The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in mid-October 2026. We hope you enjoy the updated experience.

How policies work

Prev Next

Web Control includes preconfigured default policies. You can't change the default policies, but you can create copies and modify them to meet your browsing protection needs.

You then assign the policy to managed systems running the client software. You can assign the same policy settings to all managed systems, or to groups of managed systems that require the same type of access and protection.

Multiple-instance policies

Multiple-instance policies, such as Block and Allow List and Content Actions, support combining multiple policies under a single effective policy.

Multiple-instance policies obey the Trellix ePO - On-prem laws of inheritance within a System Tree. See the Trellix ePO - On-prem Help.

You can use multiple-instance policies to apply a default list of sites, and add entries for a particular group or all groups. Instead of updating the entire list with the new entries, create a second policy instance for the new entries. Then, apply it and the default list together. The effective policy is then the combination of the two policies.

For example, you configure one Block and Allow List policy for Group A, another for Group B, and another for Group C. If Group A contains Group B, and Group B contains Group C, the Block and Allow List policy incorporates elements from the three policies. The allowed list for Group C might contain all sites listed for Group A and Group B, and extra sites specific to Group C. By using an effective policy, you don't have to re-enter all sites from Group A and Group B into the allowed list for Group C.

For more information about using policies, see the Trellix ePO - On-prem Help.