The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Enable the trigger threshold for Dynamic Application Containment

Prev Next

With Dynamic Application Containment, you can specify that applications with specific reputations run in a container, limiting the actions they can perform. If the application reputation is at or below the containment reputation threshold, the application is contained.

Task
  1. Select Menu → Policy → Policy Catalog, then select Endpoint Security Adaptive Threat Protection from the Products list in the left pane.

  2. From the Category list in the right pane, select Options.

  3. Click the Edit link for an editable policy.

  4. Verify that ATP is enabled.

  5. Select Trigger Dynamic Application Containment when reputation threshold reaches.

  6. Specify the reputation threshold at which to contain applications.

    • Might Be Trusted

    • Unknown (default for the Security rule group)

    • Might Be Malicious (default for the Balanced rule group)

    • Most Likely Malicious (default for the Productivity rule group)

    • Known Malicious

    The Dynamic Application Containment reputation threshold must be above the block and clean thresholds. For example, if the block threshold is set to Known Malicious, the Dynamic Application Containment threshold must be set to Most Likely Malicious or above.

  7. Click Save.