The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Customize quarantine message to the endpoint user

Prev Next

When you are quarantining or removing the quarantine state of an endpoint, you can add and display the customized quarantine message notification to the endpoint user.

  1. On the ePO - On-prem or ePO - SaaS console, select Menu → Policy → Policy Catalog.

  2. From the Products list, select Trellix EDR.

  3. Create a new policy or edit the existing policy to access the Network Flow policy page.

  4. On the Network Flow policy, in quarantine or remove quarantine endpoint message notification fields, enter the customized message notification to display on an endpoint when it is quarantined or removed from the quarantine state.

  5. Click Save.

    After you create a policy, assign it to managed endpoints to configure the Trellix EDR clients on those endpoints.

    For details about assigning a policy to managed endpoints, ePO - On-prem or ePO - SaaS Product Guide.

The customized message notification is displayed on the endpoint when it quarantined or removed from the quarantine state.