By default, all hosts are subject to containment. You may want to restrict containment for certain hosts (for example, containing your network’s mail server could disrupt enterprise-wide communications). Hosts can only be excluded from containment when they are members of a host set.
Note
You can create a host set that contains only one host.
If containment actions are already in progress, excluding host sets from containment will affect the hosts contained in the sets as follows:
Hosts for which containment is requested: The host remains on the Requested tab of the Containment page. However, as long as the host’s agent software is on the host, the containment request cannot be approved.
Hosts that are contained or for which containment is approved: The host remains in a contained state until released. After the host is released from containment, it can no longer be contained.
Note
You can only exclude hosts from containment by using the Endpoint Security (HX) Web UI.
When a host set is excluded from containment, the hosts included in the host set become ineligible for containment and appear on Web UI pages with the ineligible icon () next to them.
Admin access