We are proud to announce the General Availability of Trellix Drive Encryption (DE) 8.1.1 On-premises on March 25, 2026.
This release addresses the upcoming expiration of the Microsoft Unified Extensible Firmware Interface (UEFI) 2011 Certificate Authority (CA) and the upgrade to the MS UEFI 2023 Certificate Authority (CA).
Microsoft is expiring the 2011 Certificate used by DE for pre-boot. You must upgrade to DE 8.1.1 before June 2026 to ensure that encrypted devices remain secure. Failure to upgrade may result in devices that cannot boot and potential operational outages.
This upgrade ensures hardware compatibility with modern UEFI requirements, protects data integrity, and eliminates the risk of system failures associated with the retiring certificate.
Important: Before deploying DE 8.1.1, administrators must update the Secure Boot database with "Microsoft UEFI CA 2023" and "Microsoft Option ROM UEFI CA 2023" on all Windows 10 and later systems. If the UEFI Secure Boot database is not updated with CA 2023 certificate, the upgrade to DE 8.1.1 will intentionally abort.
See the Release Notes and Knowledge articles for additional information and detailed instructions:
- Release notes and other documentation:
- Knowledge articles:
Note: To receive information about product updates, sign up for the Support Notification Service.
For instructions, see the Thrive Portal User Guide and navigate to Profile and Settings > My Settings > Manage Support Notification Services (SNS) subscription preferences.