You can use the General policy tab to configure Trellix EDR on monitored devices.
Option | Definition | ||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Enable read-only for Trellix EDR data folders | This option is enabled by default. Data folder isn't readable. Only log files are readable when they are enabled. If they are enabled, files in | ||||||||||||||||||||||||||||
Enable content updates | This option is enabled by default. When the Enable content updates option is selected, the dynamic content update feature allows Trellix to immediately respond to newly found vulnerabilities by pushing content updates automatically to endpoints.
On endpoints with the Trellix EDR client 4.0.x or later, when the Enable content updates option is selected, the client checks for new content updates at the configured interval and gets updated with the latest content on endpoints automatically without performing an explicit deployment task from ePO - On-prem or ePO - SaaS.
On endpoints with the Trellix EDR client 3.5.x or earlier, make sure the Enable content updates option is selected and then check-in (Software Catalog) and deploy (Product Update) the latest content package from ePO - On-prem or ePO - SaaS. | ||||||||||||||||||||||||||||
Content update method | On endpoints with the Trellix EDR client 4.1.x or later, you have an option to select either Dynamic content update or ePO push content update to update content on Windows endpoints. Other operating systems do not support the dynamic content update. By default, the dynamic content update is selected and effective only for Windows endpoints. Other operating systems will default to the ePO - On-prem or ePO - SaaS push content update method. The below table gives details about the supported content update methods according to the version and operating system.
| ||||||||||||||||||||||||||||
Check for content updates at an interval | Updates the client content on endpoints at the configured time (in minutes) when content updates are enabled. On endpoints with the Trellix EDR client 4.0.x or later, the default interval set is 240 minutes. The minimum and maximum interval you can set is between 60 and 1440 minutes. On endpoints with the Trellix EDR client 3.5.x or earlier, the default interval set is 240 minutes. The minimum and maximum interval you can set is between 5 and 1440 minutes. However, the minimum interval varies based on the Trellix EDR client extension version installed. If the version is 4.0.x or later, the minimum interval you can set is 60 minutes.
| ||||||||||||||||||||||||||||
The maximum number of results returned by the Trellix EDR Real-time Search | Sets the maximum number of results returned by Trellix EDR search expressions. The default value set is 512. The minimum and maximum results you can set is between 32 and 8192. | ||||||||||||||||||||||||||||
Enable password to uninstall the Trellix EDR client (Windows only) | This option is disabled by default. Prevents the user from uninstalling Trellix EDR client without an uninstallation password
|
Tamper protection
The tamper protection feature allows the Administrator to configure a policy to prevent a user from uninstalling Trellix EDR client without an uninstallation password.
Important
This feature is supported only on Microsoft Windows.