Reference Guide

Manage Policies
190
If Selected, no popup notifications of Advanced Threat
Prevention events display on the client computer.
Minimum Popup Notification
Level
High
High
Medium
Low
Severity level of events that result in popup notifications
that display on the client computer.
A setting of High allows only notifications of critical
events to display. A setting of Low displays all on
-screen
notifica
tions for all events. Listed below are individual
examples of events that fall into the severity levels:
High
1) Protection status has changed. (Protected means that
the Advanced Threat Prevention service is running and
protecting the computer and needs no
user or
administrator interaction.)
2) A threat is detected and policy is not set to
automatically address the threat.
Medium
1) Execution Control blocked a process from starting
because it was detected as a threat.
2) A threat is detected that has an ass
ociated mitigation
(for example, the threat was manually quarantined), so
the process has been terminated.
3) A process was blocked or terminated due to a memory
violation.
4) A memory violation was detected and no automatic
mitigation policy is in effect
for that violation type.
Low
1) A file that was identified as a threat has been added
to the Global Safe List or deleted from the file system.
2) A threat has been detected and automatically
quarantined.
3) A file has been identified as a threat but waived
on
the computer.
4) The status of a current threat has changed (for
example, Threat to Quarantined, Quarantined to Waived,
or Waived to Quarantined).
Log Files Location <SYSTEM_DRIVE>:\ProgramData\DDP\Suite\
Logs
String
- File path
Specifies the location
for the log files.
The default location is
<SYSTEM_DRIVE>:
\ProgramData\DDP\Suite\Logs.
Enable Activity Logging Selected
Selected
Not Selected
This policy is the "master policy" for all other Threat
Protection logging policies. If this policy is Not Select
ed,
no Threat Protection logging takes place, regardless of
other policy values.
A Selected value enables Threat Protection logging.
Advanced Threat Prevention
Threat Prevention policies are available at the Enterprise, Endpoint Group, and Endpoint levels.
Policy descriptions also display in tooltips in the Remote Management Console. In this table, master policies
are in bold font.
Policy Default Setting Description