Remediation policy

Prev Next

The Remediation policy configures actions to contain and resolve threats on compromised endpoints. This includes settings to remotely isolate endpoints, customize user notifications, and specify allowed IP addresses for investigation purposes.

Host Remediation

Configure the Host Remediation server component on the Endpoint Security (HX) server before enabling the Host Remediation client component in ePO.

Option

Definition

Enable Host Remediation

Enables you to remotely connect and execute commands on a host, within the ePO on applicable endpoints.

Containment Settings

Option

Definition

Enable the option to display the message on containment actions

Enables a customizable pop-up message when an endpoint's containment status changes.

Enable password to uncontain the endpoint (Windows only)

Requires a password to remove an endpoint from containment.

Exclude application paths from containment for Windows

Exempts specified application paths from network isolation on Windows endpoints.

Exclude application paths from containment for macOS

Exempts specified application paths from network isolation on macOS endpoints.

Exclude application paths from containment for linux

Exempts specified application paths from network isolation on linux endpoints.

Allowed IP Addresses

Allows endpoints under containment to communicate with specific IP addresses for investigation and remediation, while restricting other network traffic. Essential protocols remain unaffected. This configuration persists until the endpoint is uncontained and re-contained.