The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in mid-October 2026. We hope you enjoy the updated experience.

Configure temporary access to the client interface

Prev Next

You can give temporary Administrator access to the client interface by generating a time-based password.

Before you begin

Make sure that the interface mode for the Trellix Endpoint Security (ENS) Client is set to Standard access or Lock client interface.

Tip

Best practice: During a security incident, disable the time-based password. After a security incident, change the Administrator password and regenerate the time-based password.

Changing the Administrator password invalidates the time-based password. If you change the Administrator password, save the policy, then generate a new time-based password.

If you enable a time-based password after a connectivity failure, then the Trellix Endpoint Security (ENS) Client will not accept the password.



Task
  1. Select MenuPolicyPolicy Catalog, then select Endpoint Security Common from the Products list in the left pane.

  2. From the Category list in the right pane, select Options.

  3. Click the Edit link for an editable policy.

  4. Click Show Advanced.

  5. In the Time-Based Administrator Password section, select Enable time-based password in client interface and specify an expiration date and time. The maximum expiration time is 14 days. The expiration time is relative to the Trellix ePO - On-prem server. For example, if you set the expiration time to 1:00 p.m. PST, the password expires at 4:00 p.m. on client systems in the EST time zone.

  6. Click Generate New Password.

    Two passwords are generated, one for Endpoint Security 10.5 and one for Endpoint Security 10.6 and later.

  7. Write down the auto-generated password and provide it to users to allow temporary access.

  8. Click Save.