The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Deploy Trellix Endpoint Security (ENS) 26.x when installing using a third-party tool

Prev Next

Install Trellix Endpoint Security (ENS) 26.x on multiple endpoints using the installation packages and a third-party deployment tool.

When there is a reboot pending related to operating system updates, previous installs, or third-party application changes on the endpoints with Trellix Agent 5.7.4 or later, install or upgrade of Trellix ENS on those endpoints will not occur until the operating system is rebooted. Endpoints will proactively report the reboot-pending status to ePO - On-prem. You can query the reboot pending status across multiple systems, and it can be viewed in ePO - On-prem dashboards and reports.

These steps vary depending on the tool. See the documentation for your third-party deployment tool for specific deployment details.

Note

When deploying Trellix ENS on Windows Server 2016, version 1803 or newer, or Windows Server 2019, or newer, the Windows Defender installed on your endpoints can be disabled manually. If the endpoints are onboarded to Microsoft Defender for Endpoint on Windows Server, version 1803 or newer, or Windows Server 2019, or newer, then Windows Defender can be set to passive mode manually. For more information about Windows Defetnder status after installing ENS, refer to the following Community Article

  1. Follow the steps required in your tool for creating an application to deploy and install the software on your endpoints, then specify the installation packages to deploy.

    You need to manually select the installation packages that you downloaded for the product modules.

  2. Enter a command line for installing the product.

    For the installation command line, enter setupEP.exe with the options required for your environment.

    Best practice: Use setupEP.exe ADDLOCAL="tp,atp,fw,wc" to install all the product modules on endpoints without displaying notifications or interrupting user activity.

  3. Specify the information and options required for your environment. These vary depending on your tool. Some examples might be:

    • To detect whether the product needs to be installed — Specify a detection method for determining whether the product is already installed, such as a file, a registry key, or an .msi product code. For example, Trellix ENS 26.x doesn't need to be deployed to systems where the HKEY_LOCAL_MACHINE registry key SOFTWARE\McAfee\Endpoint\AV includes a value for ProductVersion that is equal to 26.x.

    • To configure the user experience — Specify options for running the installer on the endpoint (for example, whether users need to be logged on, whether installation is hidden, and estimated and maximum installation times).

    • To check whether other required products need to be upgraded — Specify any dependencies for required products and versions. For example, if you specify Trellix Agent version 5.6.x and an earlier version is installed, it will be upgraded before Trellix ENS 10.7 is installed.

To verify that Trellix ENS installed on your endpoints, select MenuReportingDashboards, then select Endpoint Security: Installation Status. Check that version 26.xxxx is installed on the correct number of endpoints.