Device control rules

Prev Next

Device control rules define the action taken when particular devices are used.

Note

Device control rules trigger ONLY when a device is plugged in. The notification sent (block, read-only, report incident) is based on the rule action. User actions on a plugged-in device don't cause more incidents to be logged or notifications to be sent.

Removable Storage Device Rule

Removable storage devices appear on the managed computer as drives. Use removable storage device rules to block use of removable devices, or to set them to read-only. They are supported on both Trellix DLP Endpoint for Windows and Trellix DLP Endpoint for Mac.

Removable storage device rules do not require a managed device class due to the difference in how the two types of device rules use device classes:

  • Plug-and-play device rules are triggered when the hardware device is plugged into the computer. Since the reaction is to a device driver, the device class must be managed for the device to be recognized.

  • Removable storage device rules are triggered when a new file system is mounted. When file system mount occurs, the Trellix DLP Endpoint software associates the drive letter with the specific hardware device and verifies the device properties. Since the reaction is to a file system operation, not a device driver, the device class does not need to be managed.

Note

Device rules have an Enforce on parameter that applies the rule to either Windows or macOS or both. Device templates used in device rules have an Applies to parameter that specifies either Windows devices or macOS devices. When selecting device templates, match the operating system in the template and the rule. The Trellix DLP Endpoint clients for both operating systems ignore properties that do not apply to that system. But you can’t save a rule that, for example, enforces on Windows only but contains macOS device templates.

Plug-and-play Device Rule

Use plug-and-play device rules to block or monitor plug-and-play devices. They are supported on both Trellix DLP Endpoint for Windows and Trellix DLP Endpoint for Mac. On macOS computers, support is for USB devices only.

A plug-and-play device is a device that can be added to the managed computer without any configuration or manual installation of DLLs and drivers.

For plug-and-play device rules to control Microsoft Windows hardware devices, the device classes specified in device templates used by the rule must be set to Managed status.

Important

Device rules have an Enforce on parameter that applies the rule to either Windows or macOS or both. Device templates used in device rules have an Applies to parameter that specifies either Windows devices or macOS devices. When selecting device templates, match the operating system in the template and the rule. The Trellix DLP Endpoint clients for both operating systems ignore properties that do not apply to that system, but you can’t save a rule that, for example, enforces on Windows only but contains macOS device templates.

Removable Storage File Access Rule

Use removable storage file access rules to block executables on plug-in devices from running. They are supported on Trellix DLP Endpoint for Windows.

Fixed Hard Drive Rule

Use fixed hard drive device rules to control hard drives attached to the computer and not marked by the operating system as removable storage. They are supported on Trellix DLP Endpoint for Windows.

Fixed hard drive rules include a drive definition with an action to block or make read-only, a user definition, and optional user notification. They do not protect the boot or system partition.

Citrix Virtual Apps and Desktops Device Rule

Use Citrix device rules to block Citrix devices mapped to shared desktop sessions. They are supported on Trellix DLP Endpoint for Windows.

Trellix DLP Endpoint software can block Citrix devices mapped to shared desktop sessions. Floppy disk, fixed, CD, removable, and network drives can all be blocked, as well as printers and clipboard redirection. You can assign the rule to specific users. For more information on how to create Citrix Virtual Apps and Desktops admin credentials see, Create Citrix Virtual Apps and Desktops admin credentials

TrueCrypt Device Rule

Use TrueCrypt device rules to block or monitor TrueCrypt virtual encryption devices, or set them to read-only. They are supported on Trellix DLP Endpoint for Windows.

TrueCrypt device rules are a subset of removable storage device rules. TrueCrypt encrypted virtual devices can be protected with TrueCrypt device rules or with removable storage protection rules.

  • Use a device rule if you want to block or monitor a TrueCrypt volume, or make it read-only.

  • Use a protection rule if you want content-aware protection of TrueCrypt volumes.

Note

Trellix DLP Endpoint client software treats all TrueCrypt mounts as removable storage, even when the TrueCrypt application is writing to the local disk.