Categorization of users in Trellix DLP – SaaS

Prev Next

Trellix DLP – SaaS has two categories of users: administrative users and end users.

Trellix DLP – SaaS accesses your Active Directories to create both types of user definitions. User definitions consist of users, user groups, or organizational units (OU), allowing the administrator to choose an appropriate model. Enterprises organized on an OU model can continue using that model, while others can use groups or individual users as needed.

Use names or security IDs (SID) to identify LDAP objects. SIDs are more secure, and permissions can be maintained even if accounts are renamed. On the other hand, they are stored in hexadecimal, and have to be decoded to convert them to a readable format.

User definitions are set up in DLP Policy Manager on the DefinitionsEnd-user Group page. Administrative users are assigned permissions in ePO - SaaS Users & Roles. Rules can apply to specific end users or groups by specifying them in the rule Conditions. More granularity can be obtained by exempting specific users or groups on the Exceptionstab of the rule definition. In addition, privileged users can be named in the Policy Catalog on theSettings page of the DLP Policy. Privileged users are only monitored if they trigger a rule. They are not blocked by any rule in the policy.