Follow these suggestions for better management of rules when reviewing Policy Discovery requests.
Limit the use of "Allow File Globally" action. This adds the rule to the Global Rule rule group, which is embedded in the Trellix Default Application Control policy. High use of this action can lead to policy bloat and policy enforcement issues, and increased difficulty in managing the Application Control policies. Rules that allow activity within Application Control must be categorized based on vendor/application name, rather than dumped into a single Rule Group bucket for efficient management of rules.
When creating Rule Groups, a standard naming convention must be used to help organize policies within ePO - SaaS. Rule Groups include policies and application vendors such as ACCT_ADOBE or BASELINE_Microsoft.
Use Create Custom Policy to create rules based on Policy Discovery requests. Organize the rules created for separate categories such as company/vendor name, application name, application purpose, and, function rather than putting all rules into a single group. This can help manage the rules.
Some Policy Discovery requests can't be added through this process, due to the activity being generated from a Generic Launcher Process. An error "Updater rule can’t be made for Generic launcher process" might be displayed when doing so. Manual creation of rules for Generic Launcher Process is not recommended.
When trying to trust your gold image there is no need to trust the inventory of one system and allow it by adding all binaries to a rule group (auth by checksum, or auth by name). Solidification allows everything on these systems to run already unless specified not to based on your policy (ban rules or reputation). Doing so could cause performance issues due to large policies trying to apply to the system.
We do not have any constraints on how many objects can be assigned to a rule group or a policy. But, we do not recommend large number of objects in the Auth or ATTR groups. TACC is multi-slotted in Policy Catalog. If you have many large rule groups with many objects, Trellix Application and Change Control considers this as 1 group and link the objects. We apply each object to the system 1 by 1 which could take a couple of seconds to apply. If you have large policies, we recommend that you leave the policy enforcement at default settings (60 mins) to allow your policy to complete. It applies only delta changes instead of trying to reapply the whole policy at every enforcement. We have seen this cause a constant cpu constraint of 25% and never released due to policy enforcement never completing.
Policies are applied to an endpoint using one command at a time. Policies with rules numbering in thousands can cause significant performance issues, especially if duplicate updaters or rules are present.
If a non-generic process is identified as a parent process for several binaries, you can add the parent process as an updater eliminating the need for the child processes to be added as a binary.
Using certificates can significantly cut down on the administration overhead and policy size.
If possible, an in-house certificate authority must be used to sign home grown applications.