The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Configure Policies

Prev Next

Defining a network as trusted causes Firewall to create an internal bi-directional Allow rule with remote network criteria set to the trusted network. Any traffic to and from the trusted networks is allowed.

Policies are collections of settings that you create, configure, and apply, then enforce. Most policy settings correspond to settings that you configure in the Trellix Endpoint Security (ENS) Client. Other policy settings are the primary interface for configuring the software.

Your managed product adds these categories to the Policy Catalog. The available settings vary in each category.

Host Intrusion Prevention categories

Defining a network as trusted causes Firewall to create an internal bi-directional Allow rule with remote network criteria set to the trusted network. Any traffic to and from the trusted networks is allowed.

Defining a network as trusted causes Firewall to create an internal bi-directional Allow rule with remote network criteria set to the trusted network. Any traffic to and from the trusted networks is allowed.

Options

Specifies options for the Host Intrusion Prevention, including:

  • Turns on or off firewall protection.

  • Applies Adaptive mode for tuning.

  • Defines networks and trusted executables to use in rules and groups.

Rules

Specifies firewall rules, and groups of rules, that define what traffic is allowed and what is blocked.



Defining a network as trusted causes Firewall to create an internal bi-directional Allow rule with remote network criteria set to the trusted network. Any traffic to and from the trusted networks is allowed.

Each policy category includes default policies.

You can use default policies as is, edit the My Default policies, or create new policies.

Host Intrusion Prevention default policies

Defining a network as trusted causes Firewall to create an internal bi-directional Allow rule with remote network criteria set to the trusted network. Any traffic to and from the trusted networks is allowed.

Defining a network as trusted causes Firewall to create an internal bi-directional Allow rule with remote network criteria set to the trusted network. Any traffic to and from the trusted networks is allowed.

Trellix Default

Defines the default policy that takes effect if no other policy is applied. You can duplicate, but not delete or change, this policy.

Trellix Default Server

Defines the default server Rules policy, which allows all server default services, such as Windows AD Authentication, Web/FTP, and mail servers, to accept client service requests. You can duplicate, but not delete or change, this policy.

My Default

Defines default settings for the category.



User-based policies

User-based polices (UBP) enable policies to be defined and enforced using ePO - On-prem policy assignment rules with an LDAP server. These assignment rules are enforced on the client system for the user at log-on, regardless of the ePO - On-prem group.

User-based polices are enforced when a user with a matching assignment rule logs on to the client system on the console. System-based polices (SBP) are enforced when two or more users are logged on to a system. Policy assignment rules take precedence over polices defined in the System Tree.

The user policy supersedes the system policy. All system policies apply and any user-based policy overrides the system policy.

Policy assignment rules are enforced only if the user logs on as the interactive user. The system policy, rather than the user policy, is enforced if the user logs on:

  • With a runas command

  • To a remote desktop or terminal service where the user's logon is not set to interactive

For more information about user-based policies and policy assignment rules, see the ePO - On-prem Help.

Comparing policies

You can compare all policy settings for the module using the Policy Comparison feature in ePO - On-prem. For information, see the ePO - On-prem Help.

For information about policies and the Policy Catalog, see the ePO - On-prem documentation.