User logoff

Prev Next

When you see a suspicious login activity or unusual user behavior on the endpoint, you can terminate the selected user's session remotely on the endpoint using the specific user name.

The Execute User Logoff reaction is supported on Windows, Linux, and macOS endpoints.

  1. Log on to Trellix EDR.

  2. Select MenuReal-time Search.

  3. On the Search box, enter a search expression.

  4. Click the search icon to start collecting data from managed devices.

  5. Based on the search expression, the list of events, processes, or devices is displayed.

  6. From the list, select the affected event, process, or device, then select ActionContainExecute User Logoff.

    A new window appears and then you can enter details:

    • User name — The user to be logged off.

  7. Click Confirm to complete the Execute User Logoff action.

    A confirmation message displays as the action launched is completed successfully.

  8. On the Action History dashboard, Action Status displays the execute user logoff action as Completed.