Skip to content

TechDirectArchive

Hands-on IT, Cloud, Security & DevOps Insights

  • Home
  • About
  • Advertise With US
  • Reviews
  • Contact
  • Toggle search form
Home » Security | Vulnerability Scans and Assessment » ePO Server Settings: Trellix ePO AD integration and ENS Agents Installation
  • Protect OOTBI
    Best Storage for Veeam: Comparing OOTBI by ObjectFirst to VHR Backup
  • cockpit
    Installation and configuration of Cockpit on CentOS Linux Linux
  • Enable or disable SA acocunt
    How to enable an SA account that has been disabled Oracle/MSSQL/MySQL
  • The evolution of Windows authentication   NTLM to Keberos
    Bidding Farewell to NTLM in favour of Kerberos Windows
  • fdsdsd
    Configuring DHCP Scope: Post-deployment of Dynamic Host Configuration Protocol Windows Server
  • Microsoft LAPS
    Configure Windows LAPS Management with Microsoft Intune AWS/Azure/OpenShift
  • images copy
    HA-Proxy Configuration File: Copy Between Nodes on Proxmox VE Virtualization
  • Recovery keys in AD 1
    Backup existing and new BitLocker Recovery Keys to Active Directory Windows Server

ePO Server Settings: Trellix ePO AD integration and ENS Agents Installation

Posted on 29/03/202402/07/2025 Christian By Christian No Comments on ePO Server Settings: Trellix ePO AD integration and ENS Agents Installation
Trellix-configurations-after-ePo-setup

Trellix ePolicy Orchestrator (ePO) is a centralized security management platform that helps orchestrate and manage your endpoints from a single console. In this article, we shall discuss “Trellix ePO AD integration and ENS Agents Installation”. Not limited to these bt Trellix Account creation, and Trellix agent update etc. Please see Manage BitLocker and FileVault with Trellix Native Encryption, and how to Disable SQL Auto Close: Auto Close is enabled for both ePO and ePO Events Databases.

After Trellix ePolicy Orchestrator Installation on Windows Server. You might want to upgrade Trellix ePolicy Orchestrator. If there areissues during the setup, you will find this guide on “Fixes to Trellix ePolicy Orchestrator Installation Errors” very useful.

Server Task

we shall discuss some more settings in details later. but ensure you define the frequency for your desired tasks as shown below.

Server tasks

Integrate Active Directory with Trellix

Trellix ePO on-premise simplifies the process of managing users by automatically creating Windows authentication users based on their Active Directory group membership.

After the setup of ePO, you might want to integrate it with Active directory. Below are the steps to integrate Trellix ePO with Active Directory. This step assumes you have setup a Domain Controller as Recommended by Microsoft. See how to setup a Domain Controller.

Log in to your Trellix administrative interface. Under Configuration, select “Registered Servers”.

Register-servers-on-trellix

On the Registered Servers, select LDAP.

Registered-server-types
Registered server - Directory Server
New server types available after installing Service Pack 1 – Update 5

Populate the field below and click Save.

Populate-Field-with-AD-information

As you can see, the fields are populated. To confirm everything is working correctly, hit the test connection button below. It the credentials are fine, you should see “successfully connected to the LDAP server”.

LDAP-Connection-successful

Yes, we have our ePO correctly bonded with the LDAP Server.

Server-registered

Please, see Fix MSIEXEC returned 1602: Trellix Setup cannot use this account, and How to enable FIPS mode on Windows Server.

Add Domain users

To add AD users on Trellix, click the Trellix menu and under user management. Select Users.

Authenticte-to-ePO-with-Domain-user-Account

Click “New User”

Add-new-user

I am interested in creating a new account with Windows authentication. Please populate the field below. You can also create an account with ePO authentication or certificate-based authentication

AD-account-created
Now, you should be able to login to the ePO console with your domain credential.

Enable Active Directory User Logon on Trellix

We have discussed more of these steps here: Selfservice Recovery: Trellix BitLocker and fileVault Recovery. If you do not want to import an AD user as we have done above, you will have to enable allow Active Directory users to log on if the have at least one permission set.

To do this, click on Menu and under Configurations, select Server Settings. Edit the settings and click Yes.

Disallow-D-users-from-loggin-in

Note: If Active Directory User Login is enabled when an unknown user tries to log on. Trellix ePO server checks to see any permission sets mapped to Active Directory groups for which the user is a member. If there are, Trellix ePO creates a Windows authentication user and assigns the mapped permission sets to it. To enable this feature, you must do the following:

  • Active Directory User Login must be enabled as shown above.
  • At least one permission set must be mapped to the user’s Active Directory group
  • A registered LDAP server must be configured for the domain, so that Trellix ePO can determine the user’s group membership.

Delete or Disable an Imported AD User

To do this, you will follow the same method as if you were editing a use. Select “Actions” and then delete. Click the OK to confirm deletion.

delete-a-user-account

Trellix Agent Checkin (Installation on ePO)

Trellix ENS intercepts threats, monitors overall system health, and reports detection and status information. Client software is installed on each system to perform these tasks.

There are numerous ways to load Trellix Agents unto ePO. You could check them in using extension or the repository. But, I have decided to use the Software Catalog. The Trellix Software Catalog removes the need to access the Trellix Product Download website to retrieve new Trellix software and software updates.

Note: You can use the Software Catalog to install, upgrade, and remove Trellix Endpoint

To do this, click on the Trellix menu and under software. Select Software Catalog. After deploying ePO, you are required to deploy Trellix agents to endpoints as a prerequisite for other deployments. As shown below, I will select all packages relating to Trellix agents and checked them all in.

Trellix-Agent-Checkin

Accept the license terms and check them in as shown below.

Trellix-components-to-checkin

The Trellix Endpoint extensions and endpoint package are installed and updated on the Trellix ePO server.

Updating-agents

You can take a look at the Server task Details for more information.

View-tasklog

Here is how to checkin Trellix Management for Native Encryption as well.

Checkin Extension
Checkin Extension

Create a custom McAfee Agent installation package in ePO

This steps involves using a distribution method other than ePO deployment. To create an ePO custom agent installation package, please follow the steps below.

Method 1:

Log on to the ePO console. If the agent package is not checked in, go to the Software Catalog and check in the embedded package version of the agent. Next, click Menu, Systems Section, System Tree.

system-tree

Select New Systems from the top-left corner.

New-System-tree

Under how to add systems, you can see you have different options.

In my case, I am interested in showing the steps to "create and download agent installation packages". Also, I am interested in Trellix agent for Windows and Mac and click ok.
create-and-download-agents

You are prompted to download the file. You can click on the link or right click and select save link as.

save-link-as

Method 2: Link My Organisation to Active Directory

The “My Organization group” is the root of your System Tree. It contains all systems added to or detected on your network (manually or automatically). Until you create your own structure, all systems are added by default Group. The My Organization group has these characteristics as they cannot be deleted, and cannot be renamed.

If your network runs Active Directory, you can use Active Directory synchronization to create, populate, and maintain parts of the System Tree.

Once defined, the System Tree is updated with any new systems (and subcontainers) in your Active Directory.

So let’s perform the synchronisation. Click on my Organisation and under group details, select edit close to the Synchronisation button. Also, this step assume you have integrated your ePO with AD as shown above.

Define-Syncronization

Select Active Directory and other settings that pertain to you. To integrate a contain (OU), click the Browse button to select the OU you wish to integrate on ePO.

Browser-containers

When all fields have been populated. Enter your service account and password as this will be used to install the agents on the PC. Click Save when complete.

organisation-settings-sync

If you were to configure agent policy, you would do it from here as shown below when syncing group details. I will do these at a later time. Just showing you the steps to. You will see this step again when we wish to push the agent.

Trellix-Agent-push-settings

Create a Sub-group

Now that we have synced the “My Organisation Group”, lets create an OU structure on ePO to reflect our AD environment.

Note: There is no single way to organise a System Tree, and because every network is different, your System Tree organisation can be as unique as your network layout. You can use more than one method of organisation

To do this, click the Trellix Menu, Systems and System Tree. Select your organisation and click on “New Subgroup”.

Create-subgroup

Enter the New Subgroup name and click OK.

enter-subgroup-name

Note: If you delete systems from the System Tree, make sure that you select the option Remove agent from all systems. If the McAfee Agent is not removed, deleted systems reappear in the Lost and Found group because the McAfee Agent continues to communicate to Trellix ePO Cloud. Also, unless you select Remove agent installed products from all systems, the product software remains installed on the systems deleted from the System Tree.

Assign the Service Account to the Computer Administrator Group

The PCs should be discovered by Trellix. Depending on your AD setup/permission, you may have to set up a service account and assign it to the PCs in order to be able to push the agents.

Connect to the PC interactively or remotely.You could use the Computer Manager to connect as shown below.

connect-to-a-PC-remotely

Expand local Users and Groups and right click or double click on Administrators. Now that we have configured the permission, let’s proceed with the agent deployment.

Add-the-account-in-order-to-manage-the-PC

Trellix Agent Deployment

This steps require the manual deployment of agents. Click on the PC under Systems. from Actions, select Agent and then Deploy agents.

Deploy-agents

In the Trellix Deploy Agent window, click on OK.

Agent-settings

Let’s review the Server task to see the progress of the Agent Deployment. As you can se, it is in progress.

agent-deployment-in-progress

The agent deployment has succeeded and completed successfully.

agent-successfully-deployed

The PC is recognised as managed. Now, deploy the agent to the rest devices manually or follow the steps below to assign the agent via automatic assignment..

PC-recognized-as-managed-by-Trellix

Automatic Agent Assignment

This can be achieved by using the Assigned Client Tasks under the system tree. Luckily, I did not have to create a Policy using the Policy catalogue. See Manage BitLocker and FileVault with Trellix Native Encryption for more information on this topic.

Assign Client Task. When this is done by following the prompts and selecting the right OU or group etc. The assignment field will change to 1 Assignment.

Client-task-for-Trellix-Agent

Edit the assignement

Define-the-schedule-by-editing-this-assignment

Define the schedule as shown below

Save-Assignment

Trellix Product Deployment

In this section, we will discuss deployment tasks for installing products on managed systems.

Note: Product packages must be checked in before deploying them. By now, you should be familiar with the process of deploying a package.

To do this, click on Trellix Menu, and under Software, select “Product Deployment”.

Product-deployment

Select new deployment

New-product-deployment

Populate the fields for product deployment window as shown below.

Populate-product-deployment-field

Automatic Task Synchronisation

Server tasks are scheduled management or maintenance tasks that you run on your Trellix ePO – on-prem server.

Server tasks enable you to schedule and automate repetitive tasks. Use server tasks to monitor your server and software., We can verify the ePO server tasks to ensure the smooth operation. From the Trellix Menu, click Server Tasks.

Trellix-server-task

Click New Task.

New-server-task

We will configure automatic AD and ePO synchronisation as shown below.

Server-Task-Buider-name

You can select a select OU (container) to synchronise with and click OK.

select-sync-group

Define the schedule as you wish

set-schedule

On the summary page, do not forget to click save.

Save-Task-to-automate-Trellix-AD-sync

Below are some server tasks and the newly created server task.

Verify LDAP sysc is enabled

ePO Server Custom SSL Certificate Configuration

All the necessary settings specific to your ePO server are in Server Settings.

The Server Certificate option will enable you to protect and secure the connection to the ePO server and ensure it is trusted. 

To do this, log on to the ePO console, click Menu, under Configuration, and select Server Settings.

Server-Settings

Click Server Certificate under Setting Categories, and then click Edit.

Edit-Server-Certiifcate-Settings

Select Use the provided certificate and private key.

Save-Certificate-and-Private-Key

Click Browse in the Certificate (P7B, PEM) field. Locate and select the certificate file (.p7b or .cer). Then, click Open. Also, click Browse in the Private key (PEM) field.

Browser-certs

Please save the settings

Services-restart

Restart the following ePO services, and close the services manager when complete.

Trellix ePolicy Orchestrator x.x.x Application Server
Trellix ePolicy Orchestrator x.x.x Event Parser
Trellix ePolicy Orchestrator x.x.x Server
Services-restarts

FAQs relating to Trellix ePO AD integration and ENS Agents’ Installation

What authentication types are supported with BitLocker on Trellix ePO?

MNE supports TPM, TPM+PIN, and Password authentication. Password authentication is only available with Windows 8 and later.

How do I make McAfee agent unmanaged?

To change from managed to unmanaged mode on Windows systems (ePO On-Premises), select Menu → Systems → System Tree. Select the systems to change to unmanaged mode. Click Actions, select Directory Management, then click Delete.
Select Remove McAfee Agent on next agent-server communication and confirm the deletion.

I hope you found this article on “Trellix ePO AD integration and ENS Agents Installation” useful. Please feel free to leave a comment below.

5/5 - (1 vote)

Thank you for reading this post. Kindly share it with others.

  • Click to share on X (Opens in new window) X
  • Click to share on Reddit (Opens in new window) Reddit
  • Click to share on LinkedIn (Opens in new window) LinkedIn
  • Click to share on Facebook (Opens in new window) Facebook
  • Click to share on Pinterest (Opens in new window) Pinterest
  • Click to share on Tumblr (Opens in new window) Tumblr
  • Click to share on Telegram (Opens in new window) Telegram
  • Click to share on WhatsApp (Opens in new window) WhatsApp
  • Click to share on Pocket (Opens in new window) Pocket
  • Click to share on Mastodon (Opens in new window) Mastodon
  • Click to share on Bluesky (Opens in new window) Bluesky
  • Click to share on Threads (Opens in new window) Threads
  • Click to share on Nextdoor (Opens in new window) Nextdoor
Security | Vulnerability Scans and Assessment Tags:ePO, ePolicy Orchestrator, Microsoft Windows, Windows 10, Windows 11, Windows Server 2016

Post navigation

Previous Post: Selfservice Recovery: Trellix BitLocker and fileVault Recovery
Next Post: How to Sync Data in Cloud Drives to Synology NAS

Related Posts

  • Uninstall MicrosoftDefenderUpdate
    What you need to know about Microsoft Defender Antivirus Security | Vulnerability Scans and Assessment
  • Screenshot 2020 12 29 at 04.08.43
    Enable or disable BitLocker Drive Encryption on Windows Security | Vulnerability Scans and Assessment
  • How to Register Devices to Microsoft Intune and EntraID Using My Company Portal
    Register Devices to Intune and EntraID Using Company Portal AWS/Azure/OpenShift
  • Print Spooler
    Mitigate Windows Print Spooler Remote Code Execution Vulnerability Security | Vulnerability Scans and Assessment
  • 5rgh65436
    New Windows 11 encryption features and security enhancements for Hybrid Work Security | Vulnerability Scans and Assessment
  • Complete Guide on TestRail as a Test Management Tool   banner
    Complete Guide on TestRail as a Test Management Tool Security | Vulnerability Scans and Assessment

More Related Articles

Uninstall MicrosoftDefenderUpdate What you need to know about Microsoft Defender Antivirus Security | Vulnerability Scans and Assessment
Screenshot 2020 12 29 at 04.08.43 Enable or disable BitLocker Drive Encryption on Windows Security | Vulnerability Scans and Assessment
How to Register Devices to Microsoft Intune and EntraID Using My Company Portal Register Devices to Intune and EntraID Using Company Portal AWS/Azure/OpenShift
Print Spooler Mitigate Windows Print Spooler Remote Code Execution Vulnerability Security | Vulnerability Scans and Assessment
5rgh65436 New Windows 11 encryption features and security enhancements for Hybrid Work Security | Vulnerability Scans and Assessment
Complete Guide on TestRail as a Test Management Tool   banner Complete Guide on TestRail as a Test Management Tool Security | Vulnerability Scans and Assessment

Leave a Reply Cancel reply

You must be logged in to post a comment.

Microsoft MVP

VEEAMLEGEND

vexpert-badge-stars-5

Virtual Background

GoogleNews

Categories

veeaam100

sysadmin top30a

  • Protect OOTBI
    Best Storage for Veeam: Comparing OOTBI by ObjectFirst to VHR Backup
  • cockpit
    Installation and configuration of Cockpit on CentOS Linux Linux
  • Enable or disable SA acocunt
    How to enable an SA account that has been disabled Oracle/MSSQL/MySQL
  • The evolution of Windows authentication   NTLM to Keberos
    Bidding Farewell to NTLM in favour of Kerberos Windows
  • fdsdsd
    Configuring DHCP Scope: Post-deployment of Dynamic Host Configuration Protocol Windows Server
  • Microsoft LAPS
    Configure Windows LAPS Management with Microsoft Intune AWS/Azure/OpenShift
  • images copy
    HA-Proxy Configuration File: Copy Between Nodes on Proxmox VE Virtualization
  • Recovery keys in AD 1
    Backup existing and new BitLocker Recovery Keys to Active Directory Windows Server

Subscribe to Blog via Email

Enter your email address to subscribe to this blog and receive notifications of new posts by email.

Join 1,836 other subscribers
  • RSS - Posts
  • RSS - Comments
  • About
  • Authors
  • Write for us
  • Advertise with us
  • General Terms and Conditions
  • Privacy policy
  • Feedly
  • Telegram
  • Youtube
  • Facebook
  • Instagram
  • LinkedIn
  • Tumblr
  • Pinterest
  • Twitter
  • mastodon

Tags

Active Directory AWS Azure Bitlocker Microsoft Windows PowerShell WDS Windows 10 Windows 11 Windows Server 2016

Copyright © 2025 TechDirectArchive

 

Loading Comments...
 

You must be logged in to post a comment.