All Products
Search
Document Center

Security Center:Manage an anti-ransomware policy

Last Updated:Sep 18, 2026

After an anti-ransomware policy is created, you can disable or enable the policy, modify the policy name, manage protected assets and protected directories, and other information. If you no longer need a policy for your business, you can delete the policy. This topic describes how to disable, enable, edit, and delete an anti-ransomware policy, and how to manage servers in an anti-ransomware policy.

Prerequisites

An anti-ransomware policy is created. For more information, see Create and manage anti-ransomware policies and agents.

Background information

An anti-ransomware policy takes effect on a server only when the policy is enabled and the Security Center agent on the server is in a normal state. If the agent status of your policy is abnormal, you must handle the exception in a timely manner. For more information, see What do I do if the status of an anti-ransomware policy is abnormal?.

Disable or enable an anti-ransomware policy

  1. Log on to Security Center console.

  2. In the left-side navigation pane, choose Protection Configuration > Host Protection > Anti-Ransomware. In the upper-left corner of the console, select the region where the asset to be protected is located: Chinese Mainland or Outside Chinese Mainland.

  3. On the Anti-ransomware for Servers tab, find the policy that you want to disable or enable, and turn on or off the policy status switch.

    • Disable a policy

      The first time an anti-ransomware policy performs a data backup, it consumes a large amount of CPU and memory resources on the server, which may affect your normal services. To prevent this, you can disable the policy by turning off the Policy Status switch. After the policy is disabled, running backup tasks are also stopped. You can re-enable the policy during off-peak hours to perform data backup tasks.

    • Enable a policy

      After an anti-ransomware policy is disabled, you can turn on the Policy Status switch to re-enable anti-ransomware protection for the servers in the policy.

Edit an anti-ransomware policy

  1. Log on to Security Center console.

  2. In the left-side navigation pane, choose Protection Configuration > Host Protection > Anti-Ransomware. In the upper-left corner of the console, select the region where the asset to be protected is located: Chinese Mainland or Outside Chinese Mainland.

  3. On the Anti-ransomware for Servers tab, find the policy that you want to edit, and click Edit in the Actions column.

  4. In the Edit Anti-ransomware Policy panel, modify the parameters of the anti-ransomware policy.

    For more information about the parameters, see Parameter descriptions.

  5. Click OK.

    Security Center runs data backup tasks based on the modified anti-ransomware policy.

Manage servers in an anti-ransomware policy

After an anti-ransomware policy is created, you can add or remove servers for the policy, and install or uninstall the anti-ransomware agent on your servers.

  1. Log on to Security Center console.

  2. In the left-side navigation pane, choose Protection Configuration > Host Protection > Anti-Ransomware. In the upper-left corner of the console, select the region where the asset to be protected is located: Chinese Mainland or Outside Chinese Mainland.

  3. On the Anti-ransomware for Servers tab, find the policy whose servers you want to manage, and click the Expand icon to expand the server list protected by the policy.

  4. Manage the servers to which the anti-ransomware policy applies.

    • Add servers to the policy

      You can add servers to the policy when you edit the policy. For detailed steps, see Edit an anti-ransomware policy.

      Note

      To ensure reasonable and effective use of your protection capacity, each server can be added to only one anti-ransomware policy. Each policy supports a maximum of 1,000 servers.

    • Remove servers from the policy

      Important

      After a server is removed from an anti-ransomware policy, Security Center stops providing anti-ransomware protection for the server and deletes all backup data of the server. Deleted backup data cannot be recovered. We recommend that you exercise caution when removing servers from a policy.

      If you no longer need anti-ransomware protection for a server, you can click Delete in the Actions column of the server, and then click OK in the confirmation dialog box. If you want to remove multiple servers from the same policy, select the servers and click Delete below the server list.

    • Install or uninstall the anti-ransomware agent

      If you want to install or uninstall the anti-ransomware agent on a server, you can click Install or Uninstall in the Actions column of the server. If you want to install or uninstall the anti-ransomware agent on multiple servers in the same policy, select the servers and click Install or Uninstallbelow the server list.

      Note

      After the anti-ransomware agent is uninstalled, Security Center does not delete the backup data within the data retention period. If the backup data exceeds the retention period, the backup data is deleted.

Manage backup data

When the anti-ransomware storage capacity is full or exceeds 80%, causing the policy to be automatically disabled, you can release storage space by using the following methods:

  • Delete historical backup versions

    On the Anti-ransomware page of the Security Center console, find the policy that you want to manage, and click the policy name to go to the details page. In the backup data list, select the historical backup versions that you no longer need and click Delete. After deletion, the backup version cannot be used for data recovery. Exercise caution when you delete backup data.

  • Reduce the scope of protected directories

    Edit the anti-ransomware policy to narrow the scope of protected directories and reduce the amount of data to be backed up. For detailed steps, see Edit an anti-ransomware policy.

  • Remove servers from the policy

    If a server no longer needs anti-ransomware protection, you can remove it from the policy. For detailed steps, see Manage servers in an anti-ransomware policy.

    Important

    After a server is removed, all backup data of the server is deleted and cannot be recovered. Exercise caution when you remove a server.

If the preceding methods still cannot meet your requirements, you can click the upgrade capacity link on the Anti-ransomware page of the Security Center console to expand the storage capacity.

Delete an anti-ransomware policy

Important

After an anti-ransomware policy is deleted, running backup tasks of the policy are terminated, and backup data of all servers covered by the policy is deleted. Deleted backup data cannot be recovered. We recommend that you exercise caution when you delete an anti-ransomware policy.

  1. Log on to Security Center console.

  2. In the left-side navigation pane, choose Protection Configuration > Host Protection > Anti-Ransomware. In the upper-left corner of the console, select the region where the asset to be protected is located: Chinese Mainland or Outside Chinese Mainland.

  3. On the Anti-ransomware for Servers tab, find the policy that you want to delete, and click Delete in the Actions column.

  4. In the confirmation dialog box, click OK.