The Options page is where you configure Common settings, including passwords, Self Protection, exclusions, and activity and debug logging.
| Section | Option | Definition |
|---|---|---|
| Client Interface Mode | Full access | Allows access to all features. (Default) |
| Standard access | Displays protection status and allows access to most features, such as running updates and scans.
Standard access mode requires a password to view and change settings on the Endpoint Security Client Settings page. |
|
| Lock client interface | Requires a password to access the Endpoint Security Client. | |
| Set Administrator password | For
Standard access and
Lock client interface, specifies the Administrator password for accessing all features of the
Endpoint Security Client interface.
Best practice: Change Administrator passwords regularly. |
|
| Uninstallation | Require password to uninstall the client |
Requires a password to uninstall Endpoint Security Client and specifies the password. (Disabled by default)
|
| Section | Option | Definition |
|---|---|---|
| Client Interface Language | Automatic | Automatically selects the language to use for Endpoint Security Client interface text based on the language on the client system. |
| Language |
Specifies the language to use for Endpoint Security Client interface text. |
|
| Self Protection | Enable Self Protection | Protects Trellix ENS system resources from malicious activity. |
| Action |
Specifies the action to take when malicious activity occurs:
|
|
| Files and folders | Prevents changing or deleting McAfee system files and folders. | |
| Registry | Prevents changing or deleting McAfee registry keys and values. | |
| Processes | Prevents stopping McAfee processes. | |
| Exclude these processes |
Certificates access for the specified processes. Wildcards are supported. Add — Adds a process to the exclusion list. Click Add, then enter the exact resource name, such as avtask.exe. Double-click an item — Changes the selected item. Delete — Deletes the selected item. Select the resource, then click Delete. |
|
| Certificates |
Specifies certificate options. |
|
| Allow |
Allows a vendor to run code in McAfee processes.
|
|
| Vendor | Specifies the Common Name (CN) of the authority that signed and issued the certificate. | |
| Subject |
Specifies the Signer Distinguished Name (SDN) that defines the entity associated with the certificate. This information can include:
|
|
| Hash | Specifies the hash of the associated public key. | |
| Client Logging | Log files location |
Specifies the location for the log files. The default location is:
Enter or click Browse to navigate to a location. |
| Timestamp for log files | Local system time |
The log files (activity, debug, and event) are logged with local timestamps set in your system. |
| Coordinated Universal Time (UTC) |
The log files (activity, debug, and event) are logged with UTC timestamps. (Enabled by default) |
|
| Activity Logging | Enable activity logging | Enables logging of all Trellix ENS activity. |
| Log all scanned files during on-demand scans |
Enables logging of all files scanned during an on-demand scan. (Disabled by default) Best practice: If you enable this option, make sure the activity log file size is set to at least 100 MB. The on-demand scanner doesn't scan files in the clean scan cache, so the scanner doesn't log those files. |
|
| Limit size (MB) of each of the activity log files |
Limits each activity log file to the specified maximum size (between 1 MB and 999 MB). The default is 10 MB. If the log file exceeds this size, new data replaces the oldest 25 percent of the entries in the file. To allow log files to grow to any size, disable this option. |
|
| Activity logging language |
Specifies the language to use for activity logging text. Automatic — Automatically selects the language to use for activity logging text based on the language on the client system. |
|
| Debug Logging |
Enabling debug logging for any module also enables debug logging for the Common module features, such as Self Protection.
|
|
| Limit size (MB) of each of the debug log files |
Limits each debug log file to the specified maximum size (between 1 MB and 999 MB). The default is 50 MB. If the log file exceeds this size, new data replaces the oldest 25 percent of the entries in the file. To allow log files to grow to any size, disable this option. |
|
| Event Logging | Send events to Trellix ePO | Sends all events logged to the
Event Log on the
Endpoint Security Client to
Trellix ePO - On-prem.
This option is available on systems managed by Trellix ePO - On-prem only. |
| Log events to Windows Application log | Sends all events logged to the
Event Log on the
Endpoint Security Client to the Windows Application log.
The Windows Application log is accessible from the Windows Event Viewer → Windows Logs → Application. |
|
| Severity levels |
Specifies the severity level of events to log to the Event Log on the Endpoint Security Client:
|
|
| Limit the size (MB) of event DB |
Limits the size of event databases to the specified maximum size (between 50 MB and 999 MB). The default is 50 MB. |
|
| Proxy Server | No proxy server | Specifies that the managed systems retrieve Trellix GTI reputation information directly over the Internet, not through a proxy server. (Default) |
| Use system proxy settings |
Specifies the use of the proxy settings from the client system, and optionally enables HTTP proxy authentication. When you select Use system proxy settings, the client system uses the proxy settings configured in Internet Explorer, including support for PAC files. |
|
| Configure proxy server |
Customizes proxy settings.
|
|
| Enable HTTP proxy authentication |
Specifies that the HTTP proxy server requires authentication. (This option is available only when you select an HTTP proxy server.) Enter HTTP proxy credentials:
|
|
| Default Client Update | Enable the Update Now button in the client |
Displays or hides the Update Now button on the main page of the Endpoint Security Client. Click this button to manually check for and download updates to content files and software components on the client system. |
| What to update |
Specifies what to update when the Update Now button is clicked.
|
|
| Source Sites for Updates |
Configures sites from which to get updates to content files and software components. You can enable and disable the default backup source site, McAfeeHttp, and the management server, but you can't otherwise modify or delete them. |
|
|
Indicates elements that can be moved in the list. Select elements, then drag and drop to the new location. A blue line appears between elements where you can drop the dragged elements. |
|
| Add | Adds a site to the source sitelist. | |
| Double-click an item | Changes the selected item. | |
| Delete | Deletes the selected site from the source sitelist. | |
| Import |
Imports sites from a source sitelist file. Select the file to import, then click OK.
|
|
| Export All | Exports the source sitelist to the Sitelist.xml file.
Select the location to save the source sitelist file to, then click OK. |
|
| Proxy server for Source Sites | No proxy server | Specifies that the managed systems retrieve source site updates directly over the Internet, not through a proxy server. (Default) |
| Use system proxy settings | Specifies to use the proxy settings from the client system, and optionally enable HTTP or FTP proxy authentication.
When you select Use system proxy settings, the client system uses the proxy settings configured in Internet Explorer, including support for PAC files. |
|
| Configure proxy server |
Customizes proxy settings.
|
|
| Enable HTTP/FTP proxy authentication |
Specifies that the HTTP or FTP proxy server requires authentication. (This option is available only when you have selected an HTTP or FTP proxy server.) Enter proxy credentials:
|