Enforcing product policies

Prev Next

Policy enforcement is enabled by default, and is inherited in the System Tree, but you can manually enable or disable enforcement on specified systems.

You can manage policy enforcement from these locations:

  • Assigned Policies tab of the System Tree — Choose whether to enforce policies for products or components on the selected group.

  • Policy Catalog page — View policy assignments and enforcement. You can also lock policy enforcement to prevent changes below the locked node.

Important consideration: If policy enforcement is turned off, systems in the specified group don't receive updated site lists during an agent-server communication. As a result, managed systems in the group might not function as expected.

For example, you might configure managed systems to communicate with Agent Handler A. If policy enforcement is turned off, the managed systems do not receive the new site list with this information and the systems report to a different Agent Handler listed in an expired site list.

When Policies are enforced

The timing of policy enforcement depends on the configuration of the policies. Enforcement can happen:

  • Instantly

    Example: On-Access Scan policy occurs when you start any application.

  • At agent-server communication or policy enforcement intervals

    Example: Product Deployment policy runs to confirm that the installed software versions on the managed systems match the versions on the Master Repository. If a new version is available, it is downloaded to all systems.

  • At configured Client Task intervals:

    Example: On-demand scan policy, by default, runs every day at midnight to scan all your managed systems for threats.

After policy settings are applied on the managed system, the Trellix Agent continues to enforce policy settings according to the policy enforcement interval (default is 60 minutes). You can adjust this interval on the General tab as well.

When you want an on-demand scan to run every day at midnight, you configure the settings so that:

  1. The Policy Based on-demand scan Client Task runs at 12 a.m.

  2. The client task starts the full on-demand scan on the managed systems.

  3. Using the configured settings in the policy, the scan runs and if any threats are found they are cleaned, quarantined, or deleted as required.