During an investigation, when a threat in a quarantined endpoint is eradicated or dismissed as non-malicious, you can reconnect the endpoint to the network by ending the quarantine state using the Real-time Search dashboard.
Important
Make sure Enable Plug-in is selected on the Network Flow policy page for quarantine and end quarantine to work on the endpoint.
The End Quarantine Device feature is supported on Windows and macOS endpoints.
Log on to Trellix EDR.
Select Menu → Real-time Search.
On the Search box, enter a search expression.
Click the search icon to start collecting data from managed devices.
Based on the search expression, the list of events, processes, or devices is displayed.
From the list, select the affected event, process, or device, then select Action → Contain → End Quarantine Device.
A new window appears to complete the action.
Click Confirm to complete the End Quarantine Device action.
A confirmation message displays as the action launched is completed successfully.
On the Action History dashboard, Action Status displays the end quarantine device status as Completed.