Client configuration support for data protection rules

Prev Next

Data protection rules work with settings in the client configuration. Applicable for Trellix DLP Endpoint.

Tip

To optimize data protection rules, create client configurations to match the requirements of different rule sets.

The following table lists data protection rules, and the specific settings in the client configuration that affect them. In most cases, you can accept the default setting

Data protection rules and client configuration settings

Data protection rule

Client configuration page and settings

Application File Access Protection

Content Tracking — Add or edit ignored processes

Clipboard Protection

  • Operational Mode and Modules — Activate the clipboard service.

  • Clipboard Protection — Add or edit ignored processes. Enable or disable the Microsoft Office Clipboard.

Note

Microsoft Office Clipboard is enabled by default. When enabled, you can't prevent copying from one Office application to another.

Cloud Protection

Operational Mode and Modules: Select cloud protection handlers.

Email Protection

  • Operational Mode and Modules — Activate available email software (Lotus Notes, Microsoft Outlook). For Microsoft Outlook, select the required add-ins.

    Note

    In systems where both Microsoft Exchange and Lotus Notes are available, email rules do not work if the outgoing mail server (SMTP) name is not configured for both.

  • Email Protection — Select Microsoft Outlook third-party add-in (Titus or Boldon James). Set the timeout strategy, caching, API, and user notification

Note

When the third-party add-in is installed and active, the Trellix DLP Endpoint Outlook add-in sets itself to bypass mode.

Network Communication Protection

  • Corporate connectivity — Add or edit corporate VPN servers

  • Operational Mode and Modules — Activate or deactivate the network communication driver (activated by default).

Network Share Protection

No settings

Printer Protection

  • Corporate connectivity — Add or edit corporate VPN servers

  • Operational Mode and Modules — Select printer application add-ins

  • Printing Protection — Add or edit ignored processes.

Note

Printer application add-ins can improve printer performance when using certain common applications. The add-ins are only installed when a printer protection rule is enabled on the managed computer.

Removable Storage Protection

  • Operational Mode and Modules — Activate advanced options.

  • Removable Storage Protection — Set the deletion mode. Normal mode deletes the file; aggressive mode makes the deleted file unrecoverable.

Screen Capture Protection

  • Operational Mode and Modules — Activate the screen capture service. The service consist of the application handler and the Print Screen key handler, which can be activated separately.

  • Screen Capture Protection — Add, edit, or delete screen capture applications protected by screen capture protection rules.

Note

Disabling the application handler, or the screen capture service, disables all the applications listed on the Screen Capture Protection page.

Web Protection

  • Operational Mode and Modules — Enable supported browsers for web protection.

  • Web Protection — Add or edit URLs ignore list, include or exclude web URL tags, enable HTTP GET request processing (disabled by default because they are resource-intensive), and set the web timeout strategy.



Removable storage protection advanced options details

The following sections describe the Windows Client ConfigurationOperational Mode and ModulesRemovable Storage Protection Advanced Options.

Protect TrueCrypt Local Disks Mounts

TrueCrypt encrypted virtual devices can be protected with TrueCrypt device rules, or with removable storage protection rules. TrueCrypt protection is not supported on Trellix DLP Endpoint for Mac.

  • Use a device rule if you want to block or monitor a TrueCrypt volume, or make it read-only.

  • Use a protection rule if you want content-aware protection of TrueCrypt volumes.

Note

Signatures are lost when content fingerprinted content is copied to TrueCrypt volumes because TrueCrypt volumes do not support extended file attributes. Use document properties, file encryption, or file type groups definitions in the classification definition to identify the content.

Portable Devices Handler (MTP)

Media Transfer Protocol (MTP) is used for transferring files and associated metadata from computers to mobile devices such as smartphones. MTP devices are not traditional removable devices because the device implements the file system, not the computer it is connected to. When the client is configured for MTP devices, the removable storage protection rule allows it to intercept MTP transfers and apply security policies. Only USB connections are currently supported.

The handler works with all data transfers made by Windows Explorer. It does not work with iOS devices, which use iTunes to manage the data transfers. One alternative strategy with iOS devices is to use a removable storage device rule to set the devices to read-only.

Advanced file copy protection intercepts Windows Explorer copy operations and allows the Trellix DLP Endpoint client to inspect the file at source before copying it to the removable device. It is enabled by default, and should only be disabled for troubleshooting.

Note

There are use cases where advanced copy protection does not apply. For example, a file opened by an application and saved to a removable device with Save As reverts to normal copy protection. The file is copied to the device, then inspected. If sensitive content is found, the file is immediately deleted.