Reference Guide

Manage Policies
190
If Selected, no popup notifications of Advanced Threat
Prevention events display on the client computer.
Minimum Popup Notification
Level
High
High
Medium
Low
Severity level of events that result in popup notifications
that display o
n the client computer.
A setting of High allows only notifications of critical
events to display. A setting of Low displays all on
-screen
notifications for all events. Listed below are individual
examples of events that fall into the severity levels:
High
1) Protection status has changed. (Protected means that
the Advanced Threat Prevention service is running and
protecting the computer and needs no user or
administrator interaction.)
2) A threat is detected and policy is not set to
automatically address th
e threat.
Medium
1) Execution Control blocked a process from starting
because it was detected as a threat.
2) A threat is detected that has an associated mitigation
(for example, the threat was manually quarantined), so
the process has been terminated.
3) A process was blocked or terminated due to a memory
violation.
4) A memory violation was detected and no automatic
mitigation policy is in effect for that violation type.
Low
1) A file that was identified as a threat has been added
to the Global Safe List
or deleted from the file system.
2) A threat has been detected and automatically
quarantined.
3) A file has been identified as a threat but waived on
the computer.
4) The status of a current threat has changed (for
example, Threat to Quarantined, Quarantined to Waived,
or Waived to Quarantined).
Log Files Location <SYSTEM_DRIVE>:\ProgramData\DDP\Suite\
Logs
String
- File path
Specifies the location for the log files.
The default location is
<SYSTEM_DRIVE>:
\ProgramData\DDP\Suite\Logs.
Enable Activity Logging Selected
Selected
Not Selected
This policy is the "master policy" for all other Threat
Protection logging policies. If this policy is Not Selected,
no Threat Protection logging takes place, regardless of
other policy values.
A Selected value enables Thre
at Protection logging.
Advanced Threat Prevention
Threat Prevention policies are available at the Enterprise, Endpoint Group, and Endpoint levels.
Policy descriptions also display in tooltips in the Remote Management Console. In this table, master policies
are in bold font.
Policy Default Setting Description