Updated: December 10, 2025
Getting started with Trellix EDR
Overview
Trellix Endpoint Detection and Response (Trellix EDR) is a cloud-delivered service that enables you to detect, investigate, and respond to threats.
Trellix EDR provides continuous data collection and advanced analytics that helps you detect suspicious behavior on your network. Using alert ranking and data visualization, you can quickly understand the threat and take immediate action.
Guided investigation automatically gathers, summarizes, and visualizes evidence from multiple sources and iterates as the investigation evolves. With in-depth understanding of the threat and single-click response capabilities, Trellix EDR enables you to quickly and confidently respond to threats.
Trellix EDR reduces the expertise and effort needed to perform investigations and increases the speed with which analysts can determine the risk of incidents and their root cause. Trellix EDR can be managed using Trellix ePolicy Orchestrator - On-prem or Trellix ePolicy Orchestrator - SaaS in the FedRAMP environment.
For details about Trellix EDR install, upgrade, configuration, etc. see Trellix Endpoint Detection and Response Installation Guide.
For details about Trellix EDR features, how it works, etc. see Trellix Endpoint Detection and Response Product Guide.
The Getting Started Guide (FedRAMP) covers specific information such as activating the Trellix ePO - SaaS administrator account, network ports and URLs, configuration of Trellix EDR and Trellix ePO - On-prem interconnection, etc. in the FedRAMP environment.
Webhook
When creating webhooks using parameters for the Trellix EDR GovCloud environments such as FedRAMP, CRA, etc. use the appropriate API URLs. For URL details, see Server and client requirements.
Activate and configure SSO to log on to Trellix
To activate your Trellix account and configure Single Sign-On, follow these steps:
Use the https://ui.iam.us.trellix-gov.com/ URL to activate your Trellix account. For details, see Activate your Trellix account.
Configure the settings in the Identity Provider page using the https://ui.uam.us.trellix-gov.com/idp_config.html URL to enable SSO using your IdP application. For details, see Configuring Single Sign-On to log on to Trellix.
Server and client requirements
Before you install Trellix EDR, make sure that your server and client systems meet all requirements (KB91345).
For information about Trellix EDR software and hardware requirements, and supported environments, see (KB91345).
Important: The supported Trellix EDR client version for FedRAMP is 4.1.x or later. Below are the minimum supported product versions for Trellix EDR(FedRAMP) managed using Trellix ePO - On-prem.
Table 1 Supported product versions
For the Trellix ePO - On-prem connection to Trellix EDR solution to work within the FedRAMP boundary, you must upgrade the Trellix DXL Broker Extension to version 6.0.3.990 or later. This extension can be obtained from your Trellix Product Download Site and checked in to Trellix ePO - On-prem. It can also be obtained from Trellix ePO - On-prem Master Repository and checked in to Trellix ePO - On-prem.
Note: The Trellix Product Download Site requires entry of a valid Grant Number and associated email address to gain access to products available for download.
Network ports
Trellix EDR uses specific network ports to connect to DXL client and Trellix EDR client.
Note: Make sure your network settings are configured correctly and SSL traffic inspection is disabled on URL or IP address. For details about the default ports required for each component on Trellix ePO - On-prem, see {KB66797}.
URL allow list
You must allow access to Trellix EDR URLs.
Connections are always initiated from the client to the cloud services. You must allow access to Trellix EDR URLs. The Agent wakeup is done by using a DXL Agent wakeup, through an existing DXL connection.
DXL needs to be allowed from the On-premises administrator web browser and Trellix ePO - On-prem server to the following cloud service URLs.
DXL needs to be allowed on endpoints (clients) to Trellix EDR cloud services.
The following IAM URLs can be used to register a tenant in the Cloud Bridge extension.
Table 2 Common paths for Trellix ePO - On-prem and Trellix ePO - SaaS implementations
Table 3 Specific paths - Implementation with Trellix ePO - On-prem
Table 4 Specific paths — Implementation with Trellix ePO - SaaS
Configure Trellix ePO - On-prem and Trellix EDR interconnection
You can set up and configure the existing Trellix ePO - On-prem connections to the Trellix EDR within the FedRAMP boundary. This connection allows the Trellix EDR user interface to monitor or view threat events normally viewed by the Trellix ePO On-prem server.
Task
On the Trellix ePO – On-prem ePO Server, run the following remote command from a web browser, using your values for the variables. Caution with cut & paste regarding spacing.
Template Command:
https://<epo fqdn>:<port>/remote/cloudbridge.updateIAMConfig? newIAMCID=efb532b4d8e914c2619d&newIAMURL=https://iam.us.trellix-gov.com/iam/ v1.0&newIRSURL=https://iam-rs.us.trellix-gov.com/iam-registration-service/ v1.1&newUAMURL=https://api.uam.us.trellix-gov.com/govprod/api/v1&newMVISIONSSOIssuer=https:// iam.us.trellix-gov.com/iam/v1.0&newMVISIONSSOSignInURL=https://ui.iam.us.trellix-gov.com/ &newTPSURL=https://tps.epo.us.trellix-gov.com/govprod/api/v1/tenant/This sets the IAM connection status as OK.
On Trellix ePO - On-prem, select Menu | Server Settings | Trellix CB to configure the Trellix ePO - SaaS Cloud Bridge.
This step must be performed using the Trellix EDR Tenant administrator user credentials.
Note: The Tenant administrator user must not have been onboarded in Trellix ePO - SaaS.
Select Menu | Users to add details and configure the Trellix Tenant administrator user in the Trellix ePO - On-prem server.
Note: This is not a mandatory step.
Select Menu | Server Settings to configure DXL Cloud Databus with the Trellix EDR Monitoring URL.
FedRAMP UAM URL — https://api.soc.us.trellix-gov.com/cloudproxy/databus/produce
Select Menu | Server Settings | Trellix EDR Settings to make sure that Monitoring Activated indicates True and Connection Status indicates Connection Successful for the Trellix EDR Cloud services.
Note: Once the connection is successful, Monitoring Activated might take one or two minutes to reflect as True.
Log on to the FedRAMP Trellix EDR user interface. Make sure the configuration of Trellix EDR managed using Trellix ePO On-prem is complete by verifying the below items.
Check the Monitoring dashboard for the traces.
Search endpoint data using the Real-time Search "and" or "or" Historical Search dashboards.
Validate Trellix EDR workflows by performing actions as needed.
Unsupported Trellix EDR features in the FedRAMP environment
The following features in the Trellix EDR commercial environment are not yet available in the FedRAMP environment.
Trellix EDR integration with Trellix Intelligent Sandbox and Trellix SIEM products.
Trellix EDR sending traces to external Amazon S3 bucket