The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

User security

Prev Next

Add users and groups to Trellix ESM, its devices, its policies, and their associated permission.

When in FIPS mode, Trellix ESM includes User, Power User, Key & Certificate Admin, and Audit Admin. When not in FIPS mode, Trellix ESM includes System Administrator and General User.

Trellix ESM lists:

  • Users — Names of users, the number of sessions that each user has open currently, and the groups to which they belong.

  • Groups — Names of groups and the permission assigned to each group.

Note

Sort the tables by clicking Username, Sessions, or Group Name.

Group Permissions

When you set up groups, set permissions that apply to all members of the group.

If you Limit access of this group on the Privileges page of Add Group (System PropertiesAdd Group ), access to these features is limited.

  • Actions toolbar — Users can't access device management, multi-device management, or Event Streaming Viewer.

  • Alarms — The users in the group have no access to alarm management recipients, files, or templates. They can't create, edit, remove, enable, or disable alarms.

  • Asset Manager and Policy Editor — Users can't access these features.

  • Case Management — Users can access all features except Organization.

  • ELM — Users can perform enhanced Trellix Enterprise Security Manager - Enterprise Log Manager searches but can't save them or access Trellix Enterprise Security Manager - Enterprise Log Manager device properties.

  • Filters — Users can't access String Normalization, Active Directory, Assets, Asset Groups, or Tags filter tabs.

  • Reports — Users can only run a report that emails the output to them.

  • System Properties — Users can access only Reports and Watchlists.

  • Watchlists — Users can't add a dynamic watchlist.

  • Zones — Users can view only zones they have access to in their list of zones.