From the WebGUI, go to Objects > Security Profiles > Antivirus
Choose the appropriate profile (existing or new). Note: The "default' profile cannot be used for WildFire blocking
For each appropriate protocol, modify the action to "reset-both". Then, click OK. Note: The protocol limitation of POP3/IMAP is not appropriate to set to reset-both/drop action.
Go to Policies > Security. Select the appropriate security rule (edit existing or create new), then apply Antivirus profile from Step 2 (Go to the Actions tab and look for Profile Setting).
Commit
Additional Notes
WildFire is not meant to be a complete replacement of Endpoint Antivirus, rather a compliment function for day-1 malicious files.
Palo Alto Networks WildFire and Antivirus Protection Signature may encounter certain possible false positive due to its architecture and design nature.
There will be NO signature generated for WildFire test file, hence WildFire test file will NEVER be blocked, for more information please refer to this article.