Stopping containment using an unlock code

Prev Next

When you contain a Windows host running Endpoint Security (HX) xAgent version 28 or later, a macOS host running Endpoint Security (HX) xAgent version 30 or later, or a Linux host running Endpoint Security (HX) Agent version 34 or later, a containment unlock code is generated by the Endpoint Security (HX). If your Endpoint Security (HX) xAgent is unable to communicate with the Endpoint Security (HX), you can use the unlock code to remove the host from containment.

If the containment unlock code feature is enabled, your system administrator can request the unlock code from the Endpoint Security (HX) Web UI Host Details page or using an API request and provide the unlock code to the local user. The local user can run Trellix's uncontain executable with the unlock code at the Windows, macOS, or Linux command prompt to uncontain the host system.

Important

The containment unlock code feature must be enabled in order for your system administrator to request the unlock code for a contained host using the Web UI or an API request.

Each Endpoint Security (HX) xAgent has a unique unlock code, which is a random string of alpha numeric characters

Prerequisites

This section covers the following topics: