The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Configure On-demand Scan policy (Full Scan)

Prev Next

Configure On-demand Full Scan policy settings for your managed system.

  1. Log on to ePO - On-prem as an administrator.

  2. From the Policy Catalog, select Endpoint Security Threat Prevention as the product, then select On-demand Scan as the category.

  3. Click New Policy, type a name for the policy, then click OK.

  4. Click the policy that you created, click the Full Scan tab, then define these settings.

    In...

    Configure...

    What to scan

    • Compressed archive files — Scans the contents of compressed archive files.

      Note

      Scanning compressed archive files requires additional time.

    • Compressed MIME-encoded files — Detects, decodes, and scans Multipurpose Internet Mail Extensions (MIME) encoded files.

    Additional scan options

    • Detect unwanted programs — Enables the scanner to detect potentially unwanted programs.

    • Detect unknown program threats — Detects files that contain code resembling malware.

    • Detect unknown macro threats — Detects unknown macro threats.

    Scan Locations

    • Scan subfolders — Examines all subfolders in the specified volumes when any of these options are selected.

      • Home folder

      • Temp folder

      • User profile folder

      • File or folder

      • All local drives

      • All fixed drives

      • All removable drives

      • All mapped drives

    You can add locations by clicking Icon representing a plus sign, commonly used for adding or increasing values.. Click A simple minus sign symbol used in various applications and interfaces. to remove the locations from scanning.

    File Types to Scan

    • All files — Scans all files regardless of extension.

      Note

      Trellix strongly recommends that you enable All files to make sure that no malware threat resides in your managed systems.

    • Default and specified file types — Scans files with extensions defined in the software and extensions you specify.

      For the list of the default file types, see Trellix KnowledgeBase article KB79626.

      • Scan for macros — Enables scanning for macros in all files.

    • Specified file types only — Scans only files with extensions that you specify.

      • All files with no extension — Scans all files with no extensions.

    Trellix GTI

    • Enable Trellix GTI — Enables Trellix GTI, a heuristic network look up for suspicious files.

    Select the Sensitivity level as required:

    • Very Low — The detections and risk of false positives are the same as with regular DAT content files. A detection is made available to Threat Prevention when Trellix Advanced Research Center publishes it instead of waiting for the next DAT content file update.

    • Low — This setting is the minimum recommendation for systems with a strong security footprint.

    • Medium — Use this level when the regular risk of exposure to malware is greater than the risk of a false positive. Trellix Advanced Research Center proprietary, heuristic checks result in detections that are likely to be malware. However, some detections might result in a false positive. With this setting, Trellix Advanced Research Center checks that popular applications and operating system files don't result in a false positive.

    • High — Use this setting for deployment to systems or areas which are regularly infected.

    • Very High — Detections found with this level are presumed malicious, but haven't been fully tested to determine if they are false positives. Trellix recommends to use this level for systems that require highest security.

    Exclusions

    In the Exclusions section, click:

    • Add — To add files to the exclusion list.

    • Edit — To edit the exclusion settings.

    • Delete — To remove the selected item from the exclusion list.

    • Clear All — To remove all items from the exclusion list.

    For more information about configuring exclusions, see Exclude files or directories from scanning.

    Actions

    In Threat detection first response:

    • Continue scanning — Continues scanning files when a threat is detected. The scanner doesn't move items to the quarantine.

    • Clean files — Removes the threat from the detected file.

    • Delete files — Delete the file that contains malware.

    You can also configure a secondary response using the If first response fails option, in case the primary response is unsuccessful.

    In Unwanted program first response:

    • Continue scanning — Continues scanning files when a threat is detected. The scanner doesn't move items to the quarantine.

    • Clean files — Removes the threat from the detected file.

    • Delete files — Delete the file that contains malware.

    You can also configure a secondary response using the If first response fails option, in case the primary response is unsuccessful.

    Performance

    Use the scan cache — Enables the scanner to use the existing clean scan results.

    Scheduled Scan Options

    • Scan only when the system is idle — Runs the scan only when the system is idle. The system is considered as idle when there is no keyboard or mouse activity for 5 minutes.

      Note

      The User can resume paused scans option is not supported for Mac systems.

    • Scan anytime — Runs the scan even if the user is active and specifies options for the scan.

      Note

      The User can defer scans, User can pause and cancel scans, and Do not scan when the system is in presentation mode options are not supported for Mac systems.

    • Do not scan when the system is on battery power — Postpones the scan when the system is using battery power.

  5. Click Save.

    For scheduling the task, see the product guide for your version of ePO - On-prem.

    Note

    Trellix ENS for Mac does not support the Right-Click Scan option.