Exploit Guard Protection also supports Windows server operating systems 2008, 2012, and 2016. By default, Exploit Guard support for Windows servers is disabled, even if the Exploit Guard policy is enabled for other host endpoints. Exploit Guard automatically determines whether a host endpoint is a server and disables Exploit Guard for those endpoints.
In release 4.5 or later, you can enable and disable Exploit Guard processing for server operating systems using the TrellixEndpoint Security (HX) Web UI or API. See Enabling and Disabling Exploit Guard for more information. You cannot enable it with the CLI.