Customize end-user notifications in a managed environment

Prev Next

If Change Control or Application Control prevent an action on an endpoint, you can choose to display a customized notification message for the event on the endpoint.

You can configure the notification to be displayed on the endpoints for these events.

  • Execution Denied

  • File Write Denied

  • File Read Denied

  • Process Hijack Attempted

  • Nx Violation Detected

  • ActiveX Installation Prevented

  • Installation Denied

  • VASR Violation Detected

  • Blocked Interactive Mode of Process

  • Prevented File Execution

  1. On the ePO - On-prem console, select MenuPolicyPolicy Catalog.

  2. Select the Solidcore 8.x.x: Application Control product.

  3. Select the Application Control Options category and click the My Default policy to edit it.

  4. Click the End User Notifications tab and select Show the messages dialog box when an event is detected and display the specified text in the message to display a message box at the endpoint each time any of the earlier mentioned events is generated.

  5. Enter the Help Desk information.

    Mail To

    Represents the email address to which all approval requests are sent.

    Mail Subject

    Represents the subject of the email message sent for approval requests.

    Link to Website

    Indicates the website listed in the Application Control and Change Control Events window on the endpoints.

    Trellix ePO IP Address and Port

    Specifies the ePO - On-prem server address and port.

  6. Customize the notifications for the several types of events.

    1. Enter the notification message.

      You can use the listed variables to create the message string.

    2. Select Show Event in Dialog to make sure that all events of the selected event type (such as Execution Denied) are listed in the Application and Change Control Events window on the endpoints.

  7. Save the policy and apply to the relevant endpoints.

  8. From the endpoints, users can review the notifications for the events and request for approval for certain actions.

    1. Right-click the Trellix Agent icon in the notification area on the endpoint.

    2. Select Quick SettingsApplication and Change Control Events.

      The Application and Change Control Events window appears.

    3. Review the events.

    4. Request approval for a certain action by selecting the event and clicking Request Approval.