Application Control Options policy (Windows) — Self-Approval tab

Prev Next

Enable the self-approval feature on endpoints.

Option definitions

Option

Definition

Enable Self-Approval

Enables the self-approval feature.

Self-Approval Text

Specifies the message to display on the endpoint in the Trellix Application Control - Self-Approval dialog box. When a user tries to run a new or unknown application, the dialog box appears.

This option is enabled only when Enable Self-Approval is selected.

The pop-up message:

  • Supports up to 1500 characters.

  • Supports special characters.

  • Can include links which are highlighted in blue and are clickable.

    • Links can be included anywhere in the banner text.

    • Web URLs are detected with and without the protocol http or https, for instance www.example.com or http://www.example.com.

    • Other protocols are supported with the full URL text, such as email addresses mailto:user@example.com or FTP server ftp://ftpserver.com

Dialog Timeout

Specifies the time duration (in seconds) for which the Trellix Application Control - Self-Approval dialog box displays on the endpoint after an action is prevented by Application Control.

If the user does not take an action for the application in the specified time duration, the execution of the application is automatically denied and the dialog box closes.

This option is enabled only when Enable-Self Approval is selected.

Justification Message

Indicates whether it is mandatory or optional for the user to provide a business need or justification while allowing an action on the endpoint. By default, this is set to Mandatory.

This option is enabled only when Enable Self-Approval is selected.

Advanced Options

Specifies the behavior for applications when the system is starting or when an interactive session is unavailable. In either of these scenarios, Application Control cannot display the Trellix Application Control - Self-Approval dialog box. If you select this option, applications that run on the system while it is starting or when an interactive session is unavailable are allowed to execute.

This option is enabled only when Enable-Self Approval is selected.