Define rules for specific endpoints

Prev Next

If you are a Trellix ePO - On-prem administrator, you can add prepopulated rules to allow or ban an application or executable file for specific endpoints in your administered groups. Or, you can define custom rules for specific endpoints or groups, as needed.

Task

  1. On the Trellix ePO - On-prem console, select MenuApplication ControlPolicy Discovery to open the Policy Discovery page.
  2. Select the request where you want to define custom rules.
  3. Click ActionsCreate Custom Policy to open the Policy Discovery: Custom Rules page.
  4. You can review rules or define custom rules:
    • Review or add rules — Select Approve Request, Ban Request, or Allow Trusted Path, then review or add more rules as needed.
    • Define custom rules — Select Clear and define Rules, then review the request details and define relevant rules as needed.
  5. Specify the rule group for the rules.
    • To add the rules to an existing rule group, select Choose existing and select the rule group from the list.

      Note

      When adding rules to allow a network path, select your rule group carefully. If you add rules to the Global Rules rule group, all future requests received from that network path are automatically approved. Or, if you add your rules to a custom rule group, future requests from that network path aren't automatically approved.

    • To create a rule group with the rules, select Create new and enter the rule group name.
  6. (Optional) Add the changed or created rule group to a policy.
    1. Select Add rule group to existing policy.
    2. Select the policy where you want to add the rule group.
  7. Click Save.
    This approves all grouped requests. For requests received from network paths, when you click Save, the Approve Requests for Subdirectories pop-up window appears that includes a checkbox to approve all related requests. If needed, select the checkbox, then click OK to approve all requests received from the network path and its subdirectories.