When users try to run a new application on the endpoints, the Trellix Application Control - Self-Approval dialog box indicates that execution of the application has been detected and prompts the user to take action.
For trusted and malicious executable files and certificates, execution is determined based on reputation received from the configured reputation source. So, the Trellix Application Control - Self-Approval dialog box isn't displayed for trusted and malicious files. But, if the file or certificate reputation is unknown, the Trellix Application Control - Self-Approval dialog box prompts the user to take action. Perform one of these tasks:
Provide a justification (if mandatory) and click Allow to allow the action immediately. When you choose to self-approve the action, an approval request is sent to the administrator who reviews the provided justification to determine whether to allow or ban the action for one or more endpoints in the enterprise. The ePO - On-prem administrator allows the action only if it is in accordance with the corporate policies and the application is trusted and known.
Click Deny to deny the action. Users can deny the action when it isn't user-initiated or the changes seem irrelevant. The deny action is event-specific. If the same event is generated again, the user is prompted again to take an action.
Users can review the event notifications and request approval for certain actions.
Right-click the Trellix Agent icon in the notification area on the endpoint.
Select Quick Settings → Application and Change Control Events.
Request approval for a certain action from the ePO - On-prem administrator by selecting the event and clicking Request Approval. Denial events requested for approval from the Application and Change Control Events dialog box are now tagged with Approval Request and sent to the Policy Discovery page on the ePO - On-prem console by default. The administrator can create custom or global rules for these requests. If sending requests to the Policy Discovery page fails due to the unavailability of file information or unsupported event IDs, the administrator receives an email with all relevant event details and a link. The administrator can then open the event on the Solidcore Events page and define the necessary rules.