If a trusted program is blocked, you can exclude the process by creating a policy-based or rule-based exclusion.
Note
Access Protection exclusions don't apply to the Windows Services subrule type.
Select Menu → Policy → Policy Catalog, then select Endpoint Security Threat Prevention from the Products list in the left pane.
From the Category list in the right pane, select Access Protection.
Click the Edit link for an editable policy.
Click Show Advanced.
Verify that Access Protection is enabled.
Perform one of the following:
To...
Do this...
Exclude items from all rules.
In the Exclusions section, click Add to add items to exclude from all rules.
On the Exclusion page, configure the executable properties.
Click Save twice to save the settings.
Specify processes for inclusion or exclusion in a user-defined rule.
Edit an existing user-defined rule or add a rule.
On the Rule page, in the Executables section, click Add to add an executable to exclude or include.
On the Executable page, configure the executable properties, including whether to include or exclude the executable from protection.
Click Save three times to save the settings.