The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Setting up Trellix Endpoint Security (ENS) 26.x for the first time on Trellix ePO - On-prem

Prev Next

To fully protect your endpoints, you need to set up Trellix Endpoint Security (ENS) after a fresh installation. These are some recommended baseline configuration that will help you get started with protecting your endpoints.

Recommended configurations

Configuration

Description

Lock the client interface

Set a password to control access to the endpoint client. By default, the client Interface is accessible to endpoint users. Allowing users to change their security configuration can leave systems unprotected from malware attacks.

Protect Services and files

One of the first things that malware attempts to do during an attack is to disable your system security software. To prevent services and files of Trellix Endpoint Security (ENS) from being stopped or modified, enable Self Protection.

Configure the proxy server settings

Set up ENS client to redirect web traffic to a proxy server.

Set up logging for client activity

Logging client activity, debug, and events, allows you to determine if you need to change settings to enhance protection or improve system performance.

Configure predefined scans

Configure how Trellix Endpoint Security (ENS) should handle a full system scan, quick scan, and right-click scan at the endpoints.

Configure scans that run automatically when files are accessed

You can specify when the files are examined: when writing to disk, when reading from disk, both, or let Trellix Endpoint Security (ENS) decide when to scan.

Prevent applications from executing arbitrary code on client systems

Configure Trellix Endpoint Security (ENS) to prevent exploits such as buffer overflow, illegal API use, and network exploits. For the list of processes protected by Trellix Endpoint Security (ENS), see KB58007.

Configure Trellix Endpoint Security (ENS) to detect and respond to potentially unwanted programs

Specify programs that you want Trellix Endpoint Security (ENS) to treat as unwanted programs.

Enable and configure firewall for your environment

Configure the settings to set up firewall based on your organization needs.

Manage Firewall client rules

Tune and tighten the firewall security for your client systems. Tuning involves finding the right balance between protecting your environment from intrusions and allowing access to required information and applications. For more information, see Tuning Firewall.

Warn about or block unknown URLs and file downloads

Configure what action Trellix Endpoint Security (ENS) takes to blocked URLs or URLs that are not yet rated by Trellix GTI when accessed on a client system.

Manage blocked and allowed sites

Define which website are always allowed or always blocked based on their URL or domain.