The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in mid-October 2026. We hope you enjoy the updated experience.

Configure Trellix-defined containment rules

Prev Next

Trellix-defined containment rules block or log actions that contained applications perform. You can change the block and report settings, but you can't otherwise change or delete these rules.

Task
  1. Select MenuPolicyPolicy Catalog, then select Endpoint Security Adaptive Threat Protection from the Products list in the left pane.

  2. From the Category list in the right pane, select Dynamic Application Containment.

  3. Click the Edit link for an editable policy.

  4. In the Containment Rules section, select Block, Report, or both for the rule.

    • To select or deselect all rules under Block or Report, click Block All or Report All.

    • To disable the rule, deselect both Block and Report.

  5. In the Exclusions section, configure executables to exclude from Dynamic Application Containment. Processes in the Exclusions list run normally (not contained).

  6. Click Save.