The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Prevent Dynamic Application Containment from containing trusted programs

Prev Next

If a trusted program is contained, you can allow it to run normally by creating a Dynamic Application Containment exclusion.

Exclusions created using the Trellix Endpoint Security (ENS) Client apply to the client system only. These exclusions aren't sent to Trellix ePO - On-prem and don't appear in the Exclusions section in the Dynamic Application Containment settings.

Create global exclusions in the Dynamic Application Containment settings in Trellix ePO - On-prem.

Endpoint Security treats all file and folder exclusions as case insensitive — all case variations of the specified locations are excluded. For example, if you exclude C:\Temp\ABC, Endpoint Security also excludes C:\temp\abc and C:\TEMP\Abc.

Task
  1. Identify trusted applications to exclude: View the list of contained applications sent from managed systems to Trellix ePO - On-prem.

  2. Select MenuPolicyPolicy Catalog, then select Endpoint Security Adaptive Threat Protection from the Products list in the left pane.

  3. From the Category list in the right pane, select Dynamic Application Containment.

  4. Click the Edit link for an editable policy.

  5. Click Show Advanced.

  6. In the Exclusions section, click Add to add processes to exclude from all rules.

  7. On the Exclusion page, configure the executable properties.

  8. Click Save twice to save the policy settings.