> For the complete documentation index, see [llms.txt](https://doc.duaer.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://doc.duaer.com/integrations/builtin/credentials/trellixepo.md).

# Set up Trellix (McAfee) ePolicy Orchestrator credentials in Duaer

Store Trellix (McAfee) ePolicy Orchestrator connection details in Duaer for digital-organization nodes to use at runtime. Secrets are protected by the instance encryption key and are not written into node parameters.
## Fill in the Trellix ePO credential <a href="#get-your-credentials" id="get-your-credentials"></a>

The Duaer Trellix (McAfee) ePolicy Orchestrator API credential uses an ePO console account with basic auth:

1. In ePO, create an account under User Management > Users with only the permission sets it needs.
2. Put the account in Username and Password.

Duaer has no dedicated node for this service. In the HTTP Request node, set Authentication to Predefined Credential Type and pick the Trellix (McAfee) ePolicy Orchestrator API credential. Refer to [custom operations](/integrations/custom-operations.md).

Point requests at the ePO server remote command interface, such as https://epo.example.com:8443/remote/.

## Trellix (McAfee) ePolicy Orchestrator API fields in Duaer <a href="#trellix-mcafee-epolicy-orchestrator-api" id="trellix-mcafee-epolicy-orchestrator-api"></a>

In Duaer, choose Trellix (McAfee) ePolicy Orchestrator API when you create a credential, then fill in these fields:

- Username (required)
- Password (required, secret)

## Save the connection in Duaer

Open Credentials and create Trellix (McAfee) ePolicy Orchestrator. Fill in the key, OAuth, or server fields. After you save, digital-organization nodes reference this credential instead of putting the secret in a parameter.

Credential values are protected by the instance encryption key. If you change or lose that key, stored credentials cannot be decrypted. See the hosting notes on encryption keys. 

## Who can use this credential

Who can see or edit it follows projects and roles. Do not paste secrets into chat or variables. External vaults are covered under external secrets.
## Questions

### Do Trellix (McAfee) ePolicy Orchestrator secret values appear in Duaer node parameters?

No. In Duaer, Trellix (McAfee) ePolicy Orchestrator secrets stay in the credential. Nodes only reference the credential. Execution records should not show the plaintext secret either.

### What usually stops a Trellix (McAfee) ePolicy Orchestrator credential from saving in Duaer?

Wrong fields, an OAuth callback that does not match the instance URL, or a role that cannot create credentials. Check the fields Trellix (McAfee) ePolicy Orchestrator expects, then confirm you can create credentials in that project.

