The Remediation policy configures actions to contain and resolve threats on compromised endpoints. This includes settings to remotely isolate endpoints, customize user notifications, and specify allowed IP addresses for investigation purposes.
Host Remediation
Configure the Host Remediation server component on the Endpoint Security (HX) server before enabling the Host Remediation client component in ePO.
Option | Definition |
|---|---|
Enable Host Remediation | Enables you to remotely connect and execute commands on a host, within the ePO on applicable endpoints. |
Containment Settings
Option | Definition |
|---|---|
Enable the option to display the message on containment actions | Enables a customizable pop-up message when an endpoint's containment status changes. |
Enable password to uncontain the endpoint (Windows only) | Requires a password to remove an endpoint from containment. |
Exclude application paths from containment for Windows | Exempts specified application paths from network isolation on Windows endpoints. |
Exclude application paths from containment for macOS | Exempts specified application paths from network isolation on macOS endpoints. |
Exclude application paths from containment for linux | Exempts specified application paths from network isolation on linux endpoints. |
Allowed IP Addresses | Allows endpoints under containment to communicate with specific IP addresses for investigation and remediation, while restricting other network traffic. Essential protocols remain unaffected. This configuration persists until the endpoint is uncontained and re-contained. |