The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in mid-October 2026. We hope you enjoy the updated experience.

Assigning multiple instances of Exploit Prevention policy

Prev Next

Assigning one or more instances of the policy to a group or system in the ePO - On-prem System Tree provides for single policy multi-purpose protection.

Exploit Prevention is a multiple-instance policy. This policy allows the application of more than one policy concurrently on a single client. When more than one instance is applied, what results is a union of all instances, called the effective policy.

A multiple-instance policy can be useful for an IIS Server, for example, where you might apply a general default policy, a server policy, and an IIS policy, the latter two configured to specifically target systems running as IIS servers. When assigning multiple instances, you are assigning a union of all elements in each instance of the policy.

To streamline your deployment, use multi-slot policy assignment. First, define groups of users for the deployment that have an essential property in common that dictates what resources need to be protected and what resources need exceptions to work properly. This property could be based on:

  • Department — Each department should require protection of a unique set of resources and exceptions for a unique set of business activities.

  • Location — Each location can have its own unique security standards or unique set of resources that need to be protected, and exceptions needed for business activity.

  • Computer type — Each type of computer (laptops, workstations, servers) might have a unique set of applications that need to be protected but also allowed to perform essential business functions.

Without a multiple-instance IPS Rules policy, a combination of three departments, three locations, and three computer types would require 27 policies; with the multiple-instance approach, only nine are needed.

Note

When the policies are merged, the most restrictive policy settings are combined to become the effective policy.

Task
  1. Click MenuSystemSystem Tree and select a group in the System Tree.

  2. Under Assigned Policies, select Endpoint Security Threat Prevention in the Product list.

  3. For Exploit Prevention, click Edit Assignment in the Action column.

  4. On the Policy Assignment page, click New Policy Instance, and select a policy from the Assigned Policies list for the additional policy instance.

  5. Click Save to save all changes.

To view the effective or combined effect of multiple instance rule sets, click View Effective Policy under Assigned Policies.