Dear Customer,
Following our recent announcement regarding the Trellix Drive Encryption (TDE) 8.1.1 On-prem and SaaS releases, we would like to remind you to prepare for the upcoming Microsoft UEFI certificate expiration in June 2026, impacting customers of TDE for pre-boot in Windows 10 and later.
While the existing certificates may not be revoked immediately, it is recommended that customers update the impacted systems and transition to TDE 8.1.1 as soon as possible. When the certificates are revoked by Microsoft or hardware vendors, it could cause significant operational impacts for organizations that have not upgraded.
Important: Before deploying TDE 8.1.1 SaaS, administrators must update the Secure Boot database with "Microsoft UEFI CA 2023" and "Microsoft Option ROM UEFI CA 2023" on all Windows 10 and later systems.
If the UEFI secure boot database is not updated with the CA 2023 certificate, the upgrade to TDE 8.1.1 will intentionally abort.
Important note for customers also using Trellix Native Drive Encryption (TNE): prior to initiating any certificate updates, it is strongly advised to verify that recovery keys are accessible in every system. Customers may be impacted by a known issue when a cloud native identity management system is in use on the endpoint, such as EntraID (AzureID).
Note: Endpoints with an Active Directory ID are not affected. Key availability can be verified in ePO. For more details, consult KB Article.
Also, please note that to comply with FIPS 140-3 standards, TDE (On-Prem 8.1.0 and SaaS 8.1.2602) now requires a minimum user password length of 7 characters, which will be enforced during the next user-initiated or scheduled password change. Customers upgrading directly to 8.1.1 will be impacted by this change.
See the following documentation for additional information and detailed instructions.
- TDE - SaaS
- TDE - On-Prem
If you have any questions or require assistance with your upgrade plan, contact your Trellix Account Team or Support representative.