When running object scan jobs, File Threat Protection uses the file operation interceptor. It is set to one of the following file interception modes (InterceptorProtectionMode
):
If the Audit value is selected, the solution enables the notification mode of File Threat Protection.
The configured component settings are applied when File Threat Protection is activated in runtime policies. These settings are the same for all created runtime policies. If the applicable runtime policy is set to audit mode and InterceptorProtectionMode
in File Threat Protection is set to Enforce, the solution blocks the files.