If an agent detects a threat on a target machine, there are a number of different actions you can configure it to take. You use the Threat Actions tab to specify what an agent should do if it encounters a particular category of threat.
Note: The threat actions defined here will be performed whenever a threat defined on either the Threat Tasks tab or the Active Protection tab is detected by an agent.

This tab enables you to define exactly what action you want an agent to perform if it detects a threat on a target machine. By default an agent will quarantine all threats that are categorized as dialers, malware, viruses, or worms, and it will report on all other threats. You can, however, customize what actions to take for each threat category. You simply:
Select a threat category or sub-category in the threat list.
Select the action you want to take if an agent detects the threat on a target machine.
1. Select a threat to apply an action |
This box lists the different categories of threats that can be detected by VMware vCenter Protect Agent . You can expand each category to display sub-categories of threats. A description for each threat category is provided in the Threat Description box. |
2. Select an action for the threat |
For the threat currently selected in the threat category list, specify what action you want the agent to perform:
Recommended Best Practice: You might consider initially quarantining everything. This provides the most protection while still allowing you to rollback files you deem safe. After monitoring the results for a week or two you should get a good feel for what settings make the best sense for your organization. If you see that something is routinely getting quarantined that you determine is actually safe (for example, cookies for frequently-visited websites), feel free to use a less restrictive setting for that category. |
Default Action for All Threats |
To apply a new default setting to all existing categories, click this button and then select the new action. A confirmation dialog will be displayed asking if you want to apply the new setting to all categories. |
3. Quarantine |
You can configure the following quarantine settings on each agent.
|
Threat Description
|
Provides a detailed description of the threat currently selected in the threat category list. |
Save and Update Agents |
Saves all changes to the policy file and stores it on the console. Also updates any agent machines that are currently assigned this policy as follows:
The Agent Policy Editor will be closed. |
Cancel |
Indicates you want to exit the Agent Policy Editor without saving your most recent changes. A "Do you want to save your changes?" prompt will appear that gives you a second chance to save your changes. If you click Yes the policy will be saved and the associated agents updated (the same as Save and Update Agents). If you click No the Agent Policy Editor will be closed without saving your changes. |