The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Configuring exemptions for Device Guard module

Prev Next

Before enabling the policy for a host set, admins can create exemptions to the class-based policy by further configuring the Device Guard Module.

To configure exceptions for the Device Guard module from Endpoint Security Web UI:

Configuring_Device_Guard_module_Fig-2_.PNG
  1. Log in to the Endpoint Security Web UI as an administrator.

  2. From the Modules menu, select Endpoint Module Administration to access the Modules page.

  3. On the Modules page, locate the Device Guard module and click Actions and select Configure to begin configuring the module exception settings.

Once the configure button is clicked an admin will land on the Device Guard Settings page as seen below.

Device_Guard_Settings.PNG

We can then proceed to create an exemption to the Device Guard class policy restrictions by clicking on the Add Exemption button. This button will bring up the following form:

Adding_Device_Exemptions.PNG