With Dynamic Application Containment, you can specify that applications with specific reputations run in a container, limiting the actions they can perform. If the application reputation is at or below the containment reputation threshold, the application is contained.
Select Menu → Policy → Policy Catalog, then select Endpoint Security Adaptive Threat Protection from the Products list in the left pane.
From the Category list in the right pane, select Options.
Click the Edit link for an editable policy.
Verify that ATP is enabled.
Select Trigger Dynamic Application Containment when reputation threshold reaches.
Specify the reputation threshold at which to contain applications.
Might Be Trusted
Unknown (default for the Security rule group)
Might Be Malicious (default for the Balanced rule group)
Most Likely Malicious (default for the Productivity rule group)
Known Malicious
The Dynamic Application Containment reputation threshold must be above the block and clean thresholds. For example, if the block threshold is set to Known Malicious, the Dynamic Application Containment threshold must be set to Most Likely Malicious or above.
Click Save.