The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Enable the trigger threshold for Dynamic Application Containment

Prev Next

With Dynamic Application Containment, you can specify that applications with specific reputations run in a container, limiting the actions they can perform. If the application reputation is at or below the containment reputation threshold, the application is contained.

Task
  1. Select MenuPolicyPolicy Catalog, then select Endpoint Security Adaptive Threat Protection from the Products list in the left pane.

  2. From the Category list in the right pane, select Options.

  3. Click the Edit link for an editable policy.

  4. Verify that ATP is enabled.

  5. Select Trigger Dynamic Application Containment when reputation threshold reaches.

  6. Specify the reputation threshold at which to contain applications.

    • Might Be Trusted

    • Unknown (default for the Security rule group)

    • Might Be Malicious (default for the Balanced rule group)

    • Most Likely Malicious (default for the Productivity rule group)

    • Known Malicious

    The Dynamic Application Containment reputation threshold must be above the block and clean thresholds. For example, if the block threshold is set to Known Malicious, the Dynamic Application Containment threshold must be set to Most Likely Malicious or above.

  7. Click Save.