Install ePO - On-prem on a single server

Prev Next

Installing ePO - On-prem for the first time requires downloading and starting the installation.

  1. Log on to the Windows Server system to be used as the ePO - On-prem server.

    Use an account with local administrator permissions.

  2. Locate the software you downloaded from the Trellix website and extract the files to a temporary location. Right-click Setup.exe and select Run as Administrator.

    The executable is available in the downloaded ePO - On-prem installation folder.

    Caution

    If you run Setup.exe without first extracting the contents of the .zip file, the installation fails.

    The Trellix ePolicy Orchestrator - InstallShield Wizard starts.

  3. Click Next to continue installation.

    Monitor the installation process for a notification to restart your system.

  4. To select the destination folder, click:

    • Next to install your ePO - On-prem software in the default location (C:\Program Files (x86)\Trellix\ePolicy Orchestrator\).

    • Change to specify a custom destination location for your ePO - On-prem software. When the Change Current Destination Folder window opens, browse to the destination and create folders as needed, then click OK.

  5. The installer discovers active SQL Servers and displays the servers in a drop-down list. Select a SQL server.

    If the installer doesn't discover any SQL server, Click No and specify the SQL server details manually.

  6. In the Database Information, specify information of your database, then click Next.

    1. Specify the Database Server and Database Name.

      Database Server

      If the installer discovers active SQL Servers, select your server from the drop-down list. If the installer doesn't discover any SQL server, you can specify the SQL server details manually.

      If you are using dynamic SQL ports, enter the name of the SQL Server and the name of the SQL instance separated by a backslash. For example, if your SQL Server is called SQLServer and you are using the default instance name of MSSQLSERVER, enter SQLServer\MSSQLSERVER.

      Database Name

      This value is auto-populated with the name of the database. You can enter a more suitable name.

    2. Specify which type of Database Server Credentials to use.

      Windows authentication

      Select a domain of the user account from the drop-down list to access the SQL Server. If the required domain is not listed, type the domain name, user name, and password.

      SQL authentication

      Type the user name and password for your SQL Server. Make sure that credentials you provide are active and have appropriate administrator rights.

      Note

      The Domain menu is grayed out once you select the SQL authentication.

    3. Click Next.

      The installer connects to the SQL Server using the credentials. If the installer can't automatically determine the port, this message appears: Setup was unable to access the SQL UDP port 1434. Click OK to return to the Database Information page.

  7. The Pre-Installation Auditor automatically runs and validates the server condition. The checks are passed if the server meets all requirements. If the tool flags warning on a specific issue, you can rectify them and click Rerun. Once all checks have passed, click Finish.

    GUID-3358F3D3-C06F-4F9E-A5F7-13AB85EB02FF-low.png
  8. In the HTTP Port Information, review the default port assignment, then click Next to verify that the ports are not already in use on this system.

    Important

    The Agent wake-up communication port and Agent broadcast communication port can only be changed during and after installation. You cannot change the other port numbers after installation. For more information about the port information, see KB66797.

  9. In Administrator Information, specify the login credentials and click Next.

    1. Type the user name and password you want to use for your primary administrator account.

    2. Type the server recovery passphrase.

      The passphrase must be of 14–200 characters, must not contain leading or trailing backslashes (\), spaces, double quotation marks ("), or characters below ASCII 32 or above ASCII 65535.

      Important

      Save the passphrase as you need it to decrypt the Disaster Recovery Snapshot records. Trellix does not store this passphrase and can't recover it.

    GUID-19BA52EC-16C4-4154-9462-A78D47CA7662-low.png
  10. In Type License Key, type your license key, then click Next.

    If you are evaluating the software and have not purchased the license, select Evaluation to install the software. The evaluation period is limited to 90 days.

    1. You can enable the software license after the installation.

    2. (Optional) You can select Enable Automatic Product Installation to automatically download the licensed products after installation.

      Note

      The Enable Automatic Product Installation option is enabled by default and only available if you have a license key.

    GUID-A0553224-2AC7-4BD8-92F0-495F49BC9539-low.png
  11. In Ready to install the Program, you can decide whether to allow Trellix to collect system and software telemetry data, then click Install to begin installing the software.

  12. Wait until the installation process is complete, then click Finish to exit the Setup program.

    Your server is now installed with ePO - On-prem software.

  13. Double-click the Launch ePolicy Orchestrator icon on your desktop to start using your ePO - On-prem server, or browse to the server from a remote web console (https://servername:port).

Your server is now installed with ePO - On-prem software. Double-click the Launch ePolicy Orchestrator icon on your desktop to start using your ePO - On-prem server, or browse to the server from a remote web console (https://servername:port).

A certificate warning appears if you are using a self-signed certificate to access ePO - On-prem server through web console. Add the URL to the browser trusted sites.

If you're using Internet Explorer with enhanced security enabled, add the ePO - On-prem server address to your Internet Explorer trusted sites list (formatted as https://<servername>). If you don't, Internet Explorer displays an error message when you try to log on to the ePO - On-prem server.