The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Deploy Trellix 26.x with other Trellix products using Endpoint Upgrade Assistant

Prev Next

When endpoints meet the requirements for upgrading, create a deployment task in Endpoint Upgrade Assistant to deploy Trellix ENS 26.x with other required Trellix products. Endpoint Upgrade Assistant creates a task using the ePO - On-prem branch and product options that you selected on the Prepare and Overview tabs.

When there is a reboot pending related to operating system updates, previous installs, or third-party application changes on the endpoints with Trellix Agent 5.7.4 or later, install or upgrade of Trellix Endpoint Security (ENS) on those endpoints will not occur until the operating system is rebooted. Endpoints will proactively report the reboot pending status to ePO - On-prem. You can query the reboot pending status across multiple systems and it can be viewed in ePO - On-prem dashboards and reports.

Note

For the Intel architectures, you can directly upgrade to version 26.x from version 10.7.0 (November 2022) or later. For the ARM architectures, the upgrades are not supported and upgrade section is not applicable, refer 000014791 for details.

This method deploys the installation packages to all endpoints that are ready to upgrade.

When deploying Trellix ENS on Windows Server 2016, version 1803 or newer, or Windows Server 2019, the Windows Defender installed on your endpoints are disabled automatically. If the endpoints are installed with Microsoft Defender for Endpoint on Windows Server, version 1803 or newer, or Windows Server 2019, then Windows Defender is set to passive mode automatically.

Exporting the analysis details allows you to search, sort, and filter the information more readily; for example, to identify endpoints that need client properties updated (which requires refreshing the ePO - On-prem database).

Task
  1. In ePO - On-prem, select MenuSoftwareEndpoint Upgrade Assistant.

  2. Analyze upgrade requirements for your environment.

    1. Select Trellix Endpoint Security (ENS) 26.x as the version to upgrade to.

    2. Select the endpoints to analyze. The time required to analyze your selection depends on the size of the ePO - On-prem database and the number of endpoints selected

    3. Click Analyze Environment.

    When the analysis is done, you can view it in the Environment Overview chart.

  3. To see the endpoints that Endpoint Upgrade Assistant can upgrade, check Ready for Upgrade Automation on the Overview tab.

  4. Specify whether to upgrade compatible versions of Trellix Agent installed on endpoints.

  5. To select the installation packages to deploy, click the Prepare tab, then select them.

    1. If you are upgrading legacy products, follow instructions in the Policy Migration section to migrate or convert custom settings that you want to save.

      • To migrate settings — Click Endpoint Migration Assistant to run Migration Assistant, which guides you through the process of migrating your policy settings. If you haven't installed Migration Assistant, install and run it now. If you've already migrated your settings, you can skip this step.

      • To convert other product settings — Click the link to the technical article for instructions.

      Note

      The Endpoint Migration Assistant supports Trellix ENS version 10.7.18 as the final supported version for migrating legacy settings. This version limitation applies to all migration workflows.

    2. In the Packages Required for Upgrade Automation section, select the ePO - On-prem branch to deploy the upgrade from.

    3. For each installation package listed, resolve issues that are highlighted in red under the Notes section.

      • Select product version to install — If multiple versions are checked in to the selected ePO - On-prem branch, select the version you want.

        • To install a product — Select the version from the drop-down list.

        • To install an Trellix ENS update — Select the Hotfix number from the drop-down list.

        • To take no action on a product — Select Do not install or Do not upgrade.

      • Incompatible versions of this product were detected — Select a compatible version to upgrade to.

    4. If product extensions are required, install them on the ePO - On-prem server.

    5. Click Refresh to confirm that your server is up to date.

      This refreshes only the information on the Prepare tab without fully re-analyzing your selected environment.

    6. Repeat substeps c-e until all required software is checked in.

      Best practice: If you plan to deploy upgrades using ePO - On-prem, click Copy Command Line to copy the command-line options, then paste them into the product deployment task.

  6. On the Deploy & Track tab, click Create Deployment Task.

    1. On the Create Deployment Task page, specify a name for the task.

      The branch and product options that you selected on the Prepare and Overview tabs appear. If you want to change them, cancel this task, select the correct settings on those tabs, then begin this step again.

    2. For Policy Migration, select the checkbox to acknowledge that one of the following is true:

      • You have migrated your legacy custom policies and client tasks that you want to save.

      • You want Trellix Default policy settings to be enforced.

      • You aren't migrating your settings.

    3. Specify when to run the deployment task.

    4. Select the endpoints to upgrade.

      By default, both workstations and servers are upgraded. To change this, you can select individual endpoints from a list.

    5. Click Create, verify that the information for the task is correct, then click OK.

  7. On the Deploy & Track tab, under Deployment Status, verify that the deployment task completed successfully.

To verify that Trellix ENS installed on your endpoints, select MenuReportingDashboards, then select Endpoint Security: Installation Status. Check that version 26.xxxx is installed on the correct number of endpoints.