The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Best practices: Reducing the impact of on-demand scans on users

Prev Next

To minimize the impact that on-demand scans have on a system, you can select options to avoid impacting system performance and scan only what you need to.

Best practice: For suggestions on how to improve Trellix ENS performance, see KB88205.

Scan only when the system is idle

The easiest way to make sure that the scan has no impact on users is to run the on-demand scan only when the computer is idle.

When this option is enabled, Threat Prevention pauses the scan when it detects disk or user activity, such as access using the keyboard or mouse. Threat Prevention resumes the scan when the user hasn't accessed the system for three minutes.

You can optionally:

  • Allow users to resume scans that have been paused due to user activity.

  • Return the scan to run only when the system is idle.

Disable this option only on server systems and systems that users access using Remote Desktop Connection (RDP). Threat Prevention depends on the Trellix notification area icon to determine if the system is idle. On systems accessed only by RDP, the notification area icon doesn't start and the on-demand scanner never runs. To work around this issue, add the UpdaterUI.exe to the logon script.

Select Scan only when the system is idle in the Performance section of the Custom On-Demand Scan client task settings.

Pause scans automatically

To improve performance, you can pause on-demand scans when the system is running on battery power. You can also pause the scan when an application, such as a browser, media player, or presentation, is running in full-screen mode. The scan resumes immediately when the system is connected to power or is no longer in full-screen mode.

  • Do not scan when the system is on battery power

  • Do not scan when the system is in presentation mode (available when Scan anytime is enabled)

Select these options in the Performance section of the Custom On-Demand Scan client task settings.

Allow users to defer scans

If you choose Scan anytime, you can allow users to defer scheduled scans in one-hour increments, up to 24 hours, or forever. Each user deferral can last one hour. For example, if the Maximum number of hours user can defer is set to 2, the user can defer the scan twice (two hours). When the maximum specified number of hours elapses, the scan continues.

Select User can defer scans in the Performance section of the Custom On-Demand Scan client task settings.

Limit scan activity with incremental scans

Use incremental, or resumable, scans to limit when on-demand scan activity occurs, and still scan the whole system in multiple sessions. To use incremental scanning, add a time limit to the scheduled scan. The scan stops when the time limit is reached. The next time this task starts, it continues from the point in the file and folder structure where the previous scan stopped.

Select Stop the task if it runs for on the Schedule page for the Custom On-Demand Scan client task.

See ePO - On-prem Help for schedule information and the Client Task Assignment Builder.

In ePO - On-prem, check the Systems Information Product properties for Threat Prevention for scan statistics, such start time, end time, and time to complete the scan.

Configure system utilization

System utilization specifies the amount of CPU time that the scanner receives during the scan. For systems with end-user activity, set system utilization to Low.

You can use the Windows Task Manager to view CPU utilization consumed by the Trellix Scanner service process (mcshield.exe).

The scan process for Full Scan and Quick Scan on-demand scans runs at low priority. But, if no other processes are running during a scan, the mcshield.exe process might consume a higher amount of CPU resources. If any other processes make system requests, mcshield.exe releases the CPU resources.

Select System utilization in the Performance section of the On-Demand Scan client task settings.

Specify the maximum CPU percentage for scans

As an alternative to using system utilization to automatically determine the amount of CPU the scan uses, you can specify a maximum percentage. In this case, the CPU usage for Full Scan, Quick Scan, and custom scans is limited to the percentage you specify. For example, if you specify 60%, the full scan consumes 60% of the available CPU.

Note

Right-click scan is not supported.

In certain scenarios, such as in systems with a single core CPU, it has been observed that the CPU utilization exceeds the defined limit. For example, if the threshold value is set to 40%, there are chances that the CPU usage might exceed the defined threshold. But the additional usage does not exceed 5% and the scanning process is not affected because of the sudden spike.

Because the scan is single-threaded, if the system has multiple CPUs, the scan uses the percentage of 1 CPU. So, if you want to limit the scan to 25% of the total CPU processing power of a 4-CPU system, set the percentage to 25%.

This option only applies to scanning files. It doesn't limit CPU usage when scanning other items, such as memory, registry, and boot sectors.

Note

This option is available only when the Scan anytime option is selected.

Custom scans

In the Custom On-Demand Scan client task settings:

  1. Select Scan anytime in the Scheduled Scan Options section.

  2. Select Limit maximum CPU usage in the Performance section.

Quick and full scans

In the On-Demand Scan policy on the appropriate tab (Full Scan or Quick Scan):

  1. Select Scan anytime in the Scheduled Scan Options section.

  2. Select Limit maximum CPU usage in the Performance section.

Scan only what you need to

Scanning some types of files can negatively affect system performance. For this reason, select these options only if you need to scan specific types of files.

Select or deselect these options in the What to Scan section of the Custom On-Demand Scan client task settings.

  • Files that have been migrated to storage

    Some offline data storage solutions replace files with a stub file. When the scanner encounters a stub file, which indicates that the file has been migrated, the scanner restores the file to the local system before scanning. The restore process can negatively impact system performance.

    Deselect this option unless you have a specific need to scan files in storage.

    Note

    This option doesn't apply to files stored in Microsoft OneDrive. The on-demand scanner doesn't download OneDrive files or scan files that haven't been downloaded.

  • Compressed archive files

    Even if an archive contains infected files, the files can't infect the system until the archive is extracted. Once the archive is extracted, the On-Access Scan examines the files and detects any malware.

    Best practice: Because scanning compressed archive files can negatively affect system performance, deselect this option to improve system performance.