Managing account status

Prev Next

Each user has an account status that determines whether and how the user can log in to the Trellix appliance locally. The account statuses are described in the following table.

Account status

Description

Account locked out

The user cannot log in at all. This could be due to the account status being configured this way explicitly, or due to too many unsuccessful login attempts.

Local login disabled

The user cannot log in to an appliance locally, using either a password or an SSH authorized key. A user with this account status can still authenticate remotely and be mapped to this user account.

Local password login disabled

The user cannot log in to the appliance locally using a password, but can log in using an SSH authorized key.

Password set

The user can log in to the appliance locally using a username and password.

The provided Operator, Analyst, and Auditor system accounts have the "local login disabled" status set by default, so they cannot log in until an administrator changes their account status by setting passwords for them. The provided Monitor account defaults to the "account locked out" status for security.