Access Protection allows you to define access control policies and settings for processes, files, and directories. By restricting access to specific files and directories, you can protect your systems from vulnerabilities.
You can create Access Protection rules, edit the rule settings, or delete the rules from the command line. You can also enable, disable, or change the ePO - On-prem default rules. But you can’t delete these rules. For each rule, you can define the action as Report, Block, or Block and Report. Access Protection also allows global exclusion to exclude processes that are critical for business criticality.
For managed systems, the policies that you configure on client systems are overridden by the Access Protection policies from ePO - On-prem during the policy enforcement. There are no Trellix default rules defined for standalone systems.