The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Policies and Common

Prev Next

Policies are collections of settings that you create, configure, and apply, then enforce. Most policy settings correspond to settings that you configure in the Trellix Endpoint Security (ENS) Client. Other policy settings are the primary interface for configuring the software.

Policy enforcement ensures consistent security configurations across the environment, preventing unauthorized changes and maintaining a secure endpoint posture. Policy enforcement is enabled by default, and is inherited in the System Tree, but you can manually enable or disable enforcement on specified systems by adjusting the Enforcement status to Enforcing or Not enforcing.

Policy Categories

Your managed product adds these categories to the Policy Catalog. The available settings vary in each category.

Common categories

Category

Description

Options

Configures general settings, including:

  • Specify client interface mode.

  • Require a password to uninstall the client.

  • Configure a time-based password.

  • Configure the client interface language.

  • Enable and disable Self Protection.

  • Specify processes to exclude from AAC.

  • Allow certificate authentication and upload third-party certificates.

  • Set up logging for client activity.

  • Configure proxy server settings.

  • Enable and disable default client updates.

  • Display managed custom tasks.

Customizing policies (ePO - On-prem)

Each policy category includes default policies.

You can use default policies as is, edit the My Default default policies, or create policies.

Common default policies

Policy

Description

Management platform

Trellix Default

Defines the out-of-the-box policy that takes effect if no other policy is applied. You can duplicate this policy, but you can't delete or change it.

All

My Default

Defines the customizable default policy for your environment.

Tip

Modify this policy to create your own customized default.

ePO - On-prem

Comparing policies

In ePO - On-prem 5.0 and later, you can compare policies within the same policy category using Policy Comparison.

For information about policies and the Policy Catalog, see the ePO - On-prem documentation.