When policies are applied and enforced

Prev Next

Policies are applied to systems according to the amount of time defined in 2 settings. ASCI defines how often the agent communicates with the server. Policy enforcement interval defines when policy settings are enforced.

Applying policies

After you configure policy settings, the new settings are applied to specified managed systems at the next agent-server communication. By default, the agent-server communication occurs every 60 minutes. You can adjust this interval on the General tab of the Trellix Agent policy pages. Or, depending on how you implement agent-server communication, you might change the ASCI using the agent wake-up client task.

If you want to change the settings of a default policy, you need to duplicate the policy and rename it. Make the required changes and reassign the policy to the managed systems. The next time an agent-server communication occurs, the new policy is applied to these systems.

Enforcing policies

The timing of policy enforcement depends on the configuration of the policies. Enforcement can happen:

  • Instantly

    Example: On-Access Scan policy occurs when you start any application.

  • At agent-server communication or policy enforcement intervals

    Example: Product Deployment policy runs to confirm that the installed software versions on the managed systems match the versions on the Main Repository. If a new version is available, it is downloaded to all systems.

  • At configured Client Task intervals:

    Example: On-demand scan policy, by default, runs every day at midnight to scan all your managed systems for threats.

After policy settings are applied on the managed system, the Trellix Agent continues to enforce policy settings according to the policy enforcement interval (default is 60 minutes). You can adjust this interval on the General tab as well.

When you want an on-demand scan to run every day at midnight, you configure the settings so that:

  1. The Policy Based on-demand scan Client Task runs at 12 a.m.

  2. The client task starts the full on-demand scan on the managed systems.

  3. Using the configured settings in the policy, the scan runs and if any threats are found they are cleaned, quarantined, or deleted as required.