You can block access to the containment feature on the Endpoint Security (HX) Web UI using the block containment CLI command. When the containment feature is blocked, the containment switch shows DISABLED in the Web UI.
When the containment feature is blocked, you must unblock containment using the CLI.
Endpoint Detection and Response with Forensics (EDRF) > Manage your workspaces > Configure Forensics workspace > Configuring containment > Turning containment on and off
Endpoint Detection and Response with Forensics (EDRF) > Manage your workspaces > Configure Forensics workspace > Configuring containment > Turning containment on and off