Application Control and Change Control can operate in four different modes. Each mode is different in principle and usage.
Enabled mode
This mode indicates that the software is running and protection is enabled.
In Enabled mode, Application Control allows only trusted or authorized (based on rules) applications and installers to run on servers and endpoints. Change Control prevents unauthorized changes to critical system files, directories, and configurations.
Observe mode
This mode indicates that the software is running but it only monitors and logs observations. The application does not prevent any execution or changes made to the endpoints. Instead, it monitors execution activities and compares them with the local inventory and predefined rules.
Important
This mode is available only with Application Control and in a Trellix ePO - On-prem managed environment.
Update mode
This mode indicates that protection is effective but changes are allowed on protected endpoints. When you perform software updates in Update mode, Application Control tracks and records each change. Also, it dynamically updates the whitelist to make sure that the new binaries and files are authorized to run when the system returns to Enabled mode. In Update mode, all tracked changes are added to the whitelist. If you delete any software or program files from the system, their names are also removed from the whitelist.
Tip
Best practice: Use Update mode only for installing minor software updates. For example, define an interval to allow the IT team to complete maintenance tasks, such as installing patches or upgrading software.
Disabled mode
This mode indicates that the software isn't running on your system. Although the application is installed, its features are disabled. After installation, the application appears in Disabled mode by default. You can then switch to Observe, Update, or Enabled mode.
Disabled* mode
Although a complete disabling of the software without a system reboot is technically not possible, a partial disable or a no-tracking state can be achieved without a reboot by using a special mode called Global Passthru or Disabled* mode. Because everything is passed through, Application Control monitors nothing and the system behaves as if it is in Disabled mode with the following exceptions:
- Kernel modules remain loaded.
- Minimal tracking continues.
Switching between modes
- From Observe mode, you can switch to Enabled or Disabled mode.
- From Enabled mode, you can switch to Disabled(*), Update, and Observe mode.
- From Update mode, you can switch to Enabled or Disabled mode.
- From Disabled mode, you can switch to Enabled, Update, or Observe mode.