User Tools

Site Tools


zotdefend_v2

This is an old revision of the document!


ZotDefend security package information

What is ZotDefend?

ZotDefend is OIT's branding for the programs and policies that are being enforced in response to the letter that was sent out by the UCOP president in May of 2024 that set specific requirements.

More information about ZotDefend, including what needs to be installed, can be found in the FAQs below.

Temporary Exemption

If you need to quickly access a site that has been blocked, you can request a temporary exemption at the link below:

You may do this on personal devices and as often as needed.

How to set up ZotDefend on your computer:

Method One (preferred): Book an appointment with SSCS

Send us an email (sscs@uci.edu) to make an appointment to set up the ZotDefend requirements on your computer. This is only required on university-owned computers, not on tablets, phones, or personal devices. Please provide your computer's property tag, which is on a barcode sticker on your computer and looks like this:

Property Tag

The appointment should take 30 minutes, during which we will install an application called BigFix. This will add the computer to our inventory and we can use that to install the other remaining required applications in the background while you can continue using the computer normally.

We will use an application called BigFix to install the following packages:

Method Two: Install the ZotDefend components on your own

Instructions for Windows computers

If you use a Windows computer and would prefer to do this on your own, you can download the installer for BigFix for your computer on your own:

The BigFix installer is password protected. We will provide the password to open the .zip after you have sent us the property tag for your computer. See the example image above for what a property tag looks like.

After BigFix is installed, we can use that to automate the installation of Duo Desktop, Trellix HX, and Tenable Nessus.

Instructions for Mac computers

If you use a Mac computer, then we recommend scheduling an appointment with us by contacting us via email (sscs@uci.edu). When you reach out to us, please provide the property tag for your computer. See the example image above for what a property tag looks like.

You can install BigFix, but we have found that Trellix HX does not usually install correctly. It requests specific system permissions, and if you miss the security pop-up, click the wrong button, or do not give it the requested permission, then the installation ends in a broken state and we must manually uninstall and reinstall it.

Instructions for Linux computers

Please reach out to us via email (sscs@uci.edu) to let us know which computer(s) you are setting this up on and we can send you an installation script. When you reach out to us, please provide the property tag for your computer. See the example image above for what a property tag looks like.

FAQs about ZotDefend

How do I request an exemption?

If you need to log in to a site that is blocked because you do not yet have the ZotDefend security packages installed, you can use the link below to request a 24-hour exemption:

What are the software components being installed?

  • BigFix is a software management tool that OIT has selected for the IT groups across campus to use to remotely install software. This is only for Windows and Mac computers, not Linux.
  • Trellix HX is the software that OIT selected to meet the EDR (endpoint detection and response) requirement of the mandate.
  • Tenable Nessus is the software that OIT selected to meet the vulnerability management requirement of the mandate
  • Duo Desktop is installed when needed to access websites and services that OIT has determined require enforcement of a more strict security policy.

Which websites require Duo Desktop, in addition to Trellix HX and Tenable Nessus?

Duo Desktop is required in order to verify your device's status when accessing the following websites and services:

Please be aware that OIT might change the security requirements in the future as well. We will update this page as more information becomes available.

What is the UC Cybersecurity Mandate?

OIT has a detailed overview page at the following link that reviews each component of the mandate:

Essentially, UC President Michael Drake issued a letter to the chancellors of the UC campuses that requires compliance with a new policy by May 28, 2025. “ZotDefend” is the branding used for OIT's plan to comply with this letter.

The components of the policy that affect our community in Social Sciences are:

  1. 100% compliance with cybersecurity awareness training
    • this is done through our annual UCLC trainings
  2. identification, tracking and vulnerability management of all computing devices
    • this is a shared responsibility between OIT, SSCS (Social Sciences Computing Services), and you (staff and faculty in our school)
    • SSCS tracks our inventory of computing devices in an internal database
    • OIT runs a vulnerability management program and SSCS works with them to remediate devices identified as having vulnerabilities.
    • the Tenable Nessus agent that is installed as part of the ZotDefend security package complements the capability of the network scanners that OIT operates
    • all users of university-owned computers must keep their devices up to date by applying the latest updates when they become available
  3. deploy and manage UC-approved Endpoint Detection and Recovery (EDR) software
    • this is accomplished by the installation of Trellix HX as part of the ZotDefend security package
  4. deploy, enable, and configure multi-factor authentication (MFA) on email systems
    • this is done by requiring DUO when logging in to gmail and outlook email systems

Is ZotDefend required on personal computers too?

No, it is neither required nor recommended to install or configure any of this on computers/devices personally owned by you. All official university business should be done on university-owned computers.

Keep in mind that tablets, phones, and similar devices are also exempt from the ZotDefend project.

But I use a personal computer for work...

If you do not have a university-owned computer (purchased either with school funds or grant funding), reach out to us at sscs@uci.edu and we can help you determine what to do.

What has OIT published about ZotDefend?

What do I do if I installed ZotDefend following OIT's self-enrollment instructions?

Please reach out to us (sscs@uci.edu) and let us know the property tag of your computer. OIT's version of BigFix is different than what we use, so we may need to help you uninstall BigFix and any other extra components that OIT's self-enrollment instructions caused to be installed (e.g. MS Defender). Once that is sorted out, then we can help you re-install just the required packages.

What is UCOP's response to my concerns about Trellix?

UCOP has released the following FAQ regarding concerns about the EDR software, Trellix HX:

zotdefend_v2.1749151215.txt.gz · Last modified: 2025/06/05 19:20 by jnilsson