All code written by Trellix and Microsoft is inspected and validated. If those inspections result in a validation failure, it is possible that AAC might block Trellix processes. A validation failure can include certain trust failures and other types of unexpected failures.
Validation failure scenarios
When a Trellix process loads a third-party DLL, it contains third-party functions and can execute the third-party code. The third-party code resides in the Trellix process and can cause the Trellix process to perform unintended operations and result in a validation failure.
Validation failures can produce several symptoms, including these scenarios.
A third-party process is blocked from accessing Trellix-protected files or processes.
A third-party process that loads Trellix DLLs is blocked from accessing other Trellix processes, files, or folders. For example, Microsoft Outlook is blocked when it tries to access other Trellix processes.
A Trellix process fails to start properly. For example, you are unable to start the Trellix Endpoint Security (ENS) despite installation logs indicating that startup was a success.
A Trellix process is running, but is only partially operational. For example, a Trellix product loads successfully but indicates that other services are not running properly, yet the Trellix service is running.
A Trellix process is blocked from accessing other files and folders belonging to a different Trellix product.
Failure to validate Trellix or Microsoft code indicates one of these scenarios occurred. If you experience one of these issues, contact technical support for help troubleshooting and to discuss solutions.
Managing third-party certificates
A process, called MFECanary.exe, runs as a child process to MFEEsp.exe and captures digital certificate detail for any DLL that attempts to inject into the MFECanary.exe process. The information is sent to Trellix ePO - On-prem from an agent event, which is processed by the Trellix ePO - On-prem server. It is then sent to the Trellix Endpoint Security (ENS) Common policy. From the policy, you can decide whether client systems trust or do not trust the third-party certificate. To trust it, you must add the digital signature to the certificate store.
Technical support can help in identifying the third-party certificate, obtaining the certificate file (.cer), and trusting a third-party digital certificate with signed third-party DLLs that are injected into Trellix processes.
For information about opening a Service Request or to expedite the processing of an escalation, see KB88085. For technical support contact details, go to ServicePortal and select your country from the drop-down list.