The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in mid-October 2026. We hope you enjoy the updated experience.

Policies and Web Control

Prev Next

Policies are collections of settings that you create, configure, and apply, then enforce. Most policy settings correspond to settings that you configure in the Trellix Endpoint Security (ENS) Client. Other policy settings are the primary interface for configuring the software.

Policy enforcement ensures consistent security configurations across the environment, preventing unauthorized changes and maintaining a secure endpoint posture. Policy enforcement is enabled by default, and is inherited in the System Tree, but you can manually enable or disable enforcement on specified systems by adjusting the Enforcement status to Enforcing or Not enforcing.

Policy Categories

Your managed product adds these categories to the Policy Catalog. The available settings vary in each category.

Web Control policy categories

Category

Description

Block and Allow List

(Multiple-instance)

Configures the Block and Allow List, including:

  • Sites that users are allowed to access

  • Sites that users are blocked from accessing

  • Access to individual resources, such as file downloads, on the sites

  • Whether the allowed sites have precedence over blocked sites

You can apply several instances of this policy, resulting in one combined, effective policy.

Browser Control

Configures settings to prohibit specific supported and unsupported browsers.

Content Actions

(Multiple-instance)

Configures rules for user access, based on the safety ratings assigned to:

  • Categories of web content

  • Websites

  • File downloads

You can apply several instances of this policy, resulting in one combined, effective policy.

Enforcement Messaging

Specifies messages and explanations, which can include your own image, to display when users attempt to access:

  • Sites blocked and warned by Rating Actions

  • File downloads blocked and warned by Rating Actions

  • Phishing pages

  • Blocked sites on the Block and Allow List

  • Sites blocked when Trellix GTI is unreachable

  • Sites blocked and warned that Trellix GTI has not yet verified

Options

Configures general settings, including:

  • Disable and enable the client software.

  • Prevent users from uninstalling or disabling the browser plug-in.

  • Show and hide Web Control in the browser.

  • Configure action enforcement behavior.

  • Enable Observe mode to evaluate and tune policy settings before implementing them.

  • Specify Secure Search settings.

  • Configure logging.

  • Configure Web Reporter.

  • Set up Web Control behavior if your organization implements a web gateway.



Customizing policies (Trellix ePO - On-prem)

Each policy category includes default policies.

You can use default policies as is, edit the My Default default policies, or create policies.

Web Control default policies

Policy

Description

Management platform

Trellix Default

Defines the default policy that takes effect if no other policy is applied. You can duplicate, but not delete or modify, this policy.

All

My Default

Defines default settings for the category.

Trellix ePO - On-prem



Multiple-instance policies

The Content Actions and Block and Allow List policies are multiple instance policies. You can assign more than one policy instance to a client. For the policies that have multiple instances, an Effective Policy link provides a view of the details of the combined policy instances.

User-based policies (Trellix ePO - On-prem)

User-based policies (UBP) enable policies to be defined and enforced using Trellix ePO - On-prem policy assignment rules with an LDAP server. These assignment rules are enforced on the client system for the user at log-on, regardless of the Trellix ePO - On-prem group.

User-based policies are enforced when a user with a matching assignment rule logs on to the client system on the console. System-based policies (SBP) are enforced when two or more users are logged on to a system. Policy assignment rules take precedence over policies defined in the System Tree.

The user policy supersedes the system policy. All system policies apply and any user-based policy overrides the system policy.

Policy assignment rules are enforced only if the user logs on as the interactive user. The system policy, rather than the user policy, is enforced if the user logs on:

  • With a run as command

  • To a remote desktop or terminal service where the user's logon is not set to interactive

For more information about user-based policies and policy assignment rules, see the Trellix ePO - On-prem Help.

Comparing policies

You can compare all policy settings for the module using the Policy Comparison feature in Trellix ePO - On-prem. For information, see the Trellix ePO - On-prem Help.

For information about policies and the Policy Catalog, see the Trellix ePO - On-prem documentation.