The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Deploy custom Trellix ENS 26.x installation packages generated by Trellix ENS Package Designer 26.x

Prev Next

Use Package Designer 26.x to generate custom Trellix ENS 26.x installation packages that you can deploy to your endpoints with ePO - On-prem 5.10.x , 5.9.x or a third-party deployment tool.

Why use Package Designer

Package Designer lets you generate custom installation packages that:

  • Meet specific requirements — For example, preconfigure port exclusions to ensure that vital communications are not blocked when Firewall is installed, or preconfigure settings required for compliance with security regulations.

  • Replace the default settings with custom settings

  • Install Trellix ENS with settings in place — Settings take effect as soon as installation is complete, rather than waiting for the first policy enforcement.

  • Reduce the size of the installation package.

  • Remove unneeded files.

How Package Designer works

The default installation package contains...

Package Designer 10.7 lets you...

Trellix Default settings

Replace them with preconfigured, custom settings

Installers required to install Trellix ENS:

  • All product modules

  • On 64-bit and 32-bit Windows operating systems

  • Any required monthly updates and Hotfixes

Remove unused installers for:

  • Product modules you don't plan to install

  • 64-bit or 32-bit installers

  • Monthly updates and Hotfixes

To generate the custom installation package, you can run Package Designer on an endpoint where Trellix ENS 26.x is installed. Package Designer uses the current settings and installation packages on the endpoint as the source for the custom package. You can also run Package Designer on any endpoint that has access to the installation files and policy settings you plan to include in the custom package. Deploy the custom package to endpoints using a ePO - On-prem deployment task or a third-party deployment tool.

Best practice: To prevent a policy enforcement from overwriting the custom settings, run Package Designer on an unmanaged endpoint. Alternatively, you can customize the settings using ePO - On-prem, push the updated settings to the endpoint where Package Designer is installed, then run Package Designer on the endpoint.

Package Designer 10.7 is required to customize packages for Trellix ENS 26.x.

Before you begin

  • If they are not available in the Software Catalog (Software Manager on ePO - On-prem 5.9.x), download these installation packages from the Trellix Product Downloads site:

    • Endpoint Security Package Designer Version 26.x.xxxx

    • Endpoint Security Platform – Full Install Version 26.x.xxxx (Required for Threat Protection, Firewall, and Web Control)

    • Endpoint Security Threat Prevention – Full Install Version 26.x.xxxx

    • Endpoint Security Firewall – Full Install Version 26.x.xxxx

    • Endpoint Security Web Control – Full Install Version 26.x.xxxx

    • Endpoint Security Adaptive Threat Protection – Full Install Version 26.x.xxxx (Requires Threat Protection )

    Best practice: For optimal performance and protection, install the same version of the Trellix ENS modules or upgrade all modules to the latest version. All Trellix ENS modules installed or upgraded on a system should originate from the same source package, avoiding a mix and match of installed module versions.

  • On the endpoint where you plan to run Package Designer:

    • Install Package Designer 26.x.

    • Install Trellix ENS 26.x, or make sure the endpoint has access to the installation packages.

    • Configure settings on the endpoint as needed, or make sure the endpoint has access to the custom settings.