Endpoint Installation Guide

Prev Next

Last Updated: July 22, 2024

Installation overview and requirements

Software requirements

The Trellix Endpoint software is installed on Microsoft Windows 10 and Microsoft Windows Server 2016 (and later) systems and managed by Trellix ePolicy Orchestrator - On‑premises 5.9.0 and later.

You need to install two components to run Trellix Endpoint software.

  • A .zip file with six Trellix Endpoint extensions, installed on the Trellix ePO - On‑prem server. The .zip file can be downloaded from the Trellix ePO - SaaS Software Catalog, or the My Products page of the Trellix website.

  • The Trellix Endpoint client, installed on your managed endpoints

Install the Trellix Endpoint extensions on the Trellix ePO - On‑prem server and the Trellix Endpoint client package (MVISION_Endpoint_Installer_x64_Release_20xx.xx.x.xx.zip) on your managed endpoints.

The Trellix Endpoint extensions are packaged in a .zip file (MVISION_Endpoint_bundled_ePO_extensions_20xx.xx.x.xx.zip) which contains six product extensions:

  • MVISION_Endpoint_epo_extn_20xx.xx.x.xx.zip — for product installation and deployment.

  • Quarantine_Mgmt_epo_extn_20xx.xx.x.xx.zip — enables quarantine management functionality.

  • ProtectionWorkspace-services_1.0.0.xxx.zip — enables Protection Workspace services on the Trellix ePO - On‑prem server.

  • ProtectionWorkspace_1.0.0.xxx.zip — installs Protection Workspace on the Trellix ePO - On‑prem server.

  • MVISION_Endpoint_Updater_1.0.0.xx.zip — keeps extensions and packages current as Trellix releases new versions of the product.

  • Threat Detection Reporting 1.0.0 Build xxx (Extension).zip — to view the Story Graph on the Protection Workspace and Threat Event Log.

System requirements

Check that the minimum system requirements are met before you install Trellix Endpoint.

For information about Trellix Endpoint supported platforms, environments, and operating systems, see article 000012631.

Trellix ePO - On-prem scalability

Before you begin, make sure Trellix ePO - On-prem has sufficient capacity to manage the number of endpoints on which you want to deploy Trellix Endpoint. See the Trellix ePO - On-prem documentation on https://docs.trellix.com  for information about Trellix ePO - On-prem scalability.

Windows Defender Antivirus group policies

The Windows Defender Antivirus client is installed as a core part of Windows 10. It is important to consider group policies configured for Windows Defender Antivirus on your endpoints, and how they affect your Trellix Endpoint implementation.

Important

When using Trellix Endpoint to manage Windows Defender Antivirus or Windows Defender Firewall, do not use Domain Controller Group or Microsoft System Center Configuration Manager (SCCM) policies. Domain Controller and SCCM policies have higher precedence and will overwrite Trellix Endpoint policies.

For information about Windows Defender Antivirus deployments and policy configuration, see the documentation for the product.

Windows Defender Antivirus signature updates

You can configure the sources used by Windows Defender Antivirus to check for signature updates.

Windows Defender Antivirus uses several methods to check for and download signature updates.

  • Updates distributed from WSUS

  • Updates distributed from Microsoft Update

  • Updates distributed from Microsoft Malware Protection Center

  • Updates from UNC file shares

  • Updates from Configuration Manager SCCM

Select the methods you want to use in the Trellix Endpoint policy settings. To check for signature updates from UNC files shares, enter the UNC paths to be checked. See the Trellix Endpoint Product Guide for more information.

Windows Defender Firewall Management

You can use Trellix Endpoint to manage Windows Defender Firewall rules.

You can configure Windows Defender Firewall rules with Trellix Endpoint. When Trellix Endpoint is installed on Windows 10 endpoints, Trellix Endpoint manages some of the Windows Defender Firewall rules.

Important        

Windows Defender Firewall management is not enabled by default in Trellix Endpoint policies. If you want to         use Trellix Endpoint to manage Windows Defender Firewall, enable Windows Defender Firewall management and         enforce the policies on managed endpoints. For more information about the Firewall Rules policy, see the Trellix Endpoint Product Guide.      

First-time installation overview

Trellix Endpoint software is installed on Microsoft Windows 10 and Microsoft Windows Server 2016 (and later) systems and managed by Trellix ePO - On‑prem 5.9.0 and later. When you install Trellix Endpoint for the first time, you must install server-side software on the Trellix ePO - On‑prem server, then deploy the client software to managed systems.

You must install the following components to run Trellix Endpoint software:

  • A .zip file containing the Trellix Endpoint extensions, installed on the Trellix ePO - On‑prem server

  • Trellix Agent, installed on your managed endpoints

  • The Trellix Endpoint client, installed on your managed endpoints

Prepare your environment

Before you install Trellix Endpoint, make sure your environment is ready.

  1. Check system requirements for information about products that are compatible with Trellix Endpoint. Make sure any managed endpoints where you deploy Trellix Endpoint meet these requirements. For requirements, see article 000012909.

  2. Make sure Trellix Agent 5.0.6 or later is installed on all endpoints where you deploy the software.

  3. Make sure that you are logged on to Trellix ePO - On‑prem as an administrator.

  4. Check if VirusScan Enterprise, SiteAdvisor Enterprise, or Host Intrusion Prevention are installed on the endpoints where you deploy Trellix Endpoint. These products are automatically uninstalled on the system when you deploy the software.

  5. Check if Trellix ENS is installed on the endpoint before you deploy Trellix Endpoint.

  6. Check if Windows Defender Tamper Protection is supported on the endpoint. Trellix Endpoint can manage Windows Defender even if Tamper Protection is enabled.

  7. If you want to use the quarantine management function, make sure that Trellix DXL 4.0 or later is installed on all endpoints where you deploy Trellix Endpoint, and that the respective Trellix DXL extensions are installed on Trellix ePO - On‑prem.

Note

You might not see the Quarantine Content tab under Trellix ePO - On‑prem System Information if you do not have the Trellix DXL extensions installed.

Important

Designing and configuring the Trellix DXL fabric can be a complex process. See the Trellix DXL documentation on https://docs.trellix.com for information about how to install Trellix DXL.

8. Review the known issues for this release. For a full list of known issues for Trellix Endpoint, see article 000012513.

Install Trellix Endpoint extensions manually

You must install the Trellix Endpoint extensions on the Trellix ePO - On-prem server before the product can be managed.

The .zip file MVISION_Endpoint_bundled_ePO_extensions_20xx.xx.x.xx.zip contains the extensions required to install Trellix Endpoint. This can be downloaded from the Trellix ePO - SaaS Software Catalog, or the My Products page of the Trellix website.

  1. From the Trellix ePO - On-prem console, select Menu → Software → Extensions → Install Extension.

  2. Navigate to and select the zip extension file MVISION_Endpoint_bundled_ePO_extensions_20xx.xx.x.xx.zip, and click OK.

  3. Verify that the extensions appear in the Extensions list.        

    1. Select Trellix → Trellix Endpoint to view Trellix Endpoint and Quarantine Management extensions.

    2. Select ePolicy Orchestrator to view Protection Workspace and Trellix Endpoint Updater extensions.

Install Trellix Endpoint using the Software Catalog

You can use the Software Catalog to install, upgrade, and remove Trellix Endpoint. If you use the Software Catalog to upgrade Trellix Endpoint, you do not need to access the Trellix Product Download website to retrieve new Trellix Endpoint software and software updates.

  1. From Trellix ePO - On-prem, select Menu → Software → Software Catalog.

  2. Select the checkbox next to MVISION Endpoint.

  3. Click Check In All.

GUID-767A0F91-90DF-4783-9D8D-52B7A4ADBD74The Trellix Endpoint extensions and endpoint package are installed on the Trellix ePO - On-prem server.

Check in the Trellix Endpoint client software package

Check the Trellix Endpoint client package into the Master Repository so it can be deployed to your endpoints by Trellix ePO - On-prem.

Make sure that the Trellix Endpoint client package is in an accessible location on the network.

  1. Select Menu → Software → Master Repository.

  2. Click Check in package.

  3. Select the package type, then browse to and select the package file.

  4. Click Next.

  5. Click Save to begin checking in the package, then wait while the package is checked in.

GUID-EA56B59B-28AD-43B2-9DB8-DDDBC3C7CDDCThe package is checked in and appears in the Master Repository.

Deploy Trellix Endpoint to managed systems

Deploy the Trellix Endpoint software to your Windows 10 endpoints.

You must install the Trellix Endpoint extensions and check in the Trellix Endpoint package before you deploy the software to managed endpoints.

An Trellix Endpoint product deployment task is created automatically when you install Trellix Endpoint. When you assign this task to a system, the latest version of the client package checked in to Trellix ePO - On‑prem is deployed to that system.

Note

Beginning with Trellix Endpoint 2007, you can remove Trellix Endpoint Security (ENS) 10.5.5 and above as part of your Trellix Endpoint deployment. Any Trellix Endpoint Security (ENS) uninstallation failures might require targeted troubleshooting. For list of known uninstallation issues, see article 000013238.

  1. Select Menu → Software → Product Deployment.

  2. Under Endpoint Protection Software select Trellix Endpoint.

  3. Click Save. A dialog box with information on how to install your configured deployment is displayed.

  4. Select Advanced Product Deployment Task > New Deployment.        

    1. In the Name field assign a name for the deployment task.

    2. In the Package field, select Trellix Endpoint 20.xx.xx from the drop down list.

    3. To remove Trellix Endpoint Security (ENS) 10.5.5 and above as part of your Trellix Endpoint deployment, type --removeens in the Command line field.

3 | Installation overview and requirements

Note

Trellix Endpoint Security (ENS) 10.5.4 and below are not supported. The following message is displayed "The installer detected a version of Trellix Endpoint Security (ENS) that is not supported for Trellix Endpoint migration and was unable to continue. For minimum version requirements, see System requirements". Trellix Endpoint Security (ENS) 10.5.4 and below must be manually uninstalled before Trellix Endpoint can be deployed. See Remove Trellix ENS from your endpoints for further information.

  1. Click Select Individual Systems or Select by Tag or Group, then choose the system or group for which you want to apply the product deployment.

  2. Click Save.

Remove Trellix ENS from your endpoints

If Trellix ENS is installed on your endpoints, and you want to install Trellix Endpoint, you must first remove the Trellix ENS software.

  • Remove all Trellix ENS software and Trellix ENS Platform Common modules, including:

    • Trellix Endpoint Security (ENS) Threat Prevention

    • Trellix Endpoint Security (ENS) Firewall

    • Trellix Endpoint Security (ENS) Web Control

    • Trellix Endpoint Security (ENS) Adaptive Threat Protection

  • Disable Trellix ENS Exploit Prevention.

If you are migrating from Trellix ENS to Trellix Endpoint, remove any client deployment tasks that cause Trellix ENS redeployment to managed systems.

Note

If Trellix Endpoint Security (ENS) Threat Prevention exclusions are configured as part of your environment, you must convert the exclusions to the Trellix Endpoint policy. For information about Trellix Endpoint exclusions policies, see the Trellix Endpoint Product Guide.

  1. Select Menu → Client Tasks → Client Task Catalog.

  2. From the Trellix Agent navigation tree, select Product Deployment.

  3. Click New Task and select Product Deployment from the Task Types drop-down list.

    1. Complete the Task Name and Description fields. Windows is automatically selected as the target platform.

    2. From the Products and components drop-down list, select the Trellix ENS module to remove.

    3. Click + to remove multiple software packages.

    4. From the Action drop-down list, select Remove and click Save.

The new task appears in the Product Deployment list.

  1. Click Assign, select the system or group where you want to apply the client task then click OK.

    You can apply this task to a single system or to groups of managed systems in the System Tree.

  2. Select the required options in Client Task Assignment Builder and click Save. Trellix ENS is removed from the endpoint.

Note

Windows Defender Firewall is not automatically re-enabled when you remove Trellix ENS from the endpoint. Re-enable Windows Defender Firewall on each endpoint to make sure a consistent level of protection.

You can use Trellix Endpoint to configure Windows Defender Firewall rules. Windows Defender Firewall management is not enabled by default in Trellix Endpoint policies.

Verify the installation

Use Trellix ePO - On-prem to check that Trellix Endpoint is installed on the endpoint.

  1. Log on to Trellix ePO - On-prem.

  2. Select Menu → Systems → System Tree.

  3. Select the system you want to check.

  4. Click the Products tab.

  5. Verify that the version of Trellix Endpoint you installed appears in the list of products and that the status is successful.

Trellix Endpoint is deployed to the endpoint successfully.

Verify Windows Defender Antivirus is enabled

After Trellix Endpoint is installed, Windows Defender Antivirus is enabled automatically on the endpoint.

  1. Open the Group Policy Editor (gpedit.msc) on the endpoint.

  2. Select Local Group Policy.

  3. Select Computer Configuration → Administrative Templates → Windows Components → Windows Defender Antivirus from the policy tree.

  4. Select the Turn off Windows Defender Antivirus policy and verify it is set to Disabled or Not configured.

  5. Select the Real-time Protection folder.

  6. Configure these policies as follows:

    1. Set Turn off real-time protection to Not Configured or Disabled.

    2. Set Configure local setting override to turn on real-time protection to Not Configured or Disabled.

Test malware detections

Verify that Trellix Endpoint reports threat detections.

  • Make sure that Trellix Endpoint is installed correctly and can communicate with Trellix ePO - On-prem.

  • Enforce Trellix Endpoint default policies on endpoints.

  • Trellix Endpoint ML Protect cloud scanning and client scanning must function correctly to ensure endpoints can communicate with the Trellix cloud for detections. For information about how to test Trellix Endpoint detections, see article 000012532.

  1. Connect to the endpoint where Trellix Endpoint is deployed.

  2. Browse to EICAR (http://www.eicar.org/), and locate the EICAR sample virus.

  3. Select Anti-Malware Testfile.

  4. Navigate to the Anti-Malware Testfile section.

  5. Copy the sample, which begins with X50.

  6. Use Windows Notepad to save the EICAR file to your desktop.

  7. Navigate to the Trellix ePO - On-prem dashboard. The Protection Workspace appears.

  8. Expand Resolved Threats.

  9. Click the Resolved Threats total or the Basic total.

  10. Confirm that the sample file is listed as a threat in the activity list.

The threat might take several minutes to appear in the Protection Workspace.

RESULT_54CCA48D842B4DDC8AC056BF1F87D7BB Windows Defender Antivirus detects the threat. This information is listed under Analyzer. You can click the threat for Threat Details.

Upgrade overview

Upgrade Trellix Endpoint software to the latest version.

When you install the MVISION_Endpoint_Updater_1.0.0.xxx extension, as part of the bundled zip file, a server task (Trellix Endpoint Update Task) is added to Server Tasks. It pulls the latest Trellix Endpoint software from the Trellix ePO - On‑prem Software Catalog. Client components are automatically updated to the latest version available.

Note

By default, this task is enabled and runs daily.

If you want to install a specific version of Trellix Endpoint, you can manually install the extensions and client package on the Trellix ePO - On‑prem server.

Prepare your environment

Before you install Trellix Endpoint, make sure your environment is ready.

  1. Check system requirements for information about products that are compatible with Trellix Endpoint. Make sure any managed endpoints where you deploy Trellix Endpoint meet these requirements. For requirements, see article 000012909.

  2. Make sure Trellix Agent 5.0.6 or later is installed on all endpoints where you deploy the software.

  3. Make sure that you are logged on to Trellix ePO - On‑prem as an administrator.

  4. Check if VirusScan Enterprise, SiteAdvisor Enterprise, or Host Intrusion Prevention are installed on the endpoints where you deploy Trellix Endpoint. These products are automatically uninstalled on the system when you deploy the software.

  5. Check if Trellix ENS is installed on the endpoint before you deploy Trellix Endpoint.

  6. Check if Windows Defender Tamper Protection is supported on the endpoint. Trellix Endpoint can manage Windows Defender even if Tamper Protection is enabled.

  7. If you want to use the quarantine management function, make sure that Trellix DXL 4.0 or later is installed on all endpoints where you deploy Trellix Endpoint, and that the respective Trellix DXL extensions are installed on Trellix ePO - On‑prem.

Note

You might not see the Quarantine Content tab under Trellix ePO - On-prem System Information if you do not have the Trellix DXL extensions installed.

Important

Designing and configuring the Trellix DXL fabric can be a complex process. See the Trellix DXL documentation on https://docs.trellix.com for information about how to install Trellix DXL.

8. Review the known issues for this release. For a full list of known issues for Trellix Endpoint, see article 000012513.

Upgrade Trellix Endpoint software using the Software Catalog

Use the Trellix ePO - On-prem Software Catalog to upgrade the Trellix Endpoint components on the Trellix ePO - On-prem server.

  1. In Trellix ePO - On-prem, select Menu → Software → Software Catalog.

  2. In the Category menu, select Endpoint Security.

  3. Select the checkbox next to MVISION Endpoint.
    The Trellix Endpoint client package and zip extension bundle are selected automatically.

  4. If an upgrade version is available, Update All appears in the Actions column. Click Update All.

  5. Review the information in the Update pane.

  6. Click Update to upgrade to the latest available version of Trellix Endpoint.

GUID-12023A89-07C3-44F1-9E3F-8B014496F127 When the upgrade is complete, the Trellix Endpoint Status is Up to date.

Upgrade Trellix Endpoint software manually

Install the updated extensions and client package on the Trellix ePO - On-prem server manually to upgrade the Trellix Endpoint software.

Save the updated files to an accessible location on the network.

When you upgrade Trellix Endpoint, this task deploys the new version of the software, and retains previous settings, including system assignments and scheduling information.

  1. In Trellix ePO - On-prem, select Menu → Software → Extensions → Install Extension.

  2. Browse to select the zip extension file (MVISION_Endpoint_bundled_ePO_extensions_20xx.xx.x.xx.zip).

The updated extensions appear under Install Package on the Extensions page. Click OK.

  1. Verify that the updated extensions appear in the Extensions list.

    1. Select Trellix → Trellix Endpoint to view Trellix Endpoint and Quarantine Management extensions.

    2. Select ePolicy Orchestrator to view Protection Workspace and Trellix Endpoint Updater extensions.

    The updated extensions are checked in to the Trellix ePO - On-prem server.

  2. Select Menu → Software → Master Repository.

  3. Click Check in package.

  4. Select the package type, then browse to and select the package file.

  5. Click Next.

  6. Review the package information and click Save.

The updated client software package is checked in to the Trellix ePO - On-prem server.

GUID-B0FB0370-DE42-41F0-B4DF-A049B3BBE794Trellix Endpoint components are upgraded on the Trellix ePO - On-prem server.

Examine log files on an endpoint

If the software installation or removal fails, check the log files on the endpoint.

  1. Navigate to C:\windows\temp\mcafeelogs.

  2. Open the log files:

    • MveInstall.log - (processes performed by the installer)

    • MVEUninstall.log - (processes performed by the uninstaller)

    The log files are saved as text files and are the primary Trellix Endpoint log files for installing and uninstalling the software. They document each process that the Trellix Endpoint installer or uninstaller performs.

  3. Examine the log files and identify any errors that occurred.

    Starting from the top of the file, you can see the Trellix Endpoint product installer start. The installer then runs preinstall actions and removes incompatible products. For each process, you can see the command line, registry entries, and return codes.

Examine log files from Trellix ePO - On-prem

If an issue occurs during software installation, check the log files using Trellix ePO - On-prem.

  1. Navigate to Server Task Log.

  2. Locate and select the failed task.

  3. Select the Subtask tab.

  4. Select the deployment task. Additional information about any installation issues is displayed.

Remove Trellix Endpoint software from Trellix ePO - On-prem

Remove the Trellix Endpoint software package from the Trellix ePO - On-prem server.

  1. Log on to the Trellix ePO - On-prem server as an administrator.

  2. Select Menu → Software → Master Repository.        

    The Master Repository page displays the list of software packages and their details.

  3. Select the Trellix Endpoint software and click Actions → Delete Package.

The software is removed from the Trellix ePO - On-prem server.

Remove extensions from Trellix ePO - On-prem

Remove extensions from the Trellix ePO - On-prem server.

  1. Log on to the Trellix ePO - On-prem server as an administrator.

  2. Select Menu → Software → Extensions.

  3. Select Trellix Endpoint to view Trellix Endpoint and Quarantine Management extensions.

  4. Select ePolicy Orchestrator to view Protection Workspace extensions.

  5. Select Threat Detection Reporting to view Threat Detection Reporting extensions.

  6. Click Remove next to the extensions you want to remove.

  7. When prompted click OK.