The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Recommended post-installation tasks

Prev Next

Perform these tasks to make sure that the protection configuration does not affect the business routines.

Note

For a fresh installation, Trellix recommends updating the DAT to the latest version. Since the DAT version 0999 is used to reduce the product footprint, you must update the DAT to the latest version immediately after installation to protect your systems from malware threats. The DAT version 0999 detects only the EICAR test file.

Task

Description

Update the content files

After installation, Trellix Endpoint Security (ENS) for Mac automatically updates the content files to protect the Mac from the latest threats. By default, this update is scheduled at 4.45 pm local time every day. When the files are updated for the first time, it may take longer time to download the full content. The subsequent updates will be incremental.

You can view the content files last update details in the Console page.

Perform an on-demand scan

Run an on-demand-scan to scan the local volumes, after you install the software to clean any infected files that might reside in the Mac.

Configure the On-Demand Scan task to define:

  • The items to scan (files, folders, and drives)

  • Set frequency of scan (daily, weekly, monthly, or immediately)

  • Define the action when malware is found (Delete or Clean)

Threat Prevention

Trellix Endpoint Security (ENS) for Mac comes with the default settings. Verify that the default settings are consistent with your organization policies and provides complete protection against malware.

Firewall

Trellix Endpoint Security (ENS) for Mac comes with the stateful Firewall enabled, which protects your Mac from the moment the product is installed. The firewall comes with a set of default rules that enable your Mac to access the necessary services. We recommend that you review the default rules to make sure that your Mac can access the necessary services according to your organization policies.

The rules are processed using a top-down approach with the implicit default block rule that denies all traffic. This rule can't be modified.

Web Control

Review the default Web Control settings and update the Block and Allow List in such a way that you can access business-critical sites and block unwanted sites.

Caution

The Block and Allow List overrides other settings such as Enable Web Category Blocking and Rating Actions for Sites.

Self Protection

Verify that Self Protection is enabled and functioning as expected. Ensure that the required macOS permissions, including Full Disk Access, are granted to Trellix processes. Also confirm that protected Trellix files and processes cannot be modified or stopped while Self Protection is enabled.

Note

You must provide full disk access to Trellix processes as described in the Trellix Knowledge Base article KB91109.

Note

You must allow system extension and content filter for Firewall to work properly, as described in the Trellix Knowledge Base article KB93600.