If you upgrade from a previous version, the Script as Updater (SAU) feature is enabled by default. If after the upgrade you want to disable SAU, you must introduce the change with a policy.
Go to Menu → Policy → Policy Catalog.
Select the Solidcore 8.2.0: Application Control product.
Select Application Control Options (Windows) category.
Choose Trellix Default or My Default policy and click Duplicate.
Once the policy is duplicated, click the name of the policy and go to the Features tab.
Select Enforce feature control from Trellix ePO - On-prem.
Select or deselect the features you want to disable.
Click Save.
To implement the policy, go to System Tree and select the endpoint.
Go to Actions → Agent → Set Policy & Inheritance.
Select the Product, Category, and Policy.
Click Save.
Select the endpoint and click Wake up Agent.
Complete the information on the Wake Up Trellix Agent page.
Select Force complete policy and task update.
Click OK.
Reboot the endpoints to implement the policy.