The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in mid-October 2026. We hope you enjoy the updated experience.

Configure Adaptive Threat Protection with no connection to Trellix GTI on a client system

Prev Next

For systems with no network connection to Adaptive Threat Protection, such as air-gapped systems, you can improve performance by manually disabling Adaptive Threat Protection.

Before you begin

Make sure that the interface mode for the Trellix Endpoint Security (ENS) Client is set to Full access or log on to the Trellix Endpoint Security (ENS) Client as administrator.



Note

Policy changes from ePO - On-prem overwrite changes from the Settings page.

Disable Adaptive Threat Protection to eliminate unnecessary attempts to connect to Adaptive Threat Protection when no network path exists and reduce the impact on Trellix ENS performance.

Caution

Disabling Adaptive Threat Protection might result in increased false positives.

Task
  1. Open the Trellix Endpoint Security (ENS) Client.

  2. Click Threat Prevention on the main Status page.

    Or, from the Action menu GUID-A3B12F55-7EE9-4519-8FCA-9ACA85C3661F-low.png, select Settings, then click Threat Prevention on the Settings page.

  3. In the On-Access Scan, Trellix GTI section, deselect Enable Trellix GTI.

  4. Click Adaptive Threat Protection.

  5. Click Show Advanced.

  6. In the Reputation Source section, click the drop-down list and select Use only the TIE server.

  7. Click Apply.