When a macOS host endpoint's network access is restricted by containment, the end user is notified by a pop-up notification message. These pop-up notification messages are translated, based on machine locale and can appear in the following languages: Chinese (Simplified and Traditional), English, French, German, Italian, Japanese, Korean, Polish, Portuguese, Russian, and Spanish.
When a Windows or Linux host endpoint’s network access is restricted by containment, end users only know that they cannot access the network. They may attempt to restore network access by rebooting the host or taking other actions. These actions may hinder your ability to investigate the incident.
To discourage users from taking such action, you can notify them that the network restriction was deliberate in two ways.
Web page redirect: The end user’s browser is redirected to a central Web page that provides the notification. To use this method, you need to set up a Web page, include the URL on the Containment Settings page in the Endpoint Security (HX) Web UI, and add the server hosting the page to the containment whitelist. See Notifying end users about host containment using a Web page redirect.
Direct message: The agent software on the host displays the notification to the end user. To use this method, you need to enter the message on the Containment Settings page. See Notifying end users about host containment using a direct message.
Admin access