Responding to access point violations Published on Sep 14, 2026 1 minute(s) read Focus Listen
Print
Copy page Copy as Markdown for LLMs View as Markdown View the page as plain text
Open in ChatGPT Ask ChatGPT about this page Open in Claude Ask Claude about this page Prev Next When a system access point is violated, the action depends on how the rule is configured.
If the rule was configured to:
Take these steps:
Review the log file to determine which system access points were violated and which rules detected the violations.
Configure the Access Protection rules to allow users access to legitimate items and prevent users from accessing protected items.
Use these scenarios to decide which action to take as a response.
Detection type
Scenarios
Unwanted processes
If the rule reported the violation in the log file, but didn't block the violation, select Block for the rule.
If the rule blocked the violation, but didn't report the violation in the log file, select Report for the rule.
If the rule blocked the violation and reported it in the log file, no action is necessary.
If you find an unwanted process that wasn't detected, edit the rule to include it as blocked.
Legitimate processes
If the rule reported the violation in the log file, but didn't block the violation, deselect Report for the rule.
If the rule blocked the violation and reported it in the log file, edit the rule to exclude the legitimate process from being blocked.
Was this article helpful?
Yes No