When you configure the ePO - SaaS Cloud Bridge server settings, you can link your ePO - On-prem server to your ePO - SaaS account.
Using ePO - SaaS registration token
The ePO - SaaS Cloud Bridge extension must be installed on your ePO - On-prem server.
Note
You must have a valid ePO - SaaS account with Trellix Account Administrator role assigned.
From ePO - SaaS, select Menu → Configuration → Appliance and Server Registration.
Click Add to add a new registration token.
Select the Client type as Trellix ePolicy Orchestrator - SaaS.
Type the number of appliances or servers you want to register in the Number of clients field and click Save.
To view the generated token, expand Trellix ePolicy Orchestrator - SaaS under Servers. Note down the registration token.
Perform one of these actions if you want to revoke the token:
From the token list, click Revoke under Actions.
Select the token, then select Revoke from the Take Action drop-down list in the token details pane.
To revoke the token from a client - select a token from the token list, then select one or more clients from the Registered Clients pane and select Revoke from the Take Action drop-down list.
Log on to the ePO - On-prem server as an administrator. Select Menu → Configuration → Server Settings, then select Trellix ePO-SaaS Cloud Bridge from Setting Categories. The Trellix ePO-SaaS Cloud Bridge Server Settings page displays these options:
Status— Displays the status of the connection. See Status Messages for detailed status information.
Note
Before you configure your connection, the status is
This server is not linked with Trellix ePO-SaaS.Tenant ID — Displays the tenant ID of the linked ePO-SaaS account.
Cloud Bridge Client ID — Displays the Client ID associated with the token.
From the Trellix ePO-SaaS Cloud Bridge Server Settings page, click Edit.
Enter the Registration Token generated from Step 1.
In the ePO Logon URL section, enter the ePO - On-prem URL which you are using to access the on-premises ePO - On-prem server.
Click Save.
Note
The Cloud Bridge settings page now contains a field ePO Logon URL which can be seen only from ePO - On-prem 5.10.0 Update 7 onwards. This URL is added to the allowed URL list in Identity and Access Management (IAM). This is needed for IAM to redirect the user to the on-premises ePO - On-prem after authentication using Log On With ePO - SaaS feature.
The ePO - SaaS Cloud Bridge Server Settings page displays the status as This server is actively linked, and the linked account as the email address for the Trellix account:
Status — After configuration, above the Refresh button, the status is
This server is actively linked.Trellix ePO-SaaS Tenant ID — The ID for the particular ePO - SaaS tenant.
Cloud Bridge Client ID — The Client ID associated with the token.
ePO Logon URL — Your ePO - On-prem URL which you are using to access the ePO - On-prem server.
Your ePO - On-prem server is now connected to the ePO - SaaS account.
Note
You might see some error messages while linking your ePO - On-prem account with the ePO - SaaS account. For more information, see Common error messages while linking ePO - On-prem with ePO - SaaS account.
To view the connected servers in ePO - SaaS, go to Menu → Configuration → Appliance and Server Registration.
Click Trellix ePolicy Orchestrator - SaaS under Servers.
The Used Clients column displays the number of clients connected to ePO - SaaS.