Configure CLI breach notifications

Prev Next

Administrators need to be aware of any attempt to recover the CLI with an incorrect password. In case any attempt is made to breach security, the CLI needs to be disabled immediately to thwart the attempt.

You can configure Application Control products to notify the administrator of any unsuccessful attempts to recover the CLI on the endpoint.

  1. On the ePO - SaaS console, select MenuPolicyPolicy Catalog.

  2. Select Solidcore 9.x.x: General for the product.

  3. In the Configuration (Client) category, click Duplicate for the Trellix Default policy.

  4. Specify the policy name, then click OK.

  5. Open the policy and click the CLI tab.

  6. Enable the feature by clicking Enable.

    By default, this feature is disabled.

  7. Specify the number of failed attempts and the interval after which to disable the CLI in case of a security breach.

    By default, the CLI is disabled if a user makes three unsuccessful attempts in 30 minutes.

  8. Specify how long to disable the CLI if any user makes unsuccessful logon attempts.

    By default the CLI is disabled for 30 minutes.

  9. Click Save.

  10. Apply the policy to the endpoints.