Application Control and Change Control can operate in four different modes. Each mode is different in principle and usage.
Enabled mode
This mode indicates that the software is running and protection is enabled.
In Enabled mode, Application Control allows only trusted or authorized (based on rules) applications and installers to run on servers and endpoints. Change Control prevents unauthorized changes to critical system files, directories, and configurations.
Observe mode
This mode indicates that the software is running but it only monitors and logs observations. The application does not prevent any execution or changes made to the endpoints. Instead, it monitors execution activities and compares them with the local inventory and predefined rules.
Important
This mode is available only with Application Control and in a ePO - On-prem managed environment.
Update mode
This mode indicates that protection is effective but changes are allowed on protected endpoints. When you perform software updates in Update mode, Application Control tracks and records each change. Also, it dynamically updates the allow list to make sure that the new binaries and files are authorized to run when the system returns to Enabled mode. In Update mode, all tracked changes are added to the allow list. If you delete any software or program files from the system, their names are also removed from the allow list.
Update mode supports reputation-based execution. When you execute a file at an endpoint, the software fetches the file's reputation to determine whether to allow or ban the file execution.
Tip
Best practice: Use Update mode only for installing minor software updates. For example, define an interval to allow the IT team to complete maintenance tasks, such as installing patches or upgrading software.
Disabled mode
This mode indicates that the software isn't running on your system. Although the application is installed, its features are disabled. After installation, the application appears in Disabled mode by default. You can then switch to Observe, Update, or Enabled mode.
Disabled* mode
Although a complete disabling of the software without a system reboot is technically not possible, a partial disable or a no-tracking state can be achieved without a reboot by using a special mode called Global Passthru or Disabled* mode. Because everything is passed through, Application Control monitors nothing and the system behaves as if it is in Disabled mode with the following exceptions:
Kernel modules remain loaded.
Minimal tracking continues.
Note
Reputation-based execution is available in 'enable,' 'update,' and 'observe' modes but not supported in 'disabled' mode. In 'disabled' mode, no Trellix GTI file reputation queries sent to the Trellix GTI cloud. However, actions are still be taken based on the responses to previously queued and sent reputation queries before switching to the 'disabled' mode.
Switching between modes
From Observe mode, you can switch to Enabled or Disabled mode.
From Enabled mode, you can switch to Disabled(*), Update, and Observe mode.
From Update mode, you can switch to Enabled or Disabled mode.
From Disabled mode, you can switch to Enabled, Update, or Observe mode.