The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

How Application Control works in a managed environment

Prev Next

Application Control creates a allow list of all authorized executable files. When you attempt to run an executable file that is not allowed, Application Control blocks its execution.

The allow list details authorized files and determines trusted or known files. In Enabled mode, only files that are present in the allow list are permitted to execute. All files in the allow list are protected and can't be changed or deleted.

  1. A user or application tries to execute a file where Application Control and Trellix Agent are installed.

  2. Solidcore Agent and Trellix Agent are installed on the managed endpoints. When a user or application tries to execute a file, Trellix Agent registers the attempt and sends the event to ePO - On-prem.

  3. Solidcore Agent checks if the executable is added to the inventory as allowed.

  4. If the executable is allowed, the file is permitted to run.

GUID-198D62F3-7EC1-437A-A992-E39E28198633-low.png