xAgent policies provide the control you need to configure agent behavior by host sets. This allows you to establish different xAgent configurations for your endpoints. Use policies to configure global xAgent settings that apply to all of your host sets and use policies to enable or disable xAgent behaviors by host set or exclude agent behaviors by host set.
The xAgent Policy Service allows you to manage and create the following policy types:
xAgent Default Policy
The xAgent Default Policy defines the global xAgent configuration settings that apply to all host endpoints in your environment. This policy maps to the agent configuration file and defines default settings for all policy categories, including the server address list. The xAgent default policy also defines exclusion policies that globally exclude files and folders, MD5 hashes, and processes from specific xAgent processes.
The xAgent default policy has the lowest policy priority level, meaning all other policies assigned to your host endpoints take precedence over it.
All agents provisioned with an Endpoint Security (HX) server version 4.5 or later automatically receive the default policy when added to your network. You can modify the default settings within each policy category, enable or disable a specific xAgent policy, or exclude specific agent behaviors from the xAgent default policy. If you modify the default policy, all changes will immediately take affect on all of host endpoints in your enterprise.
Note
Endpoint Security (HX) version 4.5 or later does not support agent configuration file changes or xAgent policy and setting changes through the CLI.
The xAgent default policy settings are applied to all xAgent s deployed in your environment, including MIR or Windows xAgent s version 11.
You cannot disable or delete the xAgent default policy or change the policy name, description, or priority level. Use the Endpoint Security (HX) Web UI or the API to view and modify the agent default policy.
During an initial software install
Endpoint Security (HX) server 4.5 uses Trellix default values to define the agent configuration settings for each agent policy category and deploys the policy to all agents when you initially install the xAgent software on your host endpoints. You can modify the settings in the default policy and enable or disable agent behaviors on your host endpoints. See Agent Configuration File Reference for more information about the Trellix default values assigned to each xAgent setting.
After a software upgrade
When you upgrade your Endpoint Security (HX) server to version 4.5, the server migrates and maps your existing global configuration settings to the xAgent Default Policy and applies the policy to all host endpoints in your environment. This includes any existing global default settings defined for each policy category and any existing global exclusion policies defined for a specific agent process. See Policy Migration for more information.
Custom policies
Custom policies define specific xAgent configuration settings that you want to apply to one or more host sets in your environment. You can create and manage custom policies using the Web UI or the API.
When creating a custom policy, you can select one or more policy categories. Each policy category allows you to manage and control a specific set of xAgent behaviors. For example, you can create a custom policy to manage Malware Protection for one group of host sets and you can create another custom policy, with different Malware Protection settings, to manage another group of hosts sets.
Custom policies have a higher priority than the xAgent default policy. Therefore, the settings in a custom policy override the default settings for a specific policy category. For example, the Malware Protections settings in your custom policy override the Malware Protection default settings for the assigned host sets.
Use the Policies page in the Web UI to create a new custom policy. See Creating a Custom Policy for more information.
You can also manually create custom policies using an API custom configuration channel. These custom policies override all other xAgent policies for the assigned host sets. See Using API Custom Configuration Channels for more information.
Important
Trellix recommends using the Web UI to create custom policies because you cannot change the priority level or host set assignment for a custom policy created using an API custom configuration channel.
Custom exclusion policy
An exclusion policy is a type of custom policy that allows you to globally exclude specific files and folders, MD5 hashes, and processes from specific xAgent processes on all of your host endpoints or selected host sets. For example, you can access the Real-Time Indicator Detection policy within the xAgent Default Policy and globally exclude specific files and folders for Real-Time Indicator Detection processing for all of your host endpoints.
You can also create a custom exclusion policy that excludes specific files and folders, MD5 hashes, and processes from specific xAgent a processes an assign it to select host sets in your environment. Your custom exclusion policy will override your global exclusion policy in the xAgent default policy.
If you have existing global exclusion policies, after you upgrade your Endpoint Security (HX) server to version 4.5 or later, the server migrates and maps your global exclusion policies to the xAgent default policy. See Migrating Exclusion Policies for more information.
Migrated policy
xAgent policies that globally exclude selected host sets from specific agent processes. These exception policies existed in an earlier Endpoint Security (HX) server version and are migrated and mapped to separate exception policies after you upgrade your Endpoint Security (HX) server to version 4.5 or later. Migrated exception policies retain the same host set assignments that existed in your earlier xAgent software version.
See Policy Migration for more information.