When you first enable Dynamic Application Containment in your environment, set the rules to Report only and evaluate the effects before enforcing them. Users experience no blocking or prompting.
For details about product features, usage, and best practices, click ? or Help.
In the Common Options settings, Event Logging section, select Warning, Critical, and Alert from the Adaptive Threat Protection events to log drop-down list.
This step is required to send Dynamic Application Containment Would Block events to ePO - On-prem.
Enforce the Trellix Default Dynamic Application Containment policy.
This policy sets rules to Report only and generates "Dynamic Application Containment violation allowed" (event ID 37280) events.
Monitor the logs and reports and determine whether to set rules to block.
After collecting "Dynamic Application Containment violation allowed" (event ID 37280) events, set Enterprise Level Reputations or Dynamic Application Containment exclusions.
Enforce the Trellix Default Balanced Dynamic Application Containment policy.