Policies are collections of settings that you create, configure, and apply, then enforce. Most policy settings correspond to settings that you configure in the Trellix Endpoint Security (ENS) Client. Other policy settings are the primary interface for configuring the software.
Policy enforcement ensures consistent security configurations across the environment, preventing unauthorized changes and maintaining a secure endpoint posture. Policy enforcement is enabled by default, and is inherited in the System Tree, but you can manually enable or disable enforcement on specified systems by adjusting the Enforcement status to Enforcing or Not enforcing.
Policy Categories
Your managed product adds these categories to the Policy Catalog. The available settings vary in each category.
Dynamic Application Containment | Runs applications with specific reputations in a container, blocking actions based on containment rules. Uses the TIE server or Trellix GTI, depending on your configuration, for the application reputation. |
Options | Specifies options for Adaptive Threat Protection, including:
|
Customizing policies (Trellix ePO - On-prem)
Each policy category includes default policies.
You can use default policies as is, edit the My Default default policies, or create policies.
Policy | Description | Management platform |
|---|---|---|
Trellix Default | Defines the default policy that takes effect if no other policy is applied. The Trellix Default Dynamic Application Containment policy sets rules to Report only. Users experience no blocking or prompting.
You can duplicate, but not delete or change, this policy. |
|
My Default | Defines default settings for the category. | Trellix ePO - On-prem |
Trellix Default Balanced | Defines a Dynamic Application Containment policy with Block rules set to provide a base level of protection while minimizing false positives for common unsigned installers and applications. Use this policy for typical business systems where new programs and changes are installed infrequently. Users experience some blocking and prompting. |
|
Trellix Default Security | Defines a Dynamic Application Containment policy with Block rules to provide aggressive protection. This policy might cause false positives more frequently on unsigned installers and applications. |
|
Note
The Dynamic Application Containment policies, Trellix Default Balanced and Trellix Default Security, specify rules settings for Dynamic Application Containment only. These policies are different from, and don't affect the Productivity, Balanced, or Security rule groups that Adaptive Threat Protection uses to calculate reputation.
Best practice
Evaluate the impact of Dynamic Application Containment rules by enforcing the Trellix Default policy. To determine whether to set rules to block, monitor the logs and reports for "Dynamic Application Containment violation allowed" (event ID 37280) events. Then, set Enterprise-Level Reputations or Dynamic Application Containment exclusions and enforce the Trellix Default Balanced policy.
Comparing policies
In Trellix ePO - On-prem 5.0 and later, you can compare policies within the same policy category using Policy Comparison.
For information about policies and the Policy Catalog, see the Trellix ePO - On-prem documentation.