Device exclusion categories are customizable rules containing specific criteria for devices that should not trigger insufficient coverage alerts.
You may decide to not address particular content or coverage deficiencies highlighted on your devices by Trellix Insights due to environment-specific considerations. Device exclusions created in Trellix Insights can be used to exclude such devices from appropriate categories to ensure that Trellix Insights alerts you of only the most critical issues. The rules are granular and can be created at the parameter level for each category and sub-category in included in the Security Posture.
A role-based access control applied to the exclusions, and only users with Trellix Insights Admin Access can create, update, or delete an exclusion.
When an exclusion is created, Trellix Insights fetches all exclusions for a given ePO - SaaS policy group and updates the Security Posture score to reflect fewer or no devices showing insufficient coverage.
You can navigate to device exclusions by clicking Settings > Exclusions. Alternatively, you can access device exclusions in the Configure User Settings menu by clicking Exclusions in the Security Posture tooltip.
The is no limit and on the number of exclusions that can be created. Existing exclusions can be updated by adding more devices or updating the Security Posture categories (Content, Zero-day, and Configuration).