Configure an On-demand Quick Scan policy settings for your managed systems.
Log on to the ePO - On-prem server as an administrator.
From the Policy Catalog, select Endpoint Security Threat Prevention as the product, then select On-demand Scan as the category.
Click New Policy, type a name for the policy, then click OK.
Click the policy that you created, click the Quick Scan tab, then define these settings.
In...
Configure...
What to scan
Compressed MIME-encoded files — Scans Apple mail messages.
Compressed archive files — Scans the contents of compressed archive files.
Caution
Scanning compressed archive files requires additional time.
Additional Scan Locations
Detect unknown macro threats — Detects unknown macro threats.
Detect unknown program threats — Detects files that contain code resembling malware.
Detect unwanted programs — Detects unwanted programs.
Scan Locations
Scan subfolders — Examines all subfolders in the specified volumes when any of these options are selected.
Home folder
Temp folder
File or folder
All mapped drives
Select the directory from the Specify locations drop-down list. You can add directories by clicking
. Click
to remove the directory from scanning.File Types to Scan
All files — Scans all files regardless of extension.
Tip
Best Practice: Enable All files to make sure that no malware threat resides in your managed system.
Default and specified file types — Scans files with extensions defined in the software and extensions you specify.
For the list of the default and specified file types, see Trellix KnowledgeBase article KB79626.
Scan for macros — Enables scanning for macros in all files.
Specified file types only — Scans only files with extensions that you specify.
All files with no extension — Scans all files with no extensions.
Trellix GTI
Enable Trellix GTI — Enables Trellix GTI, a heuristic network check for suspicious files.
Exclusions
In the Exclusions section, click
Add — To add files to the exclusion list.
Edit — To edit the exclusion settings.
Delete — To remove the selected item from the exclusion list.
Clear All — To remove all items from the exclusion list.
For more information on configuring exclusions, see Exclude files or directories from scanning.
Actions
In Threat detection first response:
Continue scanning — Continues scanning files when a threat is detected. The scanner doesn't move items to the quarantine.
Clean files — Removes the threat from the detected file.
Delete files — Deletes the file that contains malware.
You can also configure a secondary response using the If first response fails option, in case the primary response is unsuccessful.
In Unwanted program first response:
Continue scanning — Continues scanning files when a threat is detected. The scanner doesn't move items to the quarantine.
Clean files — Removes the threat from the detected file.
Delete files — Deletes the file that contains malware.
You can also configure a secondary response using the If first response fails option, in case the primary response is unsuccessful.
Performance
Use the scan cache — Enables the scanner to use the existing clean scan results.
Scheduled Scan Options
Scan only when the system is idle — Runs the scan only when the system is idle.
Note
The User can resume paused scans option is not supported for Mac.
Scan anytime — Runs the scan even if the user is active and specifies options for the scan.
Note
The User can defer scans, User can pause and cancel scans, and Do not scan when the system is in presentation mode options are not supported for Mac.
Do not scan when the system is on battery power — Postpones the scan when the system is using battery power.
Click Save.
For scheduling the task, see the product guide of your version of ePO - On-prem.
Note
Trellix ENS for Mac does not support the Right-Click Scan option.