Configure the registered Azure server in ePO - On-prem for Microsoft Information Protection with Trellix DLP Network

Prev Next

Trellix DLP Network can integrate with Azure Microsoft Information Protection (MIP). Register an Azure server and create protection sensitivity labels so that you can protect them with your data protection policies.

  • Register a client application with Azure Active Directory. For more information, see KB91833.

  • Verify that you have permissions to configure an Azure server. In ePO - SaaS, select MenuUsers & Roles and verify that you have permissions for DLP Policy ManagerDLP Definitions.

  1. In ePO - On-prem, select MenuConfigurationRegistered Servers.

  2. Click New Server and enter the Server type as Azure Server.

  3. Enter a name for the server configuration, optional description, and click Next.

  4. In Azure authentication settings, enter the Rights Management Owner, who is configured as a superuser. Enter the Application (Client) ID, Directory (Tenant) ID, and Client Secret as defined in your Azure application registration details.

  5. Enter each Azure label name and Azure label ID as it appears in your Azure account.

  6. Click Save when you have completed the configuration.

Your Azure server and information protection labels are now saved. The files with these protection labels can now be tracked with classifications, encrypted with file encryption definition, and can be defined with a rule reaction for Email and Web Protection rules.

To select the Azure server that you registered:

  1. In Trellix ePO - On-prem, open Policy Catalog.

  2. Select DLP Appliance Management <version>, choose the General category, and open the policy that you want to edit.

  3. In Microsoft Information Protection (MIP) Decryption Service, select the registered Azure server.

    For MIP integration to work, the Microsoft URLs are resolved by Trellix DLP Network. Even when using a proxy, DNS of the external Microsoft URLs are resolved by Trellix DLP Network. The MIP SDK used by Trellix DLP Network first resolves Microsoft Azure addresses externally before connecting through the proxy for data. For more information, see KB91833.

  4. Click Save.