The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Configure the Common policy

Prev Next

Configure the Common policy settings to define the log settings.

  1. Log on to the ePO - On-prem server as an administrator.

  2. From the Policy Catalog, select Endpoint Security Common as the product, then Options as the category.

  3. Click New Policy, type a name for the policy, then click OK.

  4. On the Policy Catalog page, click Show Advanced, then define these options:

    In this section...

    In this category...

    Configure...

    Client Interface Mode

    • Full access — Allows the managed system user to view or change all feature settings using the local system password credentials.

    • Standard access — Allows the managed Mac users to run software updates, and to run scheduled scans.

    • Lock client interface — Prompts the user for the password set by the ePO - On-prem administrator to start the client software console.

    Uninstallation

    Require a password to uninstall the client

    • Password — Type a password.

    • Confirm Password — Retype the password.

    Self Protection

    Enable Self Protection

    Files and Folders — Prevents modification or deletion of Endpoint Security for Mac software files and Folders.

    Processes — Blocks unauthorized attempts to stop or terminate Trellix Endpoint Security for Mac processes.

    • Block and Report — Prevents the user from changing or deleting the software files. An event is sent to the Trellix ePO server.

    • Block only — Prevents the user from changing or deleting the software files. No Trellix ePO events are generated for this activity.

    • Report only — Allows the managed Mac user to delete or change the software files. An event is sent to the Trellix ePO server.

    The default option is Block and Report.

    Note

    Policy changes take effect on managed systems only after successful agent communication or policy enforcement.

    Client logging

    Debug Logging

    Configure the logging preferences for Threat Prevention, Firewall, and Web Control:

    You can find the product logs in the device log and also at /var/log/McAfeeSecurity.log.

    Default Client Update

    Enable Default Update task schedule in the client — Enables or disables the update task on managed Mac.

  5. Click Save.

  6. In the System Tree, select the systems or groups.

  7. In the right pane, click the Group Details tab, then click Wake Up Agents.

  8. In Force policy update, select Force complete policy and task update, then click OK.