You can configure the number of failed passwords a user can enter before the user's account is temporarily locked out of the client interface.
Make sure that the interface mode for the Trellix Endpoint Security (ENS) Client is set to Standard access or Lock client interface.
Select Menu → Policy → Policy Catalog, then select Endpoint Security Common from the Products list in the left pane.
From the Category list in the right pane, select Options.
Click the Edit link for an editable policy.
Click Show Advanced.
In the Client Interface Mode section, select Enable client interface lockout, then specify the maximum number of incorrect passwords and maximum lockout time.
The client interface automatically unlocks after the maximum lockout time expires.
Click Save.