The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Policies and Threat Prevention

Prev Next

Policies are collections of settings that you create, configure, and apply, then enforce. Most policy settings correspond to settings that you configure in the Trellix Endpoint Security (ENS) Client. Other policy settings are the primary interface for configuring the software.

Policy enforcement ensures consistent security configurations across the environment, preventing unauthorized changes and maintaining a secure endpoint posture. Policy enforcement is enabled by default, and is inherited in the System Tree, but you can manually enable or disable enforcement on specified systems by adjusting the Enforcement status to Enforcing or Not enforcing.

Policy Categories

Your managed product adds these categories to the Policy Catalog. The available settings vary in each category.

Threat Prevention categories

Category

Category

Access Protection

Prevents unwanted changes to the client system by restricting access to specified files, shares, registry keys, registry values, processes, and services.

Exploit Prevention

  • Prevents unwanted changes to the client system by restricting access to files, shares, registry keys, registry values, processes, and services.

  • Prevents applications from executing arbitrary code.

  • Detects and prevents known network-based attacks.

On-Access Scan

Configures scheduled scanning of all processes, including maximum scan time and threat-detection message configuration.

On-Demand Scan

Configures preconfigured scans that run on the client system, including:

  • Full Scan and Quick Scan from the Trellix Endpoint Security (ENS) Client

  • Right-Click Scan on the client system

  • Custom On-Demand Scan client tasks, scheduled from ePO - On-prem

Options

Configures the settings that apply to both the on-access scanner and on-demand scanner.

Customizing policies (ePO)

Each policy category includes default policies.

You can use default policies as is, edit the My Default default policies, or create policies.

Threat Prevention default policies

Policy

Description

Management platform

Trellix Default

Defines the default policy that takes effect if no other policy is applied. You can duplicate, but not delete or change, this policy.

All

My Default

Defines default settings for the category.

ePO

On-Access Scan for Exchange

Defines an on-access scan policy with exclusions for Microsoft Exchange Server. This policy isn't applied until you assigned it to systems. For information, see Knowledge Base article KB51471.

All



Comparing policies

In ePO - On-prem 5.0 and later, you can compare policies within the same policy category using Policy Comparison.

For information about policies and the Policy Catalog, see the ePO - On-prem documentation.