The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Containing applications dynamically

Prev Next

Dynamic Application Containment enables you to specify that applications with specific reputations run in a container. Contained applications aren't allowed to perform certain actions, as specified by containment rules.

Based on the reputation threshold, ATP requests that Dynamic Application Containment run the application in a container.

This technology lets you evaluate unknown and potentially unsafe applications by allowing them to run in your environment, while limiting the actions they can take. Users can use the applications, but they might not work as expected if Dynamic Application Containment blocks certain actions. Once you determine that an application is safe, you can configure ATP or TIE server to allow it to run normally.

To use Dynamic Application Containment:

  1. Enable ATP and specify the reputation threshold for triggering Dynamic Application Containment in the Options settings.

  2. Configure Trellix-defined containment rules and exclusions in the Dynamic Application Containment settings.