The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Add files to the allow list for specific endpoints

Prev Next

You can add one or more executable files to the allow list to permit the files to run on the endpoint.

  1. On the ePO - On-prem console, select Menu → Application Control → Policy Discovery to open the Policy Discovery page.

  2. Click a row to review request details in the Request Details page.

    Each row in the Enterprise level activity pane represents an executable file and endpoint combination.

  3. Click Allow Locally for a row.

    The Allow Locally dialog box lists one or more paths to add to the allow list.

    Note

    The Allow Locally action is available only for requests that are generated when you execute an application that isn't in the allow list (Application Execution activity).

  4. Review and customize the listed paths.

    For example, if you execute proc.exe for an endpoint, these paths might be listed.

    C:\Program Files\<App Name>\proc.exe

    C:\Program Files\<App Name>\a.dll

    C:\Program Files\<App Name>\b.dll

    To avoid redundancy, add only the C:\Program Files\App Name path.

  5. Click OK.

The specified paths are added to the allow list and are permitted run on the endpoint.