Web UI login options on an appliance depend on how Helix mode and SSO mode are set.
Helix mode
In a Helix deployment, a Trellix appliance can be in one of three Helix modes:
cloud―The appliance is in the Trellix private cloud.
on-premises―The appliance is in your network.
on-premises with-sso―The appliance is in your network.
disabled―The appliance is not operating in the Helix environment.
Helix mode is disabled by default, and it is enabled when it is set to cloud or on‑premises. For details, see the Helix Integration Guide.
Single Sign‑On mode
In a Helix deployment, a Trellix appliance can be in one of three SSO authentication modes:
required―Users sign in once at a Trellix Cloud Account login page with Trellix IAM credentials. Users can pivot to any Helix component without logging in again until the SSO session expires. See When SSO authentication is required.
disabled―Users log in at the standard appliance Web UI login page with local credentials for that appliance. See When SSO authentication is disabled.
allowed―Users can sign in either locally or at the Trellix Cloud Account login page. See When SSO authentication is allowed.
Single sign‑on authentication is disabled by default, and it is enabled when it is set SSO authentication mode to required or allowed.
Important
The Mandiant Managed Defense (MD) integration uses local authentication. Authentication fails and MD service delivery can be interrupted if you require SSO authentication.