The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Resolving issues that occur when analyzing your environment and deploying Trellix Endpoint Security (ENS) 26.x upgrades

Prev Next

Use this information to resolve issues that occur when using Endpoint Upgrade Assistant to analyze your environment and deploy upgrades to Trellix Endpoint Security (ENS) 26.x.

Issues with analyzing your environment and preparing to upgrade

If you see...

Do this...

Inconsistent product version numbers reported in tables

Refresh the ePO - On-prem database, then click Re-Analyze Environment to refresh the page.

Endpoints incorrectly reported as blocked

Refresh the ePO - On-prem database, then click Re-Analyze Environment to refresh the page.

The number of endpoints reported by Endpoint Upgrade Assistant doesn't match the number you expect (for example, the number of workstations, servers, or upgrade steps)

Export and download a list of endpoints and their details in CSV format.

Missing software packages highlighted on the Prepare tab

Install the highlighted packages, then click Re-Analyze Environment to refresh the page.

Endpoint Upgrade Assistant takes too long to analyze your environment

Analyze smaller groups of endpoints separately. Select a System Tree group (a subset of endpoints) when you configure an analysis, then configure more analyses with different groups until all endpoints are analyzed.

Outdated information appears in reports

Click Re-analyze Environment, then regenerate the report.

You don't have the required ePO - On-prem permissions to analyze your environment

Adjust the permissions.

Issues with deploying upgrades to endpoints

If installation fails because...

Do this...

You don't have the required ePO - On-prem permissions to install

Adjust the permissions configured for View and change task settings in the Trellix Agent permission set.

Installation package size exceeds the maximum size limit of 250 MB in ePO - On-prem

Choose one of the following:

  • Increase the limit before checking in the package to the ePO - On-prem server.

  • Use Package Creator to remove unneeded files from the installation package.

Third-party injectors were detected

Download the latest version of SysPrep from the Trellix Product Downloads site and check it in to each ePO - On-prem branch, then deploy the upgrade again. When Upgrade Automation runs on the endpoint, it downloads and runs the updated SysPrep package.

The product versions or features you want to upgrade aren't supported in Endpoint Upgrade Assistant or Package Creator

Download and install the latest versions from the Trellix Product Downloads site.

Use the same version of Endpoint Upgrade Assistant and Package Creator (for example, version 2.6.x of both).

Installation or upgrade was interrupted and requires a restart to continue

Restart the endpoint, then Endpoint Upgrade Assistant automatically resumes the installation or upgrade.

When you install or upgrade a Trellix product that includes SysCore while Exploit Prevention is enabled (in Trellix ENS or McAfee Host IPS), Endpoint Upgrade Assistant runs the mfeepmpk_utility.exe utility to detect and replace faulty drivers. If it installs a new driver, the endpoint must be restarted before Endpoint Upgrade Assistant can resume the installation or upgrade. In this case, Endpoint Upgrade Assistant closes and adds this information to the last line of the log file:

  • Code — 3010

  • Message — EUA_MFEEMPMK_UTIL_REQUIRES_REBOOT