Data protection rules work with settings in the client configuration. Applicable for Trellix DLP Endpoint.
Tip
To optimize data protection rules, create client configurations to match the requirements of different rule sets.
The following table lists data protection rules, and the specific settings in the client configuration that affect them. In most cases, you can accept the default setting
Data protection rule | Client configuration page and settings |
|---|---|
Application File Access Protection | Content Tracking — Add or edit ignored processes |
Clipboard Protection |
|
Cloud Protection | Operational Mode and Modules: Select cloud protection handlers. |
Email Protection |
|
Network Communication Protection |
|
Network Share Protection | No settings |
Printer Protection |
|
Removable Storage Protection |
|
Screen Capture Protection |
|
Web Protection |
|
Removable storage protection advanced options details
The following sections describe the Windows Client Configuration → Operational Mode and Modules → Removable Storage Protection Advanced Options.
Protect TrueCrypt Local Disks Mounts
TrueCrypt encrypted virtual devices can be protected with TrueCrypt device rules, or with removable storage protection rules. TrueCrypt protection is not supported on Trellix DLP Endpoint for Mac.
Use a device rule if you want to block or monitor a TrueCrypt volume, or make it read-only.
Use a protection rule if you want content-aware protection of TrueCrypt volumes.
Note
Signatures are lost when content fingerprinted content is copied to TrueCrypt volumes because TrueCrypt volumes do not support extended file attributes. Use document properties, file encryption, or file type groups definitions in the classification definition to identify the content.
Portable Devices Handler (MTP)
Media Transfer Protocol (MTP) is used for transferring files and associated metadata from computers to mobile devices such as smartphones. MTP devices are not traditional removable devices because the device implements the file system, not the computer it is connected to. When the client is configured for MTP devices, the removable storage protection rule allows it to intercept MTP transfers and apply security policies. Only USB connections are currently supported.
The handler works with all data transfers made by Windows Explorer. It does not work with iOS devices, which use iTunes to manage the data transfers. One alternative strategy with iOS devices is to use a removable storage device rule to set the devices to read-only.
Advanced file copy protection intercepts Windows Explorer copy operations and allows the Trellix DLP Endpoint client to inspect the file at source before copying it to the removable device. It is enabled by default, and should only be disabled for troubleshooting.
Note
There are use cases where advanced copy protection does not apply. For example, a file opened by an application and saved to a removable device with Save As reverts to normal copy protection. The file is copied to the device, then inspected. If sensitive content is found, the file is immediately deleted.