DLP Getting Started helps you configure Trellix DLP product quickly and you can begin to protect your data immediately post-installation. With this feature, you can add license and shared location details, and create your first Trellix DLP rule and policy.
Perform the following steps to help get you started with Trellix DLP:
License — Enter the license keys to activate your Trellix DLP products. You must enter at least one license key — more if you have multiple Trellix DLP products. The licenses you enter determine which configuration options in ePO - On-prem are available to you.
Shared Location — Set up a shared location for storing a copy of evidence files, registered documents, and ignored text.
Note
The next four steps help you create your first Trellix DLP policy.
Classifications — Select the data classifications you want to protect. Trellix DLP identifies and tracks sensitive content based on these classifications. Trellix DLP provides a list of built-in classifications to start with.
Vectors — Enable the enforcement points for where you want to protect data, and grant exclusions for any safe domains.
These vectors need a Trellix DLP Endpoint or Trellix DLP Network Monitor or Trellix DLP Network Prevent license.
Email — Protect your confidential and sensitive information being sent through email. You can enter the email domains you want to exclude from this policy.
Web — Block web posts that violate a policy. You can enter the domains you want to exclude from this policy.
These vectors need a Trellix DLP Endpoint license.
Clipboard — Protect your assets being copied with the Windows clipboard.
Cloud — Protect your assets being synced to cloud applications.
Network share — Protect your assets when storing in network shares.
Printer — Protect your assets from being printed.
Removable storage — Protect your assets from being written to or from removable storage devices.
Screen capture — Protect your assets from being copied using a screen capture tool.
Enforcement Mode — Choose one of the three protection methods for your protection rule. Reporting incidents and storing evidence features are enabled on all enforcement modes, by default.
Stealth — Allows you to monitor the data and user actions on the network, before committing to block certain actions from users. Notifications aren't sent to users.
Coach — Allows you to monitor the data and user actions on the network and send built-in notifications to users, before committing to block certain actions from your end-users.
Block — Your policy is applied to the selected classifications and data vectors, and certain actions will be blocked from users. Notifications are sent to users.
Exceptions — Set up your Active Directory and specify the User Groups and Users you want to exclude from this policy.
You can change these configurations and add policies in DLP Getting Started later.
The DLP Getting Started feature in ePO - On-prem is as shown:
.png)