The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Configure Trellix-defined containment rules on a client system

Prev Next

Trellix-defined containment rules block or log actions that contained applications perform. You can change the block and report settings, but you can't otherwise change or delete these rules.

Before you begin

Make sure that the interface mode for the Trellix Endpoint Security (ENS) Client is set to Full access or log on to the Trellix Endpoint Security (ENS) Client as administrator.



Task
  1. Open the Trellix Endpoint Security (ENS) Client.

  2. Click Adaptive Threat Protection on the main Status page.

    Or, from the Action menu GUID-A3B12F55-7EE9-4519-8FCA-9ACA85C3661F-low.png, select Settings, then click Adaptive Threat Protection on the Settings page.

  3. Click Show Advanced.

  4. Click Dynamic Application Containment.

  5. In the Containment Rules section, select Block, Report, or both for the rule.

    • To block or report all, select Block or Report in the first row.

    • To disable the rule, deselect both Block and Report.

  6. In the Exclusions section, configure executables to exclude from Dynamic Application Containment. Processes in the Exclusions list run normally (not contained).

  7. Click Apply.