Endpoint Security (HX) allows you to remove a host from containment using the Endpoint Security (HX) Web UI.
Admin or investigator access
A host endpoint is contained. See Approving a containment request.
Select Manage Hosts in the Endpoint Security (HX) Web UI.
Select the checkbox to the left of a host endpoint that is contained.
Select Stop containment from the Actions menu.
Click Go.
Select Manage Hosts in the Endpoint Security (HX) Web UI.
Request host details by clicking on the Expand icon (
) associated with a host.At the top of the details page, click Stop containment.
After stopping containment is requested for a host, its status changes to Stopping containment. The containment cancellation icon (
) appears beside the hostname on every page where the host is listed.
When containment stops successfully, all containment icons disappear from beside the hostname. The Contained Hosts area of the Dashboard shows one fewer hosts in the number of hosts that are contained.
If containment does not stop successfully for a host, its containment status changes to Containment cancellation failed. The containment cancellation failed icon appears beside the hostname on every page where the host is listed.
When containment is stopped for a Windows endpoint, the notification files associated with the original containment of the endpoint are deleted. However, when containment is stopped for a macOS endpoint, the notification files associated with the original containment of the endpoint are retained.