If Application Control prevent an action on an endpoint, you can choose to display a customized notification message for the event on the endpoint.
You can configure the notification to be displayed on the endpoints for these events.
Execution Denied
File Write Denied
File Read Denied
Process Hijack Attempted
Nx Violation Detected
Installation Denied
VASR Violation Detected
Blocked Interactive Mode of Process
Prevented File Execution
On the ePO - SaaS console, select Menu → Policy → Policy Catalog.
Select the Solidcore 9.x.x: Application Control product.
Select the Application Control Options category and click the My Default policy to edit it.
Click the End User Notifications tab and select Show the messages dialog box when an event is detected and display the specified text in the message to display a message box at the endpoint each time any of the earlier mentioned events is generated.
Enter the Help Desk information.
Mail To
Represents the email address to which all approval requests are sent.
Mail Subject
Represents the subject of the email message sent for approval requests.
Link to Website
Indicates the website listed in the Application Control Events window on the endpoints.
Trellix ePO IP Address and Port
Specifies the ePO - SaaS server address and port.
Customize the notifications for the several types of events.
Enter the notification message.
You can use the listed variables to create the message string.
Select Show Event in Dialog to make sure that all events of the selected event type (such as Execution Denied) are listed in the Application and Change Control Events window on the endpoints.
Save the policy and apply to the relevant endpoints.
From the endpoints, users can review the notifications for the events and request for approval for certain actions.
Right-click the Trellix Agent icon in the notification area on the endpoint.
Select Quick Settings → Application and Change Control Events.
The Application and Change Control Events window appears.
Review the events.
Request approval for a certain action by selecting the event and clicking Request Approval.