Last Updated: November 14, 2024
Overview
Install Trellix Security for Microsoft SharePoint on the standalone server and on Trellix ePO - On-prem environment.
Installation workflow on standalone server
You can install the TSMS software on a standalone server by following these workflow.

Installation workflow on Trellix ePO - On-prem
You can install TSMS software on Trellix ePO - On-prem and deploy the software on client systems by following these steps.

First-time installation (Trellix ePO - On-prem)

Log on to Trellix ePO - On-prem as an administrator

Check in TSMS package to Trellix ePO - On-prem

Install the TSMS extensions on Trellix ePO - On-prem

Deploy the TSMS software to clients
Installation requirements for Trellix Security for Microsoft SharePoint
Make sure that the client and server systems meet the mentioned requirements.
System requirements
Make sure that your server meets these requirements to install the Trellix Security for Microsoft SharePoint.
Component | Requirements |
Processor |
|
Memory |
|
Disk space | Minimum — 10% free disk space |
Component | Requirements |
|---|---|
Operating system |
|
Microsoft SharePoint server |
|
Browser |
|
Screen resolution | Recommended 1024x768 or higher |
Trellix management software | Trellix ePO - On-prem 5.9.x and 5.10.x |
Trellix® Agent | Trellix Agent 5.7.x |
Upgrade Path |
|
Network | 10/100/1000 Mbps Ethernet card |
User roles
It is recommended to understand the importance of user roles and the difference among each role before installing the software.
Role | Description |
|---|---|
SharePoint Farm administrator (full permissions) | Domain account with full administrator permissions for all Windows servers and farm level services in the SharePoint server farm. This account needs to be specified during the Trellix Security for Microsoft SharePoint installation. |
SharePoint administrator (full permissions) | Domain account with full administrator permissions for SharePoint installed on a single server. This account needs to be specified during the TSMS installation. |
Custom user (minimum permissions) | Domain account with minimum permissions/least privileges required for the product to run. This account needs to be specified during the TSMSinstallation. For more instructions, See the section Creating a customized domain user account with the least SQL permissions. |
Windows administrator | Account that is a member of local administrator’s group to launch the TSMS installer. This might be the same as the farm administrator account if being used for installing the product. If you use the custom user account to run TSMS, you need a Windows administrator account to run the installer. |
ePolicy Orchestrator administrator | To deploy and administer TSMS through ePolicy Orchestrator server. |
Prerequisites for server mode
Make sure the client and server requirements are met before installing Trellix Security for Microsoft SharePoint single-server mode and farm server mode.
Checklist for SharePoint installation on single-server mode
Make sure that you have Windows administrator credentials to install Trellix Security for Microsoft SharePoint.
Make sure that you have the SharePoint administrator credentials to start TSMS installer.
If you are upgrading TSMS from a previous version other than TSMS 3.5, please uninstall them before the upgrade.
Choose an available open port on the server where you want to host the software site. You can use the default port 45900 if available. Telnet a port using the Windows command prompt to check if it is open.
Note
From a remote server, use the command telnet <host name or IP address> <Port>.
If the port is open — connection is refused.
If the the port is in use or not available — a successful connection is established.
If the firewall blocks the access — connection timeout occurred.
From the same server, use netstat -an to check to see if 45900 port is listening.
Checklist for SharePoint installation on a farm
Follow these instructions to install Trellix Security for Microsoft SharePoint on a farm.
Trellix recommends that you install Trellix Security for Microsoft SharePoint with SharePoint Farm administrator credentials. The software should be installed on the following servers within the server farm:
All Web Front-End (WFE) servers that host Portal sites.
All WFE servers that host Windows SharePoint Services team sites.
If WFE server is set up to redirect traffic to another SharePoint server in the farm, install TSMS on both the WFE server and the destination SharePoint server. Redirected traffic does not automatically pass through TSMS, installing it on both the servers assures protection of direct and redirected traffic.
Trellix Security for Microsoft SharePoint is not required on the server types mentioned below:
Application servers — you can scan the database of Application server even if TSMS is not locally installed on it.
When on-demand or scheduled scan is configured to scan such an application server, the entire content of the database is retrieved from the application server and streamed over the network to the WFE for scanning. This might require additional bandwidth during the scanning. If you are concerned about the bandwidth, it is recommended to install TSMS locally on the application server.
Search Servers
Index Management Servers — If you choose to install Trellix Security for Microsoft SharePoint on an Indexing Server, make sure that indexing is scheduled during off-peak hours to minimize the impact of on-access scanning on server performance.
Job Servers
Microsoft SQL Servers
If your organization's policy restricts you from using SharePoint Farm administrator credentials or if you do not want to use them for other reasons, you can create a customized normal domain user account with minimum permissions needed for Trellix Security for Microsoft SharePoint to run. See the section Creating a customized domain user account with the least SQL permissions for instructions.
Installing Trellix Security for Microsoft SharePoint on Server
Install Trellix Security for Microsoft SharePoint on the standalone server and on Trellix ePO - On-prem environment.
Install Trellix Security for Microsoft SharePoint using setup wizard
You can install the software using the wizard following the instructions.
To install the TSMS, download the
MSMS35EN_L.zip(for English) archive and extract the files to a temporary location on your system.Double-click
setup.exe. Select your language and click OK.Follow the onscreen prompts for the installation.
Accept the terms in the license agreement, then click OK.
Click Next.
Specify the port where Microsoft Internet Information Server must host Trellix Security for Microsoft SharePoint, then click Next.
The default port is 45900. You can change this and specify a custom port as required.
Click Next to install the software in the default location
C:\Program Files (x86)\McAfee\McAfee PortalShield.Trellix recommends to install it in the default location.
Note
You can select a different location for installing the software by clicking Browse.
The Database Account dialog box is displayed.
Type your account name (domain or workgroup\username) and password, then click Next.
Type the credentials of the system where SharePoint is being installed. For example: Domain\UserName or Workgroup\UserName.
The server validates the account credentials. The account must be a member of the local Administrator's group on the server on which you are installing Trellix Security for Microsoft SharePoint.
If the user credentials are not resolved by the server, a warning dialog box is displayed prompting you to check your credentials.
a. Verify if you have entered correct credentials. Click OK, then click Next to override the warning and proceed with the installation process with unresolved account information.
The Ready to Install the Program dialog box is displayed.
Tip
Post installation you can use SetSQLAct.exe to change your credentials if you made an incorrect entry while installing Trellix Security for Microsoft SharePoint. This utility is located in <Installation folder>\bin.
On the command prompt, type
SetSqlAct.exe /USER=<username> /PASSWORD=<password> /DOMAIN=<domain>.
Click Install. A progress bar indicates the status of the installation.
When the installation is complete, select the following options as needed and click Finish.
Note
Trellix recommends to restart the system after installing the software.
View Readme — View release notes for information about any last-minute additions or changes, known issues, or resolved issues.
Launch User Interface — Starts TSMS user interface after you exit the installation wizard.
Update Now — Downloads the latest product updates to ensure that you are running the most current security. Your system must be connected to the Internet to receive automatic updates regularly.
Trellix Security for Microsoft SharePoint is now installed on your system.
Upgrade from a previous version
You can upgrade the software from previous versions and migrate the configuration settings.
Upgrade is supported from Trellix Security for Microsoft SharePoint 3.5 to this release.
When upgrading to a new version, you don't need to uninstall the existing version. The installation program updates your installation to the new version.
Note
Due to the availability of Trellix Content Scanning Engine 4.8.0 with TSMS 3.5.3, certain file filter categories are merged as primary and secondary file format. Some of the rules are now obsolete and are not available. For details, see this Trellix Knowledge Base article: KB85243.
Use administrator credentials to log on to the system where Microsoft SharePoint server is installed.
From the setup folder of the extracted .zip archive, double-click
setup.exe.In the Preparing to Install screen, the installation wizard is prepared and all required installation files are extracted. When the process is complete, the Changes completed screen is displayed.
Note
Trellix recommends to restart the system after upgrading the software.
You have successfully upgraded to the latest version.
Note
On completion of upgrade, an html report for any file filter categories changes in your configuration, is shown in the browser. You can also find the report in this location <MSMS Install directory>/bin/FilefilterUpgradeReport_ddmmyyyyhhmmss.html.
Testing your installation
After installing the software, you can test the scanning performance and the service of the installed components.
You can test the operation of the Trellix Security for Microsoft SharePoint software by running the EICAR Standard Anti-virus Test File on any computer where you have installed the software.
Note
The EICAR Standard Anti-virus Test File is a combined effort by anti-virus vendors throughout the world to implement one standard by which customers can verify their anti-virus installations.
Test the on-access scanner
Perform the scan test on EICAR test file using on-access scan.
Launch Microsoft SharePoint server.
Copy the following line into a file, save the file with the name
EICAR.TXT:
X5O!P%@AP[4\PZX54(P^)7CC)7}$EICAR-STANDARD-ANTIVIRUS-TEST-FILE!$H+H*The file size is 68 or 70 bytes.
Note
If you have any other security software installed on your server, you must disable its scanner during this process. This is to prevent the file from being identified by another security software.
3. Start the Trellix Security for Microsoft SharePoint software and try adding the EICAR.TXT file to your Microsoft SharePoint server. The Trellix Security for Microsoft SharePoint on-access scanner action is configured to Prevent Upload/Download of the Item and hence the file is not saved on your SharePoint server.
Test the on-demand scanner
Perform the scan test on EICAR.TXT file using on-demand scan.
Launch the Microsoft SharePoint administration interface by clicking Start → Programs → SharePoint Portal Server → SharePoint Central Administration.
Click Configure anti-virus settings under Security Configuration.
Deselect Scan documents on upload and Scan documents on download.
Delete the previous copy of EICAR.TXT from the Microsoft SharePoint server.
Add EICAR.TXT back into the Microsoft SharePoint server. Schedule an on-demand scan for that Microsoft SharePoint server. The Trellix Security for Microsoft SharePoint software reports finding the EICAR test file as per the default on-demand policy setting Replace item with an alert.
Delete the file when you have finished testing your installation to avoid alarming unsuspecting users.
Make sure that you enable on-access scanning to provide real-time protection against viruses and unwanted files and content within your SharePoint computer.
Note
If you have disabled any other anti-virus software during these tests, make sure that you enable them.
Installed components and services
Make sure that the TSMS services and components are installed appropriately on your SharePoint server.
To access these components, click Start → Programs → Trellix → Trellix Security for Microsoft SharePoint, then click the component:
Sitelist Editor — Specifies the location where automatic updates (including DATs and scanning engines) are downloaded from.
Trellix Security for Microsoft SharePoint (Web Interface)— Launches the product's user interface through web browser.
Access Control — Allows or denies access to the Trellix Security for Microsoft SharePoint user interface for specific users or groups.
Services available
Trellix Framework Service — Prerequisite for installing and using Trellix ePO - On‑prem and Trellix products. For details about this service, see Trellix ePO - On‑prem product documentation.
Trellix PortalShield — Protects your Microsoft SharePoint Server from viruses, unwanted content, potentially unwanted programs, and banned file types and messages.
Integrating with Trellix ePO - On-prem
You can integrate the TSMS with Trellix ePO - On-prem by checking the packages and extensions.
Trellix ePO - On-prem provides a scalable platform for centralized policy management and enforcement on your Trellix security products and the systems where they reside. It also provides comprehensive reporting and product deployment capabilities, all through a single point of control.
For instructions about setting up and using Trellix ePO - On-prem, see the product guide for your version of the software.
Prerequisites
Make sure that your Trellix ePO - On-prem environment meets all prerequisites to install and integrate theTrellix Security for Microsoft SharePoint.
Use administrator credentials of the Trellix ePO - On-prem server.
Add manageable systems to the Trellix ePO - On-prem server on where you want to deploy TSMS. See Trellix ePO - On-prem product documentation for instructions.
Deploy Trellix Agent on your managed systems running Microsoft SharePoint. See the Trellix Agent product documentation for installation instructions.
If you're upgrading from a previous release, uninstall any earlier versions of the product other than Trellix Security for Microsoft SharePoint 3.0.0.
Make sure that you have administrator credentials for each SharePoint server in single-server mode or farm environment.
Choose an open and unused port on the server where you want to host the Trellix Security for Microsoft SharePoint site.
Check in the software package
Check in the software package to the Trellix ePO - On-prem repository to install and manage the client systems.
Log on to ePolicy Orchestrator server as administrator.
Click Menu → Software → Main Repository, then click Action → Check In Package.
In the Package step, select Product or Update (.zip), click Browse and browse to the .zip file containing the software package, then click Next.
In the Package Options step, select Current as the branch, then click Save.
Install the software extensions
Install the software extensions on the Trellix ePO - On-prem server to configure policies.
Note
Even if you have a previous version of the software extension, this task adds the Trellix Security for Microsoft SharePoint 3.5.3 extension to the list. You can retain the previous extensions or remove them, as needed.
Log on to the Trellix ePO - On-prem server as an administrator.
Select Menu → Software → Extensions, then click Install Extension.
Click Browse and navigate to the .zip file containing the policy extension (MSMS35PolicyEx_0409.zip for English), then click OK.
Note
Install the report extension and the Help extension in the same way.
Migrate the policies from an older version
You can migrate the existing policy settings from older versions to the current version.
Note
Due to the availability of Trellix Content Scanning Engine 4.8.0 with Trellix Security for Microsoft SharePoint 3.5.3, certain file filter Categories are merged as primary and secondary file format. Some of the rules are now obsolete and are not available. For details, see this Trellix Knowledge Base article: KB85243.
Browse to the folder containing the
MSMS_ePOUpgrade.zip, then extract it.
Note
Make sure that all files in the .zip archive are extracted to the same folder.
At the command prompt, navigate to the folder where the .zip file is extracted, and run the
MSMSePOUpgrade.execommand.Type the Trellix ePO - On-prem database password, then press Enter.
Type the Trellix ePO - On-prem SQL named instance if created during the server installation, otherwise leave the field blank. Then press Enter.
The policy upgrade process starts.
Verify that the policies are upgraded: In the Trellix ePO - On-prem console, navigate to Policy Catalog, select the product as Trellix Security for Microsoft SharePoint 3.5.3, then look for upgraded policies suffixed with (Upgraded). For example, My Default (Upgraded).
Assign the custom policies to the required systems, otherwise the Trellix default policies are enforced.
On successful completion, a confirmation message appears. See EPODebugTrace.txt in the current directory for log details. Press Enter to exit.
Note
On completion of upgrade, an html report is generated for any file filter categories changes in your configuration. You can find this report in this location <ePO Upgrade tool path>/bin/FilefilterUpgradeReport_ddmmyyyhhmmss.html.
Deploy the software to clients
Deploy the software from the Trellix ePO - On-prem server to the client systems.
Migrate existing policies from older versions to Trellix Security for Microsoft SharePoint 3.5.3.
Log on to the Trellix ePO - On-prem server as an administrator.
Select Menu → Systems → System Tree, then select the required group or systems.
Note
When upgrading the software, make sure that you select all required systems.
Click the Assigned Client Tasks tab, then click Actions → New Client Task Assignment. The Client Task Assignment Builder screen appears.
In Product, select Trellix Agent.
In Task Type, select Product Deployment.
Click Create New Task. The Client Task Catalog screen appears. Type a name for the task, and any notes. Select Windows as a target platform.
In Products and components, select Trellix Security for Microsoft SharePoint 3.5.3, select Install as action, select the language, then click Save.
Note
Type the credentials for the system that has the SharePoint server installed in Trellix ePO - On-prem command line.
REMOTESQLUSER = "DomainName\UserName or HostName\UserName"
REMOTESQLPWD = "password"
IISPORT = 45900 (Optional)
Schedule the task to run immediately, click Next to view a summary of the task, then click Save.
On the System Tree page, select the systems or groups where you assigned the task, then click Wake Up Agents.
On the Wake Up Trellix Agent screen, select Force complete policy and task update, then click OK.
On successful execution of this task, the software is deployed to the selected systems.
Remove the software
You can remove the software and its extensions from your Trellix ePO - On-prem environment.
To completely remove the software and its features from your environment, remove them in this order:
Remove the Trellix Security for Microsoft SharePoint client software from the clients.
Remove the Trellix Security for Microsoft SharePoint software extensions in this order:
Reports extension
Policy extension
Help extension
Remove the software from client systems
You can remove the software from the Trellix Security for Microsoft SharePoint server by following the instructions.
Log on to the Trellix ePO - On-prem server as an administrator.
Select Menu → Systems → System Tree, then select the required group or systems.
Click the Assigned Client Tasks tab, then click Actions → New Client Task Assignment.
The Client Task Assignment Builder screen appears.
In Product, select Trellix Agent. In Task Type, select Product Deployment. Click Create New Task.
The Client Task Catalog screen appears.
Type a name for the task, and any notes. Select Windows as a target platform.
In Products and components, select Trellix Security for Microsoft SharePoint 3.5.3, select Remove as action, select the language, then click Save. The task is listed in the Task Name. Select the task and click Next.
Schedule the task to run immediately, then click Next to view a summary of the task.
Review the summary of the task, then click Save.
In the System Tree page, select the systems or groups where you assigned the task, then click Wake Up Agents.
In the Wake Up Trellix Agent screen, select Force complete policy and task update, then click OK.
Remove the software extensions
You can remove the software extensions from the Trellix ePO - On-prem server by following the instructions.
Log on to the Trellix ePO - On-prem server as an administrator.
To remove the report extension, click Menu → Software → Extensions.
From the left pane, select Trellix Security for Microsoft SharePoint.
Click the Remove against the report extension, select Force removal, bypassing any checks or errors, then click OK.
Repeat this step to remove the policy extension Trellix Security for Microsoft SharePoint 3.5.3 (MSMS____3500.ZIP).
To remove the help extension, select Help Content from the left pane and click Remove against the tsms_help.