The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Common — Options

Prev Next

The Options page is where you configure Common settings, including passwords, Self Protection, exclusions, and activity and debug logging.

Options
Section Option Definition
Client Interface Mode Full access Allows access to all features. (Default)
Standard access Displays protection status and allows access to most features, such as running updates and scans.

Standard access mode requires a password to view and change settings on the Endpoint Security Client Settings page.

Lock client interface Requires a password to access the Endpoint Security Client.
Set Administrator password For Standard access and Lock client interface, specifies the Administrator password for accessing all features of the Endpoint Security Client interface.
  • Password — Specifies the password.
  • Confirm password — Confirms the password.

Best practice: Change Administrator passwords regularly.

Uninstallation Require password to uninstall the client

Requires a password to uninstall Endpoint Security Client and specifies the password.

(Disabled by default)

  • Password — Specifies the password.
  • Confirm password — Confirms the password.
Advanced options
Section Option Definition
Client Interface Language Automatic Automatically selects the language to use for Endpoint Security Client interface text based on the language on the client system.
Language

Specifies the language to use for Endpoint Security Client interface text.

Self Protection Enable Self Protection Protects Trellix ENS system resources from malicious activity.
Action

Specifies the action to take when malicious activity occurs:

  • Block and report — Blocks activity and reports to Trellix ePO - On-prem. (Default)
  • Block only — Blocks activity but doesn't report to Trellix ePO - On-prem.
  • Report only — Reports to Trellix ePO - On-prem but doesn't block activity.
Files and folders Prevents changing or deleting McAfee system files and folders.
Registry Prevents changing or deleting McAfee registry keys and values.
Processes Prevents stopping McAfee processes.
Exclude these processes

Certificates access for the specified processes.

Wildcards are supported.

Add — Adds a process to the exclusion list. Click Add, then enter the exact resource name, such as avtask.exe.

Double-click an itemChanges the selected item.

DeleteDeletes the selected item. Select the resource, then click Delete.

Certificates

Specifies certificate options.

Allow

Allows a vendor to run code in McAfee processes.

Caution

This setting might result in compatibility issues and reduced security.

Vendor Specifies the Common Name (CN) of the authority that signed and issued the certificate.
Subject

Specifies the Signer Distinguished Name (SDN) that defines the entity associated with the certificate.

This information can include:

  • CN — Common Name
  • OU — Organization Unit
  • O — Organization
  • L — Locality
  • ST — State or province
  • C — Country Code
Hash Specifies the hash of the associated public key.
Client Logging Log files location

Specifies the location for the log files.

The default location is:

<SYSTEM_DRIVE>:\ProgramData\McAfee\Endpoint\Logs

Enter or click Browse to navigate to a location.

Timestamp for log files Local system time

The log files (activity, debug, and event) are logged with local timestamps set in your system.

Coordinated Universal Time (UTC)

The log files (activity, debug, and event) are logged with UTC timestamps.

(Enabled by default)

Activity Logging Enable activity logging Enables logging of all Trellix ENS activity.
Log all scanned files during on-demand scans

Enables logging of all files scanned during an on-demand scan. (Disabled by default)

Best practice: If you enable this option, make sure the activity log file size is set to at least 100 MB.

The on-demand scanner doesn't scan files in the clean scan cache, so the scanner doesn't log those files.

Limit size (MB) of each of the activity log files

Limits each activity log file to the specified maximum size (between 1 MB and 999 MB). The default is 10 MB.

If the log file exceeds this size, new data replaces the oldest 25 percent of the entries in the file.

To allow log files to grow to any size, disable this option.
Activity logging language

Specifies the language to use for activity logging text.

Automatic — Automatically selects the language to use for activity logging text based on the language on the client system.

Debug Logging

Enabling debug logging for any module also enables debug logging for the Common module features, such as Self Protection.

Note

Enable for Storage Protection option is applicable only when Endpoint Security Storage Protection is installed.

Limit size (MB) of each of the debug log files

Limits each debug log file to the specified maximum size (between 1 MB and 999 MB). The default is 50 MB.

If the log file exceeds this size, new data replaces the oldest 25 percent of the entries in the file.

To allow log files to grow to any size, disable this option.
Event Logging Send events to Trellix ePO Sends all events logged to the Event Log on the Endpoint Security Client to Trellix ePO - On-prem.

This option is available on systems managed by Trellix ePO - On-prem only.

Log events to Windows Application log Sends all events logged to the Event Log on the Endpoint Security Client to the Windows Application log.

The Windows Application log is accessible from the Windows Event ViewerWindows LogsApplication.

Severity levels

Specifies the severity level of events to log to the Event Log on the Endpoint Security Client:

  • None — Sends no alerts
  • Alert only — Sends alert level 1 only.
  • Critical and Alert — Sends alert levels 1 and 2.
  • Warning, Critical, and Alert — Sends alert levels 1–3.
  • All except Informational — Sends alert levels 1–4.
  • All — Sends alert levels 1–5.
  • 1 — Alert
  • 2 — Critical
  • 3 — Warning
  • 4 — Notice
  • 5 — Informational
Limit the size (MB) of event DB

Limits the size of event databases to the specified maximum size (between 50 MB and 999 MB). The default is 50 MB.

Proxy Server No proxy server Specifies that the managed systems retrieve Trellix GTI reputation information directly over the Internet, not through a proxy server. (Default)
Use system proxy settings

Specifies the use of the proxy settings from the client system, and optionally enables HTTP proxy authentication.

When you select Use system proxy settings, the client system uses the proxy settings configured in Internet Explorer, including support for PAC files.

Configure proxy server

Customizes proxy settings.

  • Address — Specifies the IP address or fully qualified domain name of the HTTP proxy server.
  • Port — Limits access through the specified port.
  • Exclude these addresses — Don't use the HTTP proxy server for websites or IP addresses that begin with the specified entries.

    Click Add, then enter the address name to exclude.

    Best practice: Exclude the Trellix GTI addresses from the proxy server. For information, see KB79640.

Enable HTTP proxy authentication

Specifies that the HTTP proxy server requires authentication. (This option is available only when you select an HTTP proxy server.) Enter HTTP proxy credentials:

  • User name — Specifies the user account with permissions to access the HTTP proxy server.
  • Password — Specifies the password for User name.
  • Confirm password — Confirms the specified password.
Default Client Update Enable the Update Now button in the client

Displays or hides the Update Now button on the main page of the Endpoint Security Client.

Click this button to manually check for and download updates to content files and software components on the client system.

What to update

Specifies what to update when the Update Now button is clicked.

  • Security content, hotfixes, and patches — Updates all security content (including engine and AMCore and Exploit Prevention content), as well as any hotfixes and patches, to the latest versions.
  • Security content — Updates security content only. (Default)
  • Hotfixes and patches — Updates hotfixes and patches only.
Source Sites for Updates

Configures sites from which to get updates to content files and software components.

You can enable and disable the default backup source site, McAfeeHttp, and the management server, but you can't otherwise modify or delete them.

Indicates elements that can be moved in the list.

Select elements, then drag and drop to the new location. A blue line appears between elements where you can drop the dragged elements.

Add Adds a site to the source sitelist.
Double-click an item Changes the selected item.
Delete Deletes the selected site from the source sitelist.
Import

Imports sites from a source sitelist file.

Select the file to import, then click OK.

Note

The sitelist file replaces the existing source sitelist.

Export All Exports the source sitelist to the Sitelist.xml file.

Select the location to save the source sitelist file to, then click OK.

Proxy server for Source Sites No proxy server Specifies that the managed systems retrieve source site updates directly over the Internet, not through a proxy server. (Default)
Use system proxy settings Specifies to use the proxy settings from the client system, and optionally enable HTTP or FTP proxy authentication.

When you select Use system proxy settings, the client system uses the proxy settings configured in Internet Explorer, including support for PAC files.

Configure proxy server

Customizes proxy settings.

  • HTTP/FTP address — Specifies the DNS, IPv4, or IPv6 address of the HTTP or FTP proxy server.
  • Port — Limits access through the specified port.
  • Exclude these addresses — Specifies the addresses for Endpoint Security Client systems that you don't want to use the proxy server for obtaining Trellix GTI ratings.

    Click Add, then enter the address name to exclude.

Enable HTTP/FTP proxy authentication

Specifies that the HTTP or FTP proxy server requires authentication. (This option is available only when you have selected an HTTP or FTP proxy server.) Enter proxy credentials:

  • User name — Specifies the user account with permissions to access the proxy server.
  • Password — Specifies the password for the specified User name.
  • Confirm password — Confirms the specified password.