The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Configure an On-Demand Scan policy (Quick Scan)

Prev Next

Configure an On-demand Quick Scan policy settings for your managed systems.

  1. Log on to the ePO - On-prem server as an administrator.

  2. From the Policy Catalog, select Endpoint Security Threat Prevention as the product, then select On-demand Scan as the category.

  3. Click New Policy, type a name for the policy, then click OK.

  4. Click the policy that you created, click the Quick Scan tab, then define these settings.

    In...

    Configure...

    What to scan

    • Compressed MIME-encoded files — Scans Apple mail messages.

    • Compressed archive files — Scans the contents of compressed archive files.

      Caution

      Scanning compressed archive files requires additional time.

    Additional Scan Locations

    • Detect unknown macro threats — Detects unknown macro threats.

    • Detect unknown program threats — Detects files that contain code resembling malware.

    • Detect unwanted programs — Detects unwanted programs.

    Scan Locations

    • Scan subfolders — Examines all subfolders in the specified volumes when any of these options are selected.

      • Home folder

      • Temp folder

      • File or folder

      • All mapped drives

    Select the directory from the Specify locations drop-down list. You can add directories by clicking Icon representing a plus sign, commonly used for adding or increasing values.. Click A minus sign indicating a decrease or subtraction in a mathematical context. to remove the directory from scanning.

    File Types to Scan

    • All files — Scans all files regardless of extension.

      Tip

      Best Practice: Enable All files to make sure that no malware threat resides in your managed system.

    • Default and specified file types — Scans files with extensions defined in the software and extensions you specify.

      For the list of the default and specified file types, see Trellix KnowledgeBase article KB79626.

      • Scan for macros — Enables scanning for macros in all files.

    • Specified file types only — Scans only files with extensions that you specify.

      • All files with no extension — Scans all files with no extensions.

    Trellix GTI

    • Enable Trellix GTI — Enables Trellix GTI, a heuristic network check for suspicious files.

    Exclusions

    In the Exclusions section, click

    • Add — To add files to the exclusion list.

    • Edit — To edit the exclusion settings.

    • Delete — To remove the selected item from the exclusion list.

    • Clear All — To remove all items from the exclusion list.

    For more information on configuring exclusions, see Exclude files or directories from scanning.

    Actions

    In Threat detection first response:

    • Continue scanning — Continues scanning files when a threat is detected. The scanner doesn't move items to the quarantine.

    • Clean files — Removes the threat from the detected file.

    • Delete files — Deletes the file that contains malware.

    You can also configure a secondary response using the If first response fails option, in case the primary response is unsuccessful.

    In Unwanted program first response:

    • Continue scanning — Continues scanning files when a threat is detected. The scanner doesn't move items to the quarantine.

    • Clean files — Removes the threat from the detected file.

    • Delete files — Deletes the file that contains malware.

    You can also configure a secondary response using the If first response fails option, in case the primary response is unsuccessful.

    Performance

    • Use the scan cache — Enables the scanner to use the existing clean scan results.

    Scheduled Scan Options

    • Scan only when the system is idle — Runs the scan only when the system is idle.

      Note

      The User can resume paused scans option is not supported for Mac.

    • Scan anytime — Runs the scan even if the user is active and specifies options for the scan.

      Note

      The User can defer scans, User can pause and cancel scans, and Do not scan when the system is in presentation mode options are not supported for Mac.

    • Do not scan when the system is on battery power — Postpones the scan when the system is using battery power.

  5. Click Save.

    For scheduling the task, see the product guide of your version of ePO - On-prem.

    Note

    Trellix ENS for Mac does not support the Right-Click Scan option.