ATP scanning uses exclusions defined in the Threat Prevention On-Access Scan settings for Standard process types.
If the TIE server is available, you can change the reputation of the file to a level that allows it to run, like Known Trusted, instead of creating exclusions.
Best practice: For suggestions on how to improve Endpoint Security performance, see KB88205.
On-access scan Standard process exclusions specified by file name or file path apply to all ATP scanners, including Dynamic Application Containment and ML Protect. On-access scan exclusions specified by file type or age don't apply to ATP. ATP supports the same wildcards in path-based exclusions as Threat Prevention does.
Endpoint Security treats all file and folder exclusions as case insensitive — all case variations of the specified locations are excluded. For example, if you exclude C:\Temp\ABC, Endpoint Security also excludes C:\temp\abc and C:\TEMP\Abc.
Best practice: For information about troubleshooting blocked third-party applications, see KB88482.
For a list of executables that ATP scanned, check the Adaptive Threat Protection debug log (AdaptiveThreatProtection_Debug.log) on the client system.
Select Menu → Policy → Policy Catalog, then select Endpoint Security Threat Prevention from the Products list in the left pane..
From the Category list in the right pane, select On-Access Scan.
Click the Edit link for an editable policy.
Click Show Advanced.
In the Process Types section, select the Standard tab.
Note
Exclusions specified in the High Risk and Low Risk tabs don't apply to ATP.
In the Exclusions section, click Add to enter the process to exclude from ATP scanning.
In the When to exclude section, select On read.
Tip
If you want to exclude items from ATP scanning only, select this option. Threat Prevention still scans those items when they are being written to or changed on the disk.