Follow these steps to globally enable or disable the blocking of files based on riskware detected by Trellix Riskware rules on the File Protect appliance.
Note
Riskware detection alerts are generated by default when files are blocked.
To enable blocking files based on riskware detected by the Trellix Riskware rules:
In the Web UI, choose Settings > Riskware Policy.
Select the FireEye Riskware Rules tab.
Click the Quarantine checkbox for the Trellix Riskware rules.
Click Apply. The following message appears:
Updated selected Riskware Rules.
To disable blocking files based on riskware detected by the Trellix Riskware rules:
In the Web UI, choose Settings > Riskware Policy.
Select the FireEye Riskware Rules tab.
Clear the Quarantine checkbox for the TrellixRiskwarerules.