Trellix ePO - SaaS as an administrator.
Select Menu → Systems → System Tree → Assigned Policies, then select a group in the System Tree.
From the Product drop-down list, select Management of Native Encryption, then click Enforcing next to Enforcement
Status.
To change the enforcement status, select Break inheritance and assign the policy and settings below.
Next to Enforcement status, select Enforcing.
Select whether to lock policy inheritance so that groups and systems that inherit this policy can't break enforcement, then click Save.
Retain non-MNE authentication protectors on endpoints
You can configure the Trellix MNE policy so that the existing non-Trellix MNE authentication protectors configured on endpoints are retained.
Task
Log on to Trellix ePO - SaaS as an administrator.
Select Policy → Policy Catalog.
From the Products pane, select Management of Native Encryption, then under BitLocker Product Settings, select a policy to edit.
In the System Authentication tab, select Keep existing non-MNE authentication protector.
Click Save.
Results
The selected Trellix MNE authentication protectors are ignored for endpoints that have an active non-Trellix MNE authentication protector. If none of the Trellix MNE authentication protectors are selected and the Keep existing non-MNE authentication protector is selected, then only systems with non-Trellix MNE authentication protectors are secured.
Managing client systems
System management allows you to import system information into Trellix ePO - SaaS. This is useful in the process of installing
Trellix MNE and viewing the list of FileVault or BitLocker users.
Trellix ePO - SaaS manages client systems through a combination of product policies. You can identify systems that require the same policy settings, and place them in a system group. This grouping allows you to update the policy settings to all systems in that group at the same time.
Customize the installation URL and send it to users
You can send the installation URL (also called the Agent Deployment URL) to all users whose systems you want to manage with
Trellix ePO - SaaS.
After you send the installation URL to the endpoint users in your network, they use a browser to access the installation URL and open the Trellix Smart Installer. The Trellix Smart Installer starts this process:
The Trellix Agent is downloaded to the system.
The system communicates back to Trellix ePO - SaaS and adds the system to the default group, My Group, in the System Tree.
After these communications, the system appears in the System Tree as Managed.
After the Trellix Agent is installed, it downloads the product software you selected when you created the installation URL.
Task
Log on to Trellix ePO - SaaS as an administrator.
Select Menu → Software → Product Deployment.
Enter a group name, select the platform type, then select the type of endpoint protection to deploy.
Click Save.
The Install Protection on Other Computers dialog box displays the installation URL.
Copy the URL to your clipboard.
Email or copy the URL to the systems that you want to manage.
Ask the endpoint users to perform the installation steps for their operating system:
Windows
macOS
Results
Once your endpoint users have installed the Trellix Agent on their systems, the Trellix Agent communicates with Trellix ePO - SaaS, downloads the product software, and brings these systems under Trellix ePO - SaaS management.
Move systems between groups
You can move systems from one group to another in the System Tree. You can also move systems from any page that displays a table of systems, including the results of a query.
Note: In addition to the steps below, you can also drag and drop systems from the Systems table to any group in the System Tree.
Even if you have a perfectly organized System Tree that mirrors your network hierarchy and uses automated tasks and tools to regularly synchronize your System Tree, you might need to move systems manually between groups. For instance, you might need to periodically move systems from the Lost&Found group.
Task
Log on to Trellix ePO - SaaS as an administrator.
Select Menu → Systems → System Tree → Systems, then browse and select the systems.
Click Actions → Directory Management → Move Systems.
Select whether to enable or disable, or to not change the System Tree sorting on the selected systems when they are moved.
Select the group where you want to place the systems, then click OK.
Using the System Tree options to recover a system
Viewing a compliance report, importing a recovery key, or recovering a system can be done from System Tree.
When you navigate to Menu → Systems → System Tree, select the required system, then click Actions → Trellix Management of Native Encryption, the following options are displayed:
Compliance report — Allows you to view the report, system, and native encryption properties for the selected system and to verify if the system is compliant with the configured policies.
Import FileVault recovery key — Allows you to manually import the recovery key of the Mac systems to the Trellix ePO - SaaS database using the Import FileVault recovery key by Machine Node page.
Trellix Management of Native Encryption Recovery — Allows you to recover a system, if a user reports accessibility issues to that system. To recover a system, select the required system in the System Tree, then click Actions → Trellix Management of Native Encryption → Trellix Management of Native Encryption Recovery to open the recovery key for that system. You must securely pass that recovery key to the user, so that the user can recover the system.
Maintenance mode on BitLocker systems
This feature allows you to temporarily disable preboot authentication on BitLocker systems, to roll out Windows or software
updates that might require a system reboot. To use this feature, the maintenancemode-x.x.x.x.exe file must be copied to the system, and executed with command-line parameters within the roll-out scripts.
Maintenance mode disables BitLocker protection and all subsequent enforcement of Trellix MNE policy, until the specified number of reboots have occurred, or maintenance mode is explicitly cleared. Once cleared, system protection is restored to its original state on next local policy enforcement.
An API version is used to verify whether the maintenance mode executable is compatible with the installed version of Trellix MNE. To test for compatibility, run the command maintenancemode-x.x.x.x.exe --version and verify the output.
Note: The maintenance mode executable requires administrator rights to run.
To restore BitLocker protection immediately, you can trigger a local policy enforcement from the Trellix Agent by calling
CmdAgent.exe, within your scripts. For more information about using command-line switches with CmdAgent, see KB52707.
Examples
For command-line options, run maintenancemode-x.x.x.x.exe --help.
Enter maintenance mode, allowing for 3 reboots before maintenance mode is cleared: maintenancemode-x.x.x.x.exe --number-of-reboots 3
Clear the maintenance mode: maintenancemode-x.x.x.x.exe --clear
Obtain the version of the maintenance mode executable, and API versions: maintenancemode-x.x.x.x.exe --version
Managing Trellix MNE reports
Trellix MNE queries are configurable objects that retrieve and display data from the database. These queries can be displayed in charts and tables.
Any query results can be exported to a variety of formats, any of which can be downloaded or sent as an attachment to an email message. Most queries can be used as a dashboard monitor.
Queries as dashboard monitors
Most queries can be used as a dashboard monitor (except those using a table to display the initial results). Dashboard monitors are refreshed automatically on a user‑configured interval (five minutes by default).
Exported results
Trellix MNE query results can be exported to four different formats. Exported results are historical data and are not refreshed like other monitors when used as dashboard monitors. Like query results and query-based monitors displayed in the console, you can drill down into the HTML exports for more detailed information.
Reports are available in several formats:
CSV — Use the data in a spreadsheet application (for example, Microsoft Excel).
XML — Transform the data for other purposes.
HTML — View the exported results as a web page.
PDF — Print the results.
View the standard Trellix MNE reports
You can run and view the standard Trellix MNE reports from the Queries & Reports page.
Task
Log on to Trellix ePO - SaaS as an administrator.
Select Menu → Reporting → Queries & Reports.
On the Groups pane, under the Trellix Groups category, select Trellix Management of Native Encryption.
You can view these standard reports:
Query | Description |
Activation Failures | Displays the list of systems that have failed activation. |
Report data protection security posture | Displays the results of the data protection security posture check on Trellix MNE systems. This report can be used to identify and report those systems that do not meet the definition of a secure system. |
Report native encryption status | Displays the Trellix MNE status of the client systems. |
Report overall encryption status | Displays the encryption status of the client systems. Important: When a volume is locked by BitLocker, the message "Unable to determine status" is displayed for the system overall encryption status. This is because BitLocker doesn't release any information for a locked volume. This is expected behavior. |
Report policy compliance | Reports the level of policy compliance of Trellix MNE systems. This report can be used to identify systems that can't or have not enforced the Trellix ePO - SaaS policy correctly. For example, a system previously encrypted with AES-128 with an AES-256 policy can't transition to AES-256, so it is out of compliance with the Trellix ePO - SaaS policy. |
Report recovery keys | Displays the list of client systems with recovery information. |
Reports users per system | Displays the list of users assigned to a Mac client system, or who have logged on to Windows systems. |
Query | Description |
Report systems in maintenance mode | Displays the systems currently in maintenance mode, where BitLocker protection has been disabled. |
Report systems pending key rotation | Displays the systems where key rotation is pending after a recovery has been performed on the system through Trellix MNE recovery pages . |
Report authentication types for MNE systems | Displays a pie chart showing authentication types for Trellix MNE systems. |
From the Queries list, select the needed query.
Click Actions → Run. The query results appear.
You can also edit or duplicate the query, and view the details.
Click Options → Export Data, make the needed selections, then click Export to export the query data.
Click the .xml link to open the query data or right-click and save the .xml file to the needed location.
Click Close.
Create Trellix MNE custom queries
You can create queries that retrieve and display the details like disk status, users, and product client events for Trellix MNE. With this wizard you can configure which data is retrieved and displayed, and how it is displayed.
Task
Log on to Trellix ePO - SaaS as an administrator.
Select Menu → Reporting → Queries & Reports, then click Actions → New.
On the Feature Group pane, select Management of Native Encryption.
On the Result Types page, select the required query type, then click Next.
On the Chart page, from the Display Result As pane, select the type of chart or table to display the primary results of the query, then click Next.
If you select Boolean Pie Chart, you must configure the criteria to include in the query.
On the Columns page, from the Available Columns pane, select the columns to be included in the query, then click Next.
If you had selected Table on the Chart page, the columns you select here are the columns of that table. Otherwise, these are the columns that make up the query details table.
On the Filter page, from the Available Properties pane, select the required properties to narrow the search results, then click Run. The Unsaved Query page displays the results of the query, which is actionable, so you can take any
available actions on items in any tables or drill-down tables.
Selected properties appear in the content pane with operators that can specify criteria used to narrow the data that is returned for that property.
If the query didn’t appear to return the expected results, click Edit Query to go back to the Query Builder and edit the details of this query.
If you don’t need to save the query, click Close.
If this is a query you want to use again, click Save and continue to the next step.
On the Save Query page, type a name for the query, add any notes, and select one:
New Group — Type the new group name and select one:
Private (Private Groups)
Public (Shared Groups)
Existing Group — Select the group from the list of Shared Groups.
Click Save.
View the standard dashboard
You can view the standard reports from the MNE Dashboard page.
Task
Log on to Trellix ePO - SaaS as an administrator.
Select Reporting → Dashboards and select MNE Dashboard from the drop-down list.
Results
You can view the Trellix MNE dashboard.
Find systems by user name
You can view the Find MNE systems by user name dashboard on the Trellix MNE Dashboards page.
The Find MNE systems by user name dashboard allows the administrator to enter a user name that reports all systems associated with that user.
Task
Log on to Trellix ePO - SaaS as an administrator.
From the Dashboard drop-down list, select MNE Dashboard.
Type the name of the user in the text box and click Go.
Results
The administrator can now view all systems associated with that user.
Create custom Trellix MNE dashboard
Dashboards are collections of user-selected and configured monitors that provide current data about your environment. You can create your own dashboards from query results or use Trellix ePO - SaaS default dashboards.
Task
Log on to Trellix ePO - SaaS as an administrator.
From the Dashboard Actions drop-down list, select New.
Next to Dashboard Name, type a name for the dashboard.
Next to Dashboard Visibility, select one of these options, as needed:
Private — To make the dashboard visible to a specific set of users.
Public — To make the dashboard visible to all users.
Shared with the following permission set(s) — To make the dashboard visible to the specified permission sets.
Click OK.
Click Add Monitor, select the MNE query, and drag and drop to the MNE dashboard.
Trellix MNE client events
While implementing and enforcing the Trellix MNE policies that control how sensitive data is encrypted, you can monitor real‑time client events and generate reports using the Trellix MNE client events query.
Event ID | Event Description | Event Type |
35203 | This event is reported in Trellix ePO - SaaS when the FileVault activation fails with an error message macOS recovery partition is not found. | Critical |
35204 | This event is reported in Trellix ePO - SaaS when an incompatible product is found. For example, Trellix Drive Encryption . | Informational |
Event ID | Event Description | Event Type |
35205 | This event is reported in Trellix ePO - SaaS when FileVault or BitLocker activation is successful. | Informational |
35206 | This event is reported in Trellix ePO - SaaS when the restart prompt appears on the client system. | Informational |
35207 | This event is reported in Trellix ePO - SaaS when the FileVault or BitLocker activation fails with an error message Unsupported operating system found. | Critical |
35208 | This event is reported in Trellix ePO - SaaS when FileVault activation fails with an error message EEMac is active. | Informational |
35209 | This event is reported in Trellix ePO - SaaS when FileVault or BitLocker is already turned on in the client system. | Informational |
35210 | This event is reported in Trellix ePO - SaaS when FileVault activation fails with an error message Unable to retrieve the recovery key from FileVault. | Error |
35211 | This event is reported in Trellix ePO - SaaS when FileVault or BitLocker activation fails with an error message Unknown exception occurred. | Error |
35212 | This event is reported in Trellix ePO - SaaS when the recovery | Informational |
Event ID | Event Description | Event Type |
key is sent to the Trellix ePO - SaaS database successfully. | ||
35213 | This event is reported in Trellix ePO - SaaS when the user is waiting for system to restart. | Informational |
35214 | This event is reported in Trellix ePO - SaaS when Trellix MNE is running in Report and Manage mode. | Informational |
35215 | This event is reported in Trellix ePO - SaaS when Trellix MNE is running in Report only mode. | Informational |
35216 | This event is reported in Trellix ePO - SaaS when Trellix MNE is disabled. | High |
35217 | This event is reported in Trellix ePO - SaaS when macOS logon banner is applied. | Informational |
35218 | This event is reported in Trellix ePO - SaaS when macOS logon banner is removed. | Informational |
35219 | This event is reported in Trellix ePO - SaaS when macOS password settings are applied. | Informational |
35220 | This event is reported in Trellix ePO - SaaS when macOS password settings are disabled. | Critical |
35221 | This event is reported in Trellix ePO - SaaS when disabling | Error |
Event ID | Event Description | Event Type |
FileVault fails because the recovery key is invalid, and the user must manually disable FileVault. | ||
35222 | This event is reported in Trellix ePO - SaaS when disabling FileVault fails because the recovery key is unavailable, and the user must manually disable FileVault. | Error |
35223 | This event is reported in Trellix ePO - SaaS when the Mac serial number is not found. | Error |
35224 | This event is reported in Trellix ePO - SaaS when the volume information is not available. | Error |
35225 | This event is reported in Trellix ePO - SaaS when FileVault user information is sent. | Informational |
35226 | This event is reported in Trellix ePO - SaaS when FileVault is disabled by third-party application or user. | Critical |
35227 | This event is reported in Trellix ePO - SaaS when the encryption is started. | Informational |
35228 | This event is reported in Trellix ePO - SaaS when the encryption is completed. | Informational |
35229 | This event is reported in Trellix | Informational |
Event ID | Event Description | Event Type |
ePO - SaaS when the decryption is started. | ||
35230 | This event is reported in Trellix ePO - SaaS when the decryption is completed, and FileVault or BitLocker is disabled. | Informational |
35231 | This event is reported in Trellix ePO - SaaS when the restart prompt fails to appear. | Error |
35232 | This event is reported in Trellix ePO - SaaS when disabling FileVault or BitLocker fails. | Error |
35233 | This event is reported in Trellix ePO - SaaS when a user is removed from FileVault. | Informational |
35234 | This event is reported in Trellix ePO - SaaS when removing a user from FileVault fails. | Error |
35235 | This event is reported in Trellix ePO - SaaS when the user imports a FileVault recovery key. | Informational |
35236 | This event is reported in Trellix ePO - SaaS when the user fails to import a FileVault recovery key since the key is invalid. | Informational |
35238 | This event is reported in Trellix ePO - SaaS when the system is not compliant with Trellix MNE policy as the local policy changes have been made. | Critical |
Event ID | Event Description | Event Type |
35239 | This event is reported in Trellix ePO - SaaS when the BitLocker GPO policy is overriding the Trellix MNE policy. | Critical |
35240 | This event is reported in Trellix ePO - SaaS when BitLocker fails to activate as TPM is not available, or when changing from password to TPM policy, if TPM is not available, leaving the system in an unprotected state. | Error |
35241 | This event is reported in Trellix ePO - SaaS when BitLocker fails to activate as TPM is not available and fails to fall back to password authentication on Windows 7 systems that do not support the password encryption method. | Error |
35242 | This event is reported in Trellix ePO - SaaS when BitLocker fails to activate as the password policy is not supported on Windows 7 systems. | Error |
35243 | This event is reported in Trellix ePO - SaaS when BitLocker fails to activate as TPMs PIN policy is not supported on Windows 7 systems. | Error |
35244 | This event is reported in Trellix ePO - SaaS when the encryption algorithm strength used to encrypt the disk is weaker than the strength specified in the policy. | Warning |
Event ID | Event Description | Event Type |
35245 | This event is reported in Trellix ePO - SaaS when the encryption algorithm strength used to encrypt the disk is stronger than the strength specified in the policy. | Warning |
35246 | This event is reported in Trellix ePO - SaaS when TPM is not available and the client system has fallen back to password encryption method for authentication. | Informational |
35247 | This event is reported in Trellix ePO - SaaS when the client system has more than one user on the system while activating FileVault. | Informational |
35248 | This event is reported in Trellix ePO - SaaS when the FileVault users have been successfully excluded from inheriting the password policy. | Informational |
35249 | This event is reported in Trellix ePO - SaaS when excluding FileVault users fails from inheriting the password policy. | Error |
35250 | This event is reported in Trellix ePO - SaaS when the recovery key is successfully regenerated on the client system. | Informational |
35251 | This event is reported in Trellix ePO - SaaS when the recovery key fails to regenerate on the | Critical |
Event ID | Event Description | Event Type |
client system. | ||
35252 | This event is reported in Trellix ePO - SaaS when BitLocker activation fails as SafeBoot or Trellix Drive Encryption is installed. | Critical |
35253 | This event is reported in Trellix ePO - SaaS when FIPS mode activation fails on Windows 8 systems. | Critical |
35254 | This event is reported in Trellix ePO - SaaS when password authentication is not supported on Windows 7 systems and falls back to TPM and PIN authentication method. | Informational |
35255 | This event is reported in Trellix ePO - SaaS when Trellix MNE activation is refused due to failed hardware test. | Critical |
35256 | This event is reported in Trellix ePO - SaaS when the hardware test is ignored as FIPS is enabled. | Critical |
35257 | This event is reported in Trellix ePO - SaaS when the key rotation is successful. | Informational |
35258 | This event is reported in Trellix ePO - SaaS when key rotation fails because one or more keys failed to rotate. | Major |
Event ID | Event Description | Event Type |
35259 | This event is reported in Trellix ePO - SaaS when the calculation of compliance to policy fails. For more information, refer to the client logs. | Critical |
35260 | This event is reported in Trellix ePO - SaaS when there are no supported BitLocker volumes. For more information, see KB83141. | Major |
35261 | This event is reported in Trellix ePO - SaaS when a keyboard is not detected for use in preboot environment for tablets/slates and the activation fails. | Major |
35262 | This event is reported in Trellix ePO - SaaS when the non-Trellix MNE recovery keys have been removed. | Informational |
35263 | This event is reported in Trellix ePO - SaaS when the system fails to remove the non-Trellix MNE recovery keys. | Major |
35264 | This event is reported in Trellix ePO - SaaS when key rotation is requested by Trellix ePO - SaaS from the client system. | Informational |
35265 | This event is reported in Trellix ePO - SaaS when the maintenance mode has been disabled successfully. | Informational |
35266 | This event is reported in Trellix ePO - SaaS when the | Informational |
Event ID | Event Description | Event Type |
maintenance mode is active. | ||
35267 | This event is reported in Trellix ePO - SaaS when the maintenance mode fails to activate. | Major |
35268 | This event is reported in Trellix ePO - SaaS when the maintenance mode has ended after the specified number of reboots. | Informational |
35269 | This event is reported in Trellix ePO - SaaS when key rotation was only partially successful (some keys failed to rotate). | Informational |
35274 | This event is reported in Trellix ePO - SaaS when a user successfully changed their password through the Trellix MNE user interface. | Informational |
35275 | This event is reported in Trellix ePO - SaaS when a user successfully changed their PIN through the Trellix MNE user interface. | Informational |
35276 | Activation failed: Hardware encryption is required but not supported. | Informational |
35277 | Hardware encryption is required but drive is already encrypted with software. | Informational |
Event ID | Event Description | Event Type |
35278 | Failed to disable FileVault due to empty UUID. | Error |
35279 | Successfully applied password authentication. | Informational |
35280 | Failed to apply password authentication. | Error |
35281 | Successfully applied TPM authentication. | Informational |
35282 | Failed to apply TPM authentication. | Error |
35283 | Successfully applied TPM and standard PIN authentication. | Informational |
35284 | Failed to apply TPM and standard PIN authentication. | Error |
35285 | Successfully applied TPM and enhanced PIN authentication. | Informational |
35286 | Failed to apply TPM and enhanced PIN authentication. | Error |
35291 | Information | Informational |
35292 | Error | Error |
35293 | Failed to apply any of the authentication methods specified in the policy. | Critical |
35299 | An error occurs while reading Boot Configuration Data. | Error |
Event ID | Event Description | Event Type |
40200 | An error occurs while reading or writing UEFI variables. | Error |
Recovering systems
System recovery is a process of recovering a user's system from system crashes, system malfunctions, accessibility issues, and more. If a user reports any such problems, you must provide the recovery key of the system to the user for the user to recover the system using FileVault recovery tools provided by Apple or BitLocker recovery tools provided by Microsoft.
Note: We don't provide support for FileVault or BitLocker recovery tools. If you encounter any problems with this recovery process, we recommend that you contact Apple or Microsoft Support as appropriate.
How is the key escrowed in the Trellix ePO - SaaS database?
The recovery key can be escrowed in two ways:
When enabling FileVault or BitLocker on a client system using Trellix MNE, Trellix MNE obtains the recovery key of the system automatically and sends it to the Trellix ePO - SaaS database.
If the user has previously enabled FileVault at the point when Trellix MNE is installed on the client system, then one of the following options is applicable:
The system user must enter their FileVault password when prompted to grant Trellix MNE the right to the recovery key
The system user must import their FileVault recovery key on the system
The administrator must import the recovery key of the system manually into the Trellix ePO - SaaS database for the recovery feature to be available for that system.
If none of these actions are taken, recovery is not possible.
Note: You can obtain the recovery key of a client system only if Trellix MNE manages FileVault or BitLocker.
Obtaining the serial number of a Mac system
The serial number of the Mac system can be obtained in two ways:
At the back/side/bottom of your Mac hardware, the serial number of the system is displayed.
When you click the About this Mac option, the serial number of the system is displayed.
Import the recovery key
You might need to manually import the recovery key of a Mac client system to the Trellix ePO - SaaS database using the System Tree or Data Protection menu. The client user can also import the recovery key to the Trellix ePO - SaaS database from the client system.
These tasks must be performed only if the user has previously enabled FileVault.
Note: This is required only for FileVault systems.
Import the recovery key using System Tree
You must manually import the recovery key of the client system to the Trellix ePO - SaaS database using the Import FileVault recovery key by Machine Node page.
Task
Log on to Trellix ePO - SaaS as an administrator.
Select Menu → Systems → System Tree → Systems tab, select the required system, then click Actions → Trellix Management of Native Encryption → Import FileVault recovery key to open the Import FileVault recovery key by Machine Node page.
In the Enter recovery key field, type the recovery key of the system that you obtained.
Click Ok.
Import the recovery key using the Data Protection menu
You must manually import the recovery key of the client system to the Trellix ePO - SaaS database using the Import FileVault recovery key by serial number page.
Task
Log on to Trellix ePO - SaaS as an administrator.
Select Menu → Data Protection → Import FileVault recovery key to open the Import FileVault recovery key by serial number page.
In the Enter serial number field, type the serial number of the system that you received from the user.
In the Enter recovery key field, type the recovery key of the system that you obtained.
Click Ok.
Import the recovery key from a client system
Client users now have an option of importing the recovery key directly from the client system to the Trellix ePO - SaaS database.
Before you begin
This task must be performed by the client user on the client system.
Make sure that the administrator has enabled the FileVault policy for the client system.
Make sure that the administrator has enabled and enforced the Allows users to import recovery key on client policy on to the client system.
Task
Open the Trellix MNE client interface on the client system.
On the left pane, click Encryption.
Enter the new recovery key.
To generate a new recovery key, enter this command: sudo fdesetup changerecovery -personal.
Click Apply.
After the recovery key is escrowed to the Trellix ePO - SaaS database, the last key import time is displayed on the
Encryption pane.
Results
The recovery key is successfully escrowed to the Trellix ePO - SaaS database.
Import the recovery key using the Trellix MNE command-line
Client users now have an option of importing the recovery key directly from the client system, installed with Mavericks operating system or later, to the Trellix ePO - SaaS database using the Trellix MNE command line interface tool.
Before you begin
This task must be performed by the client user who has 'sudo' or 'root' privileges on the client system.
Make sure that the administrator has enabled the FileVault policy for the client system.
Make sure that the administrator has enabled and enforced the Allows users to import recovery key on client policy on to the client system.
Task
Open the Terminal.app on the Mac client system.
Run the command:
sudo /usr/local/McAfee/MNE/bin/MNEMacTool -i xxxx-xxxx-xxxx-xxxx-xxxx-xxxx
Where xxxx refers to a valid recovery key for that particular client system.
Results
The recovery key is successfully escrowed to the Trellix ePO - SaaS database.
Perform system recovery using Trellix ePO - SaaS
When a system needs to be recovered, a recovery key can be obtained from Trellix ePO - SaaS. The recovery key must be passed to the user to recover their system through the Apple FileVault or Microsoft BitLocker recovery tools.
Note: FileVault provides a single recovery key per system. BitLocker provides one or more recovery keys per volume. If multiple recovery keys are available for a single volume (which might happen when Trellix MNE is installed on a previously encrypted system), then any of the recovery keys can be used to recover the volume.
Provide the recovery key to the user
You must provide the recovery key of the client system that is managed by Trellix ePO - SaaS to the user for the user to recover the system using the Apple FileVault or Microsoft BitLocker recovery tools.
Task
Log on to Trellix ePO - SaaS as an administrator.
Select Menu → Data Protection → Trellix Management of Native Encryption recovery.
Note: You can also access Management of Native Encryption recovery: select Menu → Systems → System Tree → Systems tab, select the required system, then click Actions → Trellix Management of Native Encryption recovery.
On the Enter serial number (FileVault) or recovery key ID (BitLocker) page, type the serial number for FileVault systems or recovery key ID for BitLocker systems that you received from the user, then click Next.
This step is not applicable if you access Management of Native Encryption recovery through the System Tree menu, because the serial number or recovery key ID of the system is automatically populated. In this case, multiple keys might be displayed.
The recovery key of the system appears on the Recovery key from serial number/ recovery key ID page.
Note: Provide the recovery key to the user so that the user can recover the system. For FileVault, the recovery key is always a string. For BitLocker in non-FIPS mode, the recovery key is always a string. For BitLocker in FIPS mode, the recovery key is always a file that must be downloaded and managed by Cryptographic Officers.
What to do next
Once the user has received the recovery key, we recommend the user to contact Apple or Microsoft Support for assistance in recovering the client system.
Rotate recovery keys
You can enable rotating the recovery keys when the system recovery is performed through Trellix MNE recovery pages. There might be a delay of up to an hour before the server requests that the client rotates the keys.
Task
Log on to Trellix ePO - SaaS as an administrator.
Select Menu → Configuration → Server Settings.
In the Setting Categories pane, click Trellix Management of Native Encryption, then click Edit to open the Edit Trellix Management of Native Encryption page.
Recovery is performed through MNE recovery pages — Enable this option to rotate the recovery keys when the recovery is performed through Trellix MNE recovery pages.
Note: Key rotation following recovery is not available on macOS systems.
Click Save.
Troubleshooting Trellix MNE on Trellix ePO - SaaS
You can troubleshoot issues related to Trellix MNE on Trellix ePO - SaaS and master keys by verifying how you configured your server settings.
AWS Customer Master Key (CMK) registration failed
The CMK registration can fail if the correct roles are not assigned for keys or if the key is disabled or deactivated. To make sure that the AWS CMK is configured correctly, follow the steps here: Create a Customer Master Key on AWS.
Key revoke failed
Revoking a key can fail if its status is active. You must first change the status of the master key to inactive before you can revoke it. Also, revoking the default Trellix key is not supported.
Key recovery failed
Make sure that the CMK or role is not changed, deleted, or disabled in the AWS console.
Key activation failed
When changing the active master key, both the existing active master key and the prospective active master key must be available for use by Trellix. The role and CMK must not be changed, deleted, or disabled in the AWS console. The role and CMK are required to decrypt your data, which is protected with the existing active master key and then to re- encrypt your data with the prospective active master key.
Issues with missing Trellix MNE policies
Contact Trellix Support or your onboarding team to verify if the Trellix ePO - SaaS account is set up correctly and whether the account has an Trellix MNE license.

