End quarantine devices using a tool

Prev Next

During an investigation, when a threat in a quarantined endpoint is eradicated or dismissed as non-malicious, you can reconnect the endpoint to the network by ending the quarantine state using a tool.

Important

Make sure Enable Plug-in is selected on the Network Flow policy page for quarantine and end quarantine to work on the endpoint.

This End quarantine device using a tool feature is supported only on Windows endpoints.

  1. On ePO - On-prem or ePO - SaaS, select MenuPolicyPolicy Catalog.

  2. From the Product list, select Trellix EDR.

  3. On existing or new policy, select Network Flow.

  4. On the Network Flow tab under Quarantine Settings, select Enable password to unquarantine the Trellix EDR client at endpoint (Windows only).

  5. Set a password that can be used to end the quarantine of an endpoint and click Save.

    After you create a new policy or updated the existing policy, assign it to managed endpoints to configure the Trellix EDR clients on those endpoints.

    For details about assigning a policy to managed endpoints, see ePO - On-prem or ePO - SaaS Product Guide.

  6. On the quarantined endpoint, navigate to Program FilesMcAfeeMAR.

  7. Run the quarantineUti application.

  8. Get the password set by administrator and enter.

A successful message is displayed on the screen that an endpoint is removed from the quarantine state. However, this message can be customized.