Last Updated: September 11, 2024
FileVault product settings
The product policies provide you with the settings that are required for FileVault management, password settings, and client messaging.
Option definitions
Option | Definition |
FileVault Management | Manage FileVault — Allows you to manage FileVault and receive reports from the client system.
When you turn on FileVault and enforce this policy to the required client systems, users will see a pop-up message on their client systems requesting that they restart the system. The user must restart the system to enable FileVault to encrypt the system managed by Trellix ePO - On-prem, or choose to postpone the restart until a more convenient time.
|
Option | Definition |
Note: If users ignore this request, their system can't be recovered because no recovery key can be escrowed to Trellix ePO - On-prem; FileVault will only release the current recovery key if authentication is provided.
5.2.x.x on the Mac client system, then FileVault will be enabled only if DEGO tests pass. |
Option | Definition |
Note: Make sure that you have already installed EEGO.zip(DEGO extension) before enabling this option. For more information about the DEGO extension, see the Trellix Drive Encryption Product Guide.
Note: On enabling this option, the Password Settings and Client Messaging functions get disabled. Do not manage FileVault — When enforced, Trellix Native Drive Encryption will not manage FileVault.
If FileVault is managed by Trellix Native Drive Encryption, or if report-only mode is selected, the client system reports the following information to Trellix ePO - On-prem:
|
Option | Definition |
Password Settings | Apply password content rules — Allows you to set password settings on to OS X, which will enforce these password settings on the client system.
password after the specified number of days.
|
Client Messaging | Display the following message, instead of the default, when enabling FileVault — The user receives this message when FileVault is enabled. If left empty, a default message will be provided. Display the following login banner — Enable this option and provide a login banner for the user to receive this login banner after authenticating into FileVault. Display the following message, instead of the default, when FileVault has been disabled by 3rd party application or user — The user receives this message if FileVault is disabled by anything other than Trellix Native Drive Encryption. If left empty, a default message will be provided. |
Option | Definition |
Duplicate | Duplicates or copies the policy settings with a different name which can be assigned to a different user. |
Save | Saves the Trellix Native Drive Encryption product settings policy. |
Cancel | Exits the current page. |
BitLocker product settings
The product policies provide you with the settings that are required for BitLocker management, operating system volume, and authentication settings.
Option definitions
Option | Definition |
Show/Hide Advanced | Clicking this will show or hide advanced settings within the policy page. All policy options have suitable defaults for those that do not want to define advanced settings. |
BitLocker management |
Note: Make sure that the encryption strength can't be changed on a previously encrypted client. To change the encryption strength, BitLocker needs to be decrypted, disabled, and then re-enabled by Trellix Native Drive Encryption.
|
Option | Definition |
encryption.
Note: This algorithm is supported on Windows 10 and above only. Older systems will fall back to the AES-128 algorithm.
Note: This algorithm is supported on Windows 10 and above only. Older systems fall back to the AES-256 algorithm.
|
Option | Definition |
Encryption takes over management. This is useful for BYOD (Bring your Own Device) systems to make sure that any pre-existing non-Trellix Native Drive Encryption recovery keys are removed.
If BitLocker is managed by Trellix Native Drive Encryption, or report-only mode is enabled, the client system reports the following information to Trellix ePO - On-prem:
|
Option | Definition |
Note: BitLocker protection is suspended when the administrator alters the policy to change protector on the operating system drive during the switch-over period. Otherwise, if switching authentication method, the endpoint is unprotected until the new authentication method is fully applied.
| |
System authentication |
|
Option | Definition |
— Allows you to use an enhanced PIN as additional security for TPM supported client systems. Note: It is recommended to enable the hardware test option under BitLocker advanced settings to make sure pre-boot supports enhanced PINs.
|
Option | Definition |
client systems that do not support TPM. Note: If the Use Trusted Platform Module (TPM), Also use PIN, and Fall back to Password if no TPM is available (Windows 8 and above) options are all enabled and the current protector is the passphrase protector, then the client system is compliant to the policy.
Note: If you enable this option, Windows 7 systems automatically fall back to using TPM with PIN, as password is not supported for Windows 7 systems.
|
Option | Definition |
Authentication Settings | Minimum pin length (4-20) — Enter the minimum PIN length from 4 to 20 that you would like to set for the PIN number. Minimum password length (8-99) — Enter the minimum password length from 8 to 99 that you would like to set for the password. Maximum number of times user can postpone activation (1-10) — Enable this option and enter the maximum number of times from 1 to 10 to postpone activation. |
End user messaging | Provide a custom URL for the BitLocker recovery screen in preboot (Windows 10 and above) — Enable this option to enter a custom URL that will appear in the pre-boot BitLocker recovery screen on Windows 10 systems. The user needs to copy this URL on a web page of another system for information about retrieving the recovery key. Recovery URL — Enter the URL that will appear in the pre-boot BitLocker recovery screen. |
BitLocker advanced settings | You can choose to enable, disable, or not manage the following options:
|
Option | Definition |
Note: Make sure that the user restarts the client system after it's encrypted. The system will not start encrypting until a successful hardware test is completed. This makes sure that systems that do not support BitLocker because of hardware compatibility issues can be easily recovered after they failed to boot.
Note: Sensitive data that was previously deleted from the file system may not be protected, as not all sectors are protected.
|
Option | Definition |
further recoveries (Windows 8 and above) — After a BitLocker recovery, the system boot is re-measured using the TPM to ensure that it is current, therefore reducing the risk of reoccurrence of a recovery scenario caused by a boot measurement change.
| |
Duplicate | Duplicates or copies the policy settings with a different name which can be assigned to a different user. |
Save | Saves the product settings policy of Trellix Native Drive Encryption. |
Cancel | Exits the current page. |
Security Posture Report settings
Security posture reporting allows you to report the endpoints that meet your required security posture settings for your organization.
The security posture report settings allow you to define the criteria for securing endpoints. This policy has no effect on the management of the endpoint; it simply defines the tests that the endpoints run to assure its data protection security posture.
Each specific posture test passes unless there is a specific reason for failing. For example, a system without data volumes passes all data volume tests, because there are no data volumes to fail. This reporting is primarily designed to report failures against specific criteria.
Note: You can view the overall result of security posture reporting tests by navigating to Menu → Systems → System Tree →
Systems. Select the required system, then click Native Encryption → Security posture reporting.
Option definitions
Settings | Description |
Security posture reports apply to: |
Note: If the system doesn't have data volumes, the data volume tests will pass each of the posture tests. |
Security posture reporting: |
|
Settings | Description |
selected volume types require user authentication, network unlock, or TPM authentication.
Note: Systems that are activated with higher strength Algorithm AES-256 and Security Posture set to Algorithm AES-128 displays as pass.
— Enable this option to report that the system is secure only if the selected volume types are FIPS-compliant. (Note: Systems that were activated prior to being managed by Trellix Native Drive Encryption cannot be verified as FIPS compliant) | |
Duplicate | Duplicates or copies the security posture settings with a different name. |
Save | Saves the security posture settings policy of Trellix Native Drive Encryption. |
Cancel | Exits the current page. |
System recovery
The Enter serial number (FileVault) or recovery key ID (BitLocker) pane allows you to type the serial number of the client system to receive the recovery key of that client system.
Option definitions
Option | Definition |
Serial number (FileVault) or recovery key ID (BitLocker) | Type the serial number or recovery key ID of the client system that you received from the user. |
Back | Navigates to the previous page. |
Next | Navigates to the next page. |
Cancel | Exits the current page. |
Recovery key
The Recovery key from serial number/ recovery key ID pane allows you to view the recovery key to send it to the user. Option definitions
Option | Definition |
Recovery keys | Displays the response code. The codes are phonetically arranged in the table. |
Can't find your key? Search for it here. | Allows you to search for your key if you are unable to find your key. |
Close | Exits the current page. |
Import recovery key
You must manually import the recovery key of the client system to the Trellix ePO - On-prem database using the Data Protection or System Tree menu.
Data Protection menu
Option | Definition |
Enter serial number | Type the serial number of the client system that you received from the user. |
Enter recovery key | Type the recovery key of the client system that you received from the user. |
Ok | Imports the recovery key of the client system to the Trellix ePO - On-prem database. |
Cancel | Exits the current page. |
System Tree menu
Option | Definition |
Enter recovery key | Type the recovery key of the client system that you had selected. |
Ok | Imports the recovery key of the client system to the Trellix ePO - On-prem database. |
Cancel | Exits the current page. |
Trellix Native Drive Encryption server settings
Enable rotating the recovery keys when the system recovery is performed through Trellix Native Drive Encryption recovery pages and DPSSP.
Option | Definition |
Recovery is performed through Trellix Native Drive Encryption recovery pages | Enable this option to rotate the recovery keys when the recovery is performed through Trellix Native Drive Encryption recovery pages. |
Recovery is performed through Data Protection Self Service Portal | Enable this option to rotate the recovery keys when the recovery is performed through DPSSP. Note: Key rotation after the recovery process is not available for Mac OS X systems. |
Revealed through web API | Enable this option to reveal the rotated recovery keys through web API. |
Automatic (network) unlock of volumes for system under | Click Edit network rule, select whether you wish to grant or deny access for systems in this branch by selecting GRANTED or DENIED respectively, then click Apply. Browse through the System Tree View, select the required system or group, and click OK. |
Add rule | Click to add the rule selected. |
Save | Saves the server settings for Trellix Native Drive Encryption. |
Cancel | Exits the current page. |