Application Control Options policy (Windows) — Features tab

Prev Next

Enable or disable selected features on endpoints.

This page is useful to diagnose or troubleshoot issues faced on endpoint systems.

Option definitions

Option

Definition

Feature Control

Enforce feature control from Trellix ePO

Enables or disables selected features on endpoints. Only when this option is selected are the settings for the following features applied to the endpoints.

ActiveX

By default, Application Control prevents the installation of ActiveX controls on endpoints. Select this option to enable the ActiveX feature to install and run ActiveX controls on endpoints. Alternatively, deselect this option to disable the ActiveX feature on endpoints.

This feature is available only on the Windows platform.

Execution Control

Application Control performs a set of checks to determine whether to allow or block a file. For files whose execution is allowed after the checks, you can define additional granular and context-based rules to control execution. You can define attribute-based rules to allow, block, or monitor file execution in different contexts.

Memory Protection

Enables or disables these memory-protection techniques on endpoints.

CASP

Enables or disables the Critical Address Space Protection technique on endpoints.

NX (64-Bit)

Enables or disables the No eXecute technique on endpoints.

Generate Observations

Enables or disables the generation of observations in Enabled mode.

Package Control

By default, Application Control prevents MSI-based installers from running on endpoints. Select this option to enable the Package Control feature to allow MSI-based installers to run and install software on endpoints. Alternatively, deselect this option to disable the Package Control feature on endpoints.

Note

For endpoints running versions earlier than 6.1.1, a restart is required to enable the Package Control feature.

Bypass Package Control

Bypasses package control on endpoints running version 6.1.1 or later.

Allow Uninstallation

Allows uninstallation of software packages on endpoints running version 6.1.1 or later.