Skip to content

TechDirectArchive

Hands-on IT, Cloud, Security & DevOps Insights

  • Home
  • About
  • Advertise With US
  • Reviews
  • Contact
  • Toggle search form
Home » Security | Vulnerability Scans and Assessment » ePO Server Settings: Trellix ePO AD integration and ENS Agents Installation
  • CreateanAWSact
    How to Set up an Amazon Web Services (AWS) Account AWS/Azure/OpenShift
  • header picture 1
    Azure CI/CD: Configuring Email Notifications in Azure DevOps AWS/Azure/OpenShift
  • How to Find Out Which Users Are Logged on Windows Server
    How to Find Out Which Users Are Logged on Windows Server Windows
  • cisco general
    How to update Cisco ASA Network | Monitoring
  • sql server
    Download and install MSSQL 2019 Express Edition and SSMS Oracle/MSSQL/MySQL
  • 2022 1
    Install Windows Server 2022 on VirtualBox Network | Monitoring
  • How to configure Azure container register with secured connection with container apps
    Configure Azure Container Registry for a secure connection with Azure Container Apps AWS/Azure/OpenShift
  • sdgfdhx
    MDT Warning: Unable to set working directory, the application returned an unexpected code 2 Windows Server

ePO Server Settings: Trellix ePO AD integration and ENS Agents Installation

Posted on 29/03/202402/07/2025 Christian By Christian No Comments on ePO Server Settings: Trellix ePO AD integration and ENS Agents Installation
Trellix-configurations-after-ePo-setup

Trellix ePolicy Orchestrator (ePO) is a centralized security management platform that helps orchestrate and manage your endpoints from a single console. In this article, we shall discuss “Trellix ePO AD integration and ENS Agents Installation”. Not limited to these bt Trellix Account creation, and Trellix agent update etc. Please see Manage BitLocker and FileVault with Trellix Native Encryption, and how to Disable SQL Auto Close: Auto Close is enabled for both ePO and ePO Events Databases.

After Trellix ePolicy Orchestrator Installation on Windows Server. You might want to upgrade Trellix ePolicy Orchestrator. If there areissues during the setup, you will find this guide on “Fixes to Trellix ePolicy Orchestrator Installation Errors” very useful.

Server Task

we shall discuss some more settings in details later. but ensure you define the frequency for your desired tasks as shown below.

Server tasks

Integrate Active Directory with Trellix

Trellix ePO on-premise simplifies the process of managing users by automatically creating Windows authentication users based on their Active Directory group membership.

After the setup of ePO, you might want to integrate it with Active directory. Below are the steps to integrate Trellix ePO with Active Directory. This step assumes you have setup a Domain Controller as Recommended by Microsoft. See how to setup a Domain Controller.

Log in to your Trellix administrative interface. Under Configuration, select “Registered Servers”.

Register-servers-on-trellix

On the Registered Servers, select LDAP.

Registered-server-types
Registered server - Directory Server
New server types available after installing Service Pack 1 – Update 5

Populate the field below and click Save.

Populate-Field-with-AD-information

As you can see, the fields are populated. To confirm everything is working correctly, hit the test connection button below. It the credentials are fine, you should see “successfully connected to the LDAP server”.

LDAP-Connection-successful

Yes, we have our ePO correctly bonded with the LDAP Server.

Server-registered

Please, see Fix MSIEXEC returned 1602: Trellix Setup cannot use this account, and How to enable FIPS mode on Windows Server.

Add Domain users

To add AD users on Trellix, click the Trellix menu and under user management. Select Users.

Authenticte-to-ePO-with-Domain-user-Account

Click “New User”

Add-new-user

I am interested in creating a new account with Windows authentication. Please populate the field below. You can also create an account with ePO authentication or certificate-based authentication

AD-account-created
Now, you should be able to login to the ePO console with your domain credential.

Enable Active Directory User Logon on Trellix

We have discussed more of these steps here: Selfservice Recovery: Trellix BitLocker and fileVault Recovery. If you do not want to import an AD user as we have done above, you will have to enable allow Active Directory users to log on if the have at least one permission set.

To do this, click on Menu and under Configurations, select Server Settings. Edit the settings and click Yes.

Disallow-D-users-from-loggin-in

Note: If Active Directory User Login is enabled when an unknown user tries to log on. Trellix ePO server checks to see any permission sets mapped to Active Directory groups for which the user is a member. If there are, Trellix ePO creates a Windows authentication user and assigns the mapped permission sets to it. To enable this feature, you must do the following:

  • Active Directory User Login must be enabled as shown above.
  • At least one permission set must be mapped to the user’s Active Directory group
  • A registered LDAP server must be configured for the domain, so that Trellix ePO can determine the user’s group membership.

Delete or Disable an Imported AD User

To do this, you will follow the same method as if you were editing a use. Select “Actions” and then delete. Click the OK to confirm deletion.

delete-a-user-account

Trellix Agent Checkin (Installation on ePO)

Trellix ENS intercepts threats, monitors overall system health, and reports detection and status information. Client software is installed on each system to perform these tasks.

There are numerous ways to load Trellix Agents unto ePO. You could check them in using extension or the repository. But, I have decided to use the Software Catalog. The Trellix Software Catalog removes the need to access the Trellix Product Download website to retrieve new Trellix software and software updates.

Note: You can use the Software Catalog to install, upgrade, and remove Trellix Endpoint

To do this, click on the Trellix menu and under software. Select Software Catalog. After deploying ePO, you are required to deploy Trellix agents to endpoints as a prerequisite for other deployments. As shown below, I will select all packages relating to Trellix agents and checked them all in.

Trellix-Agent-Checkin

Accept the license terms and check them in as shown below.

Trellix-components-to-checkin

The Trellix Endpoint extensions and endpoint package are installed and updated on the Trellix ePO server.

Updating-agents

You can take a look at the Server task Details for more information.

View-tasklog

Here is how to checkin Trellix Management for Native Encryption as well.

Checkin Extension
Checkin Extension

Create a custom McAfee Agent installation package in ePO

This steps involves using a distribution method other than ePO deployment. To create an ePO custom agent installation package, please follow the steps below.

Method 1:

Log on to the ePO console. If the agent package is not checked in, go to the Software Catalog and check in the embedded package version of the agent. Next, click Menu, Systems Section, System Tree.

system-tree

Select New Systems from the top-left corner.

New-System-tree

Under how to add systems, you can see you have different options.

In my case, I am interested in showing the steps to "create and download agent installation packages". Also, I am interested in Trellix agent for Windows and Mac and click ok.
create-and-download-agents

You are prompted to download the file. You can click on the link or right click and select save link as.

save-link-as

Method 2: Link My Organisation to Active Directory

The “My Organization group” is the root of your System Tree. It contains all systems added to or detected on your network (manually or automatically). Until you create your own structure, all systems are added by default Group. The My Organization group has these characteristics as they cannot be deleted, and cannot be renamed.

If your network runs Active Directory, you can use Active Directory synchronization to create, populate, and maintain parts of the System Tree.

Once defined, the System Tree is updated with any new systems (and subcontainers) in your Active Directory.

So let’s perform the synchronisation. Click on my Organisation and under group details, select edit close to the Synchronisation button. Also, this step assume you have integrated your ePO with AD as shown above.

Define-Syncronization

Select Active Directory and other settings that pertain to you. To integrate a contain (OU), click the Browse button to select the OU you wish to integrate on ePO.

Browser-containers

When all fields have been populated. Enter your service account and password as this will be used to install the agents on the PC. Click Save when complete.

organisation-settings-sync

If you were to configure agent policy, you would do it from here as shown below when syncing group details. I will do these at a later time. Just showing you the steps to. You will see this step again when we wish to push the agent.

Trellix-Agent-push-settings

Create a Sub-group

Now that we have synced the “My Organisation Group”, lets create an OU structure on ePO to reflect our AD environment.

Note: There is no single way to organise a System Tree, and because every network is different, your System Tree organisation can be as unique as your network layout. You can use more than one method of organisation

To do this, click the Trellix Menu, Systems and System Tree. Select your organisation and click on “New Subgroup”.

Create-subgroup

Enter the New Subgroup name and click OK.

enter-subgroup-name

Note: If you delete systems from the System Tree, make sure that you select the option Remove agent from all systems. If the McAfee Agent is not removed, deleted systems reappear in the Lost and Found group because the McAfee Agent continues to communicate to Trellix ePO Cloud. Also, unless you select Remove agent installed products from all systems, the product software remains installed on the systems deleted from the System Tree.

Assign the Service Account to the Computer Administrator Group

The PCs should be discovered by Trellix. Depending on your AD setup/permission, you may have to set up a service account and assign it to the PCs in order to be able to push the agents.

Connect to the PC interactively or remotely.You could use the Computer Manager to connect as shown below.

connect-to-a-PC-remotely

Expand local Users and Groups and right click or double click on Administrators. Now that we have configured the permission, let’s proceed with the agent deployment.

Add-the-account-in-order-to-manage-the-PC

Trellix Agent Deployment

This steps require the manual deployment of agents. Click on the PC under Systems. from Actions, select Agent and then Deploy agents.

Deploy-agents

In the Trellix Deploy Agent window, click on OK.

Agent-settings

Let’s review the Server task to see the progress of the Agent Deployment. As you can se, it is in progress.

agent-deployment-in-progress

The agent deployment has succeeded and completed successfully.

agent-successfully-deployed

The PC is recognised as managed. Now, deploy the agent to the rest devices manually or follow the steps below to assign the agent via automatic assignment..

PC-recognized-as-managed-by-Trellix

Automatic Agent Assignment

This can be achieved by using the Assigned Client Tasks under the system tree. Luckily, I did not have to create a Policy using the Policy catalogue. See Manage BitLocker and FileVault with Trellix Native Encryption for more information on this topic.

Assign Client Task. When this is done by following the prompts and selecting the right OU or group etc. The assignment field will change to 1 Assignment.

Client-task-for-Trellix-Agent

Edit the assignement

Define-the-schedule-by-editing-this-assignment

Define the schedule as shown below

Save-Assignment

Trellix Product Deployment

In this section, we will discuss deployment tasks for installing products on managed systems.

Note: Product packages must be checked in before deploying them. By now, you should be familiar with the process of deploying a package.

To do this, click on Trellix Menu, and under Software, select “Product Deployment”.

Product-deployment

Select new deployment

New-product-deployment

Populate the fields for product deployment window as shown below.

Populate-product-deployment-field

Automatic Task Synchronisation

Server tasks are scheduled management or maintenance tasks that you run on your Trellix ePO – on-prem server.

Server tasks enable you to schedule and automate repetitive tasks. Use server tasks to monitor your server and software., We can verify the ePO server tasks to ensure the smooth operation. From the Trellix Menu, click Server Tasks.

Trellix-server-task

Click New Task.

New-server-task

We will configure automatic AD and ePO synchronisation as shown below.

Server-Task-Buider-name

You can select a select OU (container) to synchronise with and click OK.

select-sync-group

Define the schedule as you wish

set-schedule

On the summary page, do not forget to click save.

Save-Task-to-automate-Trellix-AD-sync

Below are some server tasks and the newly created server task.

Verify LDAP sysc is enabled

ePO Server Custom SSL Certificate Configuration

All the necessary settings specific to your ePO server are in Server Settings.

The Server Certificate option will enable you to protect and secure the connection to the ePO server and ensure it is trusted. 

To do this, log on to the ePO console, click Menu, under Configuration, and select Server Settings.

Server-Settings

Click Server Certificate under Setting Categories, and then click Edit.

Edit-Server-Certiifcate-Settings

Select Use the provided certificate and private key.

Save-Certificate-and-Private-Key

Click Browse in the Certificate (P7B, PEM) field. Locate and select the certificate file (.p7b or .cer). Then, click Open. Also, click Browse in the Private key (PEM) field.

Browser-certs

Please save the settings

Services-restart

Restart the following ePO services, and close the services manager when complete.

Trellix ePolicy Orchestrator x.x.x Application Server
Trellix ePolicy Orchestrator x.x.x Event Parser
Trellix ePolicy Orchestrator x.x.x Server
Services-restarts

FAQs relating to Trellix ePO AD integration and ENS Agents’ Installation

What authentication types are supported with BitLocker on Trellix ePO?

MNE supports TPM, TPM+PIN, and Password authentication. Password authentication is only available with Windows 8 and later.

How do I make McAfee agent unmanaged?

To change from managed to unmanaged mode on Windows systems (ePO On-Premises), select Menu → Systems → System Tree. Select the systems to change to unmanaged mode. Click Actions, select Directory Management, then click Delete.
Select Remove McAfee Agent on next agent-server communication and confirm the deletion.

I hope you found this article on “Trellix ePO AD integration and ENS Agents Installation” useful. Please feel free to leave a comment below.

5/5 - (1 vote)

Thank you for reading this post. Kindly share it with others.

  • Share on X (Opens in new window) X
  • Share on Reddit (Opens in new window) Reddit
  • Share on LinkedIn (Opens in new window) LinkedIn
  • Share on Facebook (Opens in new window) Facebook
  • Share on Pinterest (Opens in new window) Pinterest
  • Share on Tumblr (Opens in new window) Tumblr
  • Share on Telegram (Opens in new window) Telegram
  • Share on WhatsApp (Opens in new window) WhatsApp
  • Share on Pocket (Opens in new window) Pocket
  • Share on Mastodon (Opens in new window) Mastodon
  • Share on Bluesky (Opens in new window) Bluesky
  • Share on Threads (Opens in new window) Threads
  • Share on Nextdoor (Opens in new window) Nextdoor
Security | Vulnerability Scans and Assessment Tags:ePO, ePolicy Orchestrator, Microsoft Windows, Windows 10, Windows 11, Windows Server 2016

Post navigation

Previous Post: Selfservice Recovery: Trellix BitLocker and fileVault Recovery
Next Post: How to Sync Data in Cloud Drives to Synology NAS

Related Posts

  • hero activedirectory 1
    Active Directory Contact and a User Account Object Differences Security | Vulnerability Scans and Assessment
  • Mimikatz hacktool Trillix
    Windows Defender detects Endpoint Security HipHandlers.dll Security | Vulnerability Scans and Assessment
  • How to Register Devices to Microsoft Intune and EntraID Using My Company Portal
    Register Devices to Intune and EntraID Using Company Portal AWS/Azure/OpenShift
  • Turn On Or Off Auto Unlock For BitLocker Drive
    How To Turn On Or Off Auto-Unlock For BitLocker Drive In Windows 10/11 Security | Vulnerability Scans and Assessment
  • Disable Open File Security Warnings on Windows
    How to Disable Open File Security Warnings on Windows Security | Vulnerability Scans and Assessment
  • Protecting DS923 NAS
    DSM Security: How to Protect Synology DS923+ NAS Reviews

More Related Articles

hero activedirectory 1 Active Directory Contact and a User Account Object Differences Security | Vulnerability Scans and Assessment
Mimikatz hacktool Trillix Windows Defender detects Endpoint Security HipHandlers.dll Security | Vulnerability Scans and Assessment
How to Register Devices to Microsoft Intune and EntraID Using My Company Portal Register Devices to Intune and EntraID Using Company Portal AWS/Azure/OpenShift
Turn On Or Off Auto Unlock For BitLocker Drive How To Turn On Or Off Auto-Unlock For BitLocker Drive In Windows 10/11 Security | Vulnerability Scans and Assessment
Disable Open File Security Warnings on Windows How to Disable Open File Security Warnings on Windows Security | Vulnerability Scans and Assessment
Protecting DS923 NAS DSM Security: How to Protect Synology DS923+ NAS Reviews

Leave a Reply Cancel reply

You must be logged in to post a comment.

Microsoft MVP

VEEAMLEGEND

vexpert-badge-stars-5

Virtual Background

GoogleNews

Categories

veeaam100

sysadmin top30a

  • CreateanAWSact
    How to Set up an Amazon Web Services (AWS) Account AWS/Azure/OpenShift
  • header picture 1
    Azure CI/CD: Configuring Email Notifications in Azure DevOps AWS/Azure/OpenShift
  • How to Find Out Which Users Are Logged on Windows Server
    How to Find Out Which Users Are Logged on Windows Server Windows
  • cisco general
    How to update Cisco ASA Network | Monitoring
  • sql server
    Download and install MSSQL 2019 Express Edition and SSMS Oracle/MSSQL/MySQL
  • 2022 1
    Install Windows Server 2022 on VirtualBox Network | Monitoring
  • How to configure Azure container register with secured connection with container apps
    Configure Azure Container Registry for a secure connection with Azure Container Apps AWS/Azure/OpenShift
  • sdgfdhx
    MDT Warning: Unable to set working directory, the application returned an unexpected code 2 Windows Server

Subscribe to Blog via Email

Enter your email address to subscribe to this blog and receive notifications of new posts by email.

Join 1,832 other subscribers
  • RSS - Posts
  • RSS - Comments
  • About
  • Authors
  • Write for us
  • Advertise with us
  • General Terms and Conditions
  • Privacy policy
  • Feedly
  • Telegram
  • Youtube
  • Facebook
  • Instagram
  • LinkedIn
  • Tumblr
  • Pinterest
  • Twitter
  • mastodon

Tags

AWS Azure Bitlocker Microsoft Windows PowerShell WDS Windows 10 Windows 11 Windows Deployment Services Windows Server 2016

Copyright © 2025 TechDirectArchive

 

Loading Comments...
 

You must be logged in to post a comment.