The malware protection feature allows you to quarantine infected files to prevent the spread of malware on your host endpoints.
When you enable malware detection (Signature and Heuristic Detection) and quarantine on all of your host endpoints or select host sets in your environment, infected files are automatically copied to a quarantine location. After relocating the infected file to quarantine, malware protection attempts to clean the file by removing malicious code. You can manage quarantined files from the Endpoint Security Web UI by acquiring the file from the quarantine area, restoring the file to its normal location on the endpoint, and deleting the file from quarantine.
Quarantined files are stored in the quarantine area on the host endpoint until you manually delete them, manually restore them, or they exceed the quarantine file aging period. See "Deleting Quarantined Files" in the Endpoint Security (HX) Server User Guide for more information on manually deleting quarantined files. You can configure the quarantine file aging period in the Endpoint Security (HX) Web UI. The default quarantine file aging period is 90 days. See Setting the Aging Interval for Quarantine Files for more information.
This section covers how to use the Web UI to enable and disable file quarantine for all of your host endpoints and for selected host sets in your environment. See the Endpoint Security (HX) REST API Guide for information on using the API to enable and disable file quarantine.