TrellixEndpoint Security

    ePolicy Orchestrator

    One console for policy, posture, and enforcement across the whole estate.

    Trellix ePolicy Orchestrator (ePO) is the centralised management platform the rest of the Trellix portfolio runs through — a single pane of glass for policy, compliance status, and security posture across every device. The SaaS edition removes the infrastructure entirely: zero deployment time, continuous updates, FedRAMP certified. Faltrox holds the console so your team does not have to.

    Overview

    What ePolicy Orchestrator is

    Trellix ePolicy Orchestrator (ePO) is the centralised management platform the rest of the Trellix portfolio runs through — a single pane of glass for policy, compliance status, and security posture across every device. If you run more than one Trellix product, you are running ePO. It does not detect threats itself; it is where deployment, policy enforcement, and posture reporting are consolidated.

    The SaaS edition removes the infrastructure entirely: zero deployment time, continuous updates, and FedRAMP certification, with local and regional data centres for residency requirements. It co-manages the security controls built into Windows rather than replacing them, avoiding a second console and its licence. Faltrox holds the console, tunes the policy catalogue, and acts on what the Protection Workspace surfaces, so your team keeps policy intent and approvals without operating the platform.

    Coverage

    What it protects

    The platforms, threats, and surfaces this product is built to defend.

    01

    Windows Endpoints

    Deploys, monitors, and manages Trellix and native Windows security across the desktop and server estate.

    02

    Heterogeneous Devices

    Shared policies span Windows and non-Windows devices for consistency across a mixed estate.

    03

    Native Windows Controls

    Co-manages Windows Defender Antivirus, Exploit Guard, and Firewall alongside Trellix technology.

    04

    Security Posture

    The Protection Workspace summarises risk and posture across your entire digital terrain in one view.

    05

    Policy Compliance

    A single dashboard shows the compliance status of all endpoints against your policy baseline.

    06

    The Whole Estate

    Instant policy push and automated remediation reach every managed endpoint from one console.

    How it works

    The mechanism

    How the product moves from signal to protected state, step by step.

    1. 01

      Connect

      Brings together data from multiple sources — Trellix controls and native Windows controls — into one management interface.

    2. 02

      See

      The Protection Workspace prioritises risk and summarises posture across the estate in a single graphical view, with drill-down into events.

    3. 03

      Set Policy

      A comprehensive, customisable policy catalogue defines security controls, with an optional approval gate before any change goes out.

    4. 04

      Enforce

      Policies push to all endpoints instantly, and contextual routing directs alerts and responses by the type and criticality of the event.

    5. 05

      Automate

      Automated remediation triggers an action when an event occurs — from a notification to approved containment — across security and IT operations.

    Capabilities

    Key capabilities

    Protection Workspace

    Prioritises risk and summarises security posture across your entire digital terrain in one graphical view, with drill-down into specific events — replacing the report-building cycle with a live view.

    Zero Deployment

    The SaaS edition takes zero minutes to stand up and removes the setup and maintenance of security management infrastructure altogether.

    Windows Defender Co-Management

    Manages the native controls built into Microsoft Windows alongside Trellix technology, with shared policies across Windows and heterogeneous devices, avoiding a second console and its licence.

    Instant Policy Enforcement

    A comprehensive, customisable policy catalogue pushes to all endpoints instantly, with an optional approval gate before any new or updated policy goes out.

    Contextual Routing

    Directs alerts and responses based on the type and criticality of the event for your environment, policies, and tools, rather than broadcasting everything to one queue.

    Automated Remediation

    Triggers an action automatically when an event occurs — from a notification to approved remediation — and builds workflows between security and IT operations systems.

    Predictive Threat Analysis

    Surfaces proactive remediation targets and feeds critical device insight into your SIEM or SOAR, so posture data reaches the tools your analysts already live in.

    Governed Access

    Role-based access control, two-factor authentication, personalised dashboards per user, and local or regional data centres for residency requirements.

    Specifications

    Technical detail

    Delivery
    SaaS (zero deployment) or on-premises
    Certification
    FedRAMP certified
    Access Control
    Role-based access control with two-factor authentication
    Data Residency
    Local and regional data centres
    Extensibility
    Marketplace apps and public APIs
    Standards Alignment
    CIS Controls and Benchmarks, NIST SP 800-53

    Works with

    Part of the platform

    Trellix products this pairs with, and the Faltrox services that operate it.

    Delivery

    You buy the outcome, not the console

    Managed by Faltrox

    Faltrox licenses, deploys, and tunes Trellix ePolicy Orchestrator for your environment, then runs it as part of a managed service, so you get the protection without staffing another security console.

    See the service

    FAQ

    Common questions

    01Is ePO a security product or a management console?

    A management console. It does not detect threats itself — it is where policy, deployment, compliance status, and posture reporting for the Trellix portfolio are centralised. If you run more than one Trellix product, you are running ePO.

    02SaaS or on-premises?

    SaaS removes infrastructure maintenance entirely and updates continuously. On-premises is the right call when data residency or air-gap requirements demand it. Migration between them is designed to be gradual without disrupting daily operations.

    03Does it replace Windows Defender?

    No — it manages it. ePO co-manages Defender Antivirus, Exploit Guard, and Firewall policy with shared policies across your Windows and non-Windows estate, so you get one console rather than two overlapping products.

    04What does the FedRAMP certification mean for us?

    It matters if you work with US federal agencies or contracts that inherit federal requirements. For everyone else it is a useful proxy for the platform having passed a rigorous third-party security assessment.

    05If Faltrox holds the console, what do we still control?

    Policy intent and approvals. We operate the console, tune the policy catalogue, and act on what the Protection Workspace surfaces; you keep role-based access to the dashboards and sign-off on policy changes through the approval workflow.

    Start an engagement

    Secure what’s next.

    Speak with the engineering team to define scope, walk through the methodology, and decide whether Faltrox is the right team to test and run your environment.

    Contact us