The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Policies and Adaptive Threat Protection

Prev Next

Policies are collections of settings that you create, configure, and apply, then enforce. Most policy settings correspond to settings that you configure in the Trellix Endpoint Security (ENS) Client. Other policy settings are the primary interface for configuring the software.

Policy enforcement ensures consistent security configurations across the environment, preventing unauthorized changes and maintaining a secure endpoint posture. Policy enforcement is enabled by default, and is inherited in the System Tree, but you can manually enable or disable enforcement on specified systems by adjusting the Enforcement status to Enforcing or Not enforcing.

Policy Categories

Your managed product adds these categories to the Policy Catalog. The available settings vary in each category.

Adaptive Threat Protection categories

Dynamic Application Containment

Runs applications with specific reputations in a container, blocking actions based on containment rules. Uses the TIE server or Trellix GTI, depending on your configuration, for the application reputation.

Options

Specifies options for Adaptive Threat Protection, including:

  • Enabling and disabling Adaptive Threat Protection.

  • Selecting the rule group (Productivity, Balanced, or Security), which contains the rules Adaptive Threat Protection uses to calculate reputation.

  • Enabling and disabling ML Protect client-based and cloud-based scanning.

  • Enabling and disabling Credential Theft Protection. (It can also be set to run in Observe Mode)

    Note

    Credential Theft Protection (CTP) is not supported in the ARM architecture.

  • Setting reputation thresholds.

  • Enabling and disabling enhanced remediation.

  • Configuring user messaging.

  • Specifying options for sending files to Sandbox server.



Customizing policies (ePO - On-prem)

Each policy category includes default policies.

You can use default policies as is, edit the My Default default policies, or create policies.

Adaptive Threat Protection default policies

Policy

Description

Management platform

Trellix Default

Defines the default policy that takes effect if no other policy is applied.

The Trellix Default Dynamic Application Containment policy sets rules to Report only. Users experience no blocking or prompting.

Note

To send Dynamic Application Containment Would Block events to ePO - On-prem, in the Common Options settings, set Adaptive Threat Protection events to log to Warning, Critical, and Alert.

You can duplicate, but not delete or change, this policy.

  • ePO - On-prem

  • ePO - SaaS

My Default

Defines default settings for the category.

ePO - On-prem

Trellix Default Balanced

Defines a Dynamic Application Containment policy with Block rules set to provide a base level of protection while minimizing false positives for common unsigned installers and applications.

Use this policy for typical business systems where new programs and changes are installed infrequently. Users experience some blocking and prompting.

  • ePO - On-prem

  • ePO - SaaS

Trellix Default Security

Defines a Dynamic Application Containment policy with Block rules to provide aggressive protection. This policy might cause false positives more frequently on unsigned installers and applications.

  • ePO - On-prem

  • ePO - SaaS



Note

The Dynamic Application Containment policies, Trellix Default Balanced and Trellix Default Security, specify rules settings for Dynamic Application Containment only. These policies are different from, and don't affect the Productivity, Balanced, or Security rule groups that Adaptive Threat Protection uses to calculate reputation.

Best practice

Evaluate the impact of Dynamic Application Containment rules by enforcing the Trellix Default policy. To determine whether to set rules to block, monitor the logs and reports for "Dynamic Application Containment violation allowed" (event ID 37280) events. Then, set Enterprise-Level Reputations or Dynamic Application Containment exclusions and enforce the Trellix Default Balanced policy.

Comparing policies

In ePO - On-prem 5.0 and later, you can compare policies within the same policy category using Policy Comparison.

For information about policies and the Policy Catalog, see the ePO - On-prem documentation.