The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Enable the trigger threshold for Dynamic Application Containment on a client system

Prev Next

With Dynamic Application Containment, you can specify that applications with specific reputations run in a container, limiting the actions they can perform. If the application reputation is at or below the containment reputation threshold, the application is contained.

Before you begin

Make sure that the interface mode for the Trellix Endpoint Security (ENS) Client is set to Full access or log on to the Trellix Endpoint Security (ENS) Client as administrator.



Task
  1. Open the Trellix Endpoint Security (ENS) Client.

  2. Click Adaptive Threat Protection on the main Status page.

    Or, from the Action menu GUID-A3B12F55-7EE9-4519-8FCA-9ACA85C3661F-low.png, select Settings, then clickAdaptive Threat Protection on the Settings page.

  3. Click Show Advanced.

  4. Click Options.

  5. Verify that ATP is enabled.

  6. Select Trigger Dynamic Application Containment when reputation threshold reaches.

  7. Specify the reputation threshold at which to contain applications.

    • Might Be Trusted

    • Unknown (default for the Security rule group)

    • Might Be Malicious (default for the Balanced rule group)

    • Most Likely Malicious (default for the Productivity rule group)

    • Known Malicious

    The Dynamic Application Containment reputation threshold must be above the block and clean thresholds. For example, if the block threshold is set to Known Malicious, the Dynamic Application Containment threshold must be set to Most Likely Malicious or above.

  8. Click Apply.