Policies are collections of settings that you create, configure, and apply, then enforce. Most policy settings correspond to settings that you configure in the Trellix Endpoint Security (ENS) Client. Other policy settings are the primary interface for configuring the software.
Policy enforcement ensures consistent security configurations across the environment, preventing unauthorized changes and maintaining a secure endpoint posture. Policy enforcement is enabled by default, and is inherited in the System Tree, but you can manually enable or disable enforcement on specified systems by adjusting the Enforcement status to Enforcing or Not enforcing.
Policy Categories
Your managed product adds these categories to the Policy Catalog. The available settings vary in each category.
Common categories
Category | Description |
|---|---|
Options | Configures general settings, including:
|
Customizing policies (ePO - On-prem)
Each policy category includes default policies.
You can use default policies as is, edit the My Default default policies, or create policies.
Common default policies
Policy | Description | Management platform |
|---|---|---|
Trellix Default | Defines the out-of-the-box policy that takes effect if no other policy is applied. You can duplicate this policy, but you can't delete or change it. | All |
My Default | Defines the customizable default policy for your environment.
| ePO - On-prem |
Comparing policies
In ePO - On-prem 5.0 and later, you can compare policies within the same policy category using Policy Comparison.
For information about policies and the Policy Catalog, see the ePO - On-prem documentation.