Skip to main content

Policy Configuration

A Threat Prevention policy has many elements that define the objects and events it monitors or blocks, where it looks in networks, and when it is active. These policy attributes are organized into the following major components:

Each major component has its own tabbed view. A policy requires at least the General tab and Event Type tab to be configured before it properly functions. The Actions tab is optional.

The Recent Events Tab displays information on the events your policy has recently monitored or blocked. You can also view these events on the Investigate Interface.

You can create, edit, delete, and enable policies through PowerShell API integration without opening the Administration Console. See the PowerShell API Integration topic for additional information.