The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in mid-October 2026. We hope you enjoy the updated experience.

Disable On-Access Scan on a client system

Prev Next

On disabling the On-Access Scan, Trellix remains registered as your active antivirus in Windows Security Center.

You might need to disable the On-Access Scan (OAS) during troubleshooting to determine if Endpoint Security is conflicting with a specific local application or to perform system maintenance that requires high disk I/O.

Tip

We recommend that you only disable On-Access Scan temporarily. For maximum protection, always keep On-Access Scan enabled in your production environment.

Before you begin

Make sure that the interface mode for the Trellix Endpoint Security (ENS) Client is set to Full access or log on to the Trellix Endpoint Security (ENS) Client as administrator.



Task
  1. Open the Trellix Endpoint Security (ENS) Client.

  2. Click Threat Prevention on the main Status page.

    Or, from the Action menu GUID-A3B12F55-7EE9-4519-8FCA-9ACA85C3661F-low.png, select Settings, then click Threat Prevention on the Settings page.

  3. Click Show Advanced.

  4. Click On-Access Scan.

  5. Under On-Access Scan, select Disable.

  6. Click Apply.