Trellix Helix is a unified detection and response platform that aggregates and prioritizes security alerts generated from the smart nodes and endpoint agents in your network. Security operations are managed from a single console for alert management, search, analysis, rules, analytics, investigations, and reporting.

Trellix Identity and Access Management (IAM) provides user provisioning through role-based access control policies and optional access control policies based on dynamic data. Using the default IAM organization administrator account, you log in to the Trellix Cloud Web UI to configure security policies, other Trellix IAM users, and user access controls.

Trellix IAM enables Helix to support single sign-on (SSO). Users authenticate against Trellix IAM when they log in to a Helix appliance with their Trellix IAM account credentials. The appliance verifies the user’s identity and obtains information from the user’s ID token, access token, or session token. The user can navigate among components without logging in to each appliance locally.
Important
OIDC‑based authentication and X.509‑based authentication are mutually exclusive. Trellix IAM uses OIDC-based authentication. If you use Trellix IAM, do not enable the use of Common Access Cards (CAC) or Personal Identity Verification (PIV) smart cards. Both CAC and PIV use the X.509 standard for a Public Key Infrastructure (PKI) as an authentication mechanism to manage certificates.
See IAM overview and Common Access Card (CAC) for certificate authentication.