Use this page for configuring access protection and other settings for the Trellix DLP Endpoint for Windows client.
You can access the Advanced Configuration page from Menu → Policy → Policy Catalog → Data Loss Prevention <version> → Windows → edit a policy → Settings → Advanced Configuration.
Category | Option | Definition |
|---|---|---|
Endpoint Settings | Delay the start of DLP client | Time interval between logging on and client up . In rare cases, the endpoint software needs more time to load. Reset this default as recommended by Support. Changing this setting requires an endpoint restart. Default: Run immediately |
Run DLP client in Safe Mode | When enabled, activates endpoint protection when the computer starts in Safe Mode. Default: Disabled | |
Maximum DLP client memory used (MB) | Limits the Trellix DLP Endpoint client memory. If a process pushes the client software over the set limit, it closes and restarts. Range: 150–500 | |
Access Protection Settings | DLP access protection | When enabled, activates the DLP data access protection features. Default: Enabled in both Trellix Device Control and full Trellix DLP Endpoint. |
Show challenge response on upgrade | When enabled, activates the challenge/response pop-up window on upgrade. Default: Enabled | |
Show challenge response on uninstall | When enabled, activates the challenge/response pop-up window on uninstall. Default: Enabled | |
Run DLP client watch dog | When enabled, monitors the endpoint processes and restarts them if closed. Changing this setting requires a client computer restart. Default: Enabled | |
Run DLP client service watch dog | When enabled, monitors the watch dog and restarts it if it closes. Changing this setting requires a client computer restart. Default: Enabled | |
Agent Bypass | Stop agent bypass immediately when a new client configuration is loaded by Trellix DLP Endpoint client. | When enabled, stops the agent bypass when the client configuration is updated. Default: Deselected (bypass continues to timeout) |
Advanced Pattern Settings | Use default agent behavior for regex | When enabled, activates regex case sensitivity. To apply case sensitivity with any regular expression, the regex pattern must begin with ?i. You can also edit the existing regex pattern and append ?i at the beginning of the pattern. |
Network Shares | Manually Resolve DFS | When enabled, you can manually resolve network share paths of all the child nodes of DFS shares and enter them individually in the network definitions. When disabled, Trellix DLP Endpoint resolves all child nodes' share paths of the DFS share paths mentioned in the network definition. |
Advanced Parameters | Allows you to enable or disable experimental features and specify parameter values directly from the Trellix ePO console. This functionality eliminates the need to restart endpoint services when modifying or applying feature parameter values. | |