The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Configure Trellix-defined containment rules on a client system

Prev Next

Trellix-defined containment rules block or log actions that contained applications perform. You can change the block and report settings, but you can't otherwise change or delete these rules.

Before you begin

Make sure that the interface mode for the Trellix Endpoint Security (ENS) Client is set to Full access or log on to the Trellix Endpoint Security (ENS) Client as administrator.



Task
  1. Open the Trellix Endpoint Security (ENS) Client.

  2. Click Adaptive Threat Protection on the main Status page.

    Or, from the Action menu GUID-A3B12F55-7EE9-4519-8FCA-9ACA85C3661F-low.png, select Settings, then click Adaptive Threat Protection on the Settings page.

  3. Click Show Advanced.

  4. Click Dynamic Application Containment.

  5. In the Containment Rules section, select Block, Report, or both for the rule.

    • To block or report all, select Block or Report in the first row.

    • To disable the rule, deselect both Block and Report.

  6. In the Exclusions section, configure executables to exclude from Dynamic Application Containment. Processes in the Exclusions list run normally (not contained).

  7. Click Apply.