You can enable reputation source and sandboxing using TI ENS policy.
Make sure DXL local broker is deployed and configured correctly.
In ePO - SaaS, select → → .
From the Products pane, select Endpoint Security Adaptive Threat Protection and a policy to edit.
Click Show Advanced.
Select Reputation Source from the drop-down list.
From the Sandboxing pane, select Send files not yet verified to Trellix Intelligent Sandbox for analysis checkbox to send files for analysis.
Submit files when reputation threshold reaches Unknown and limit size 5 MB by default.
You can select other reputations, but files with Unknown reputation are default and recommended to send for sandboxing.
Click Save.
Reputation source and sandboxing are enabled successfully.