Classification scans detect classified or sensitive information.
A classification scan performs the following:
Action | When scanning a file repository | |
|---|---|---|
Analyzes the true file type based on the content of the file rather than the extension | x | |
Collects data on files or tables that match the configured classification | x | |
Restores the last access time of files scanned | x |
Classifications consist of definitions that can include keywords, dictionaries, text patterns, and document properties. These definitions help identify sensitive content that might require extra protection. By using the OLAP tools to view multidimensional patterns of these parameters, you can create optimized remediation scans.
Detecting encrypted files
File repository classification scans detect data with these encryption types:
Microsoft Purview Rights Management
Azure RMS encryption
Seclore Rights Management encryption
Unsupported encryption types or password protection
Not encrypted
Consider these points when scanning encrypted files:
Trellix DLP Discover – SaaS can only scan files encrypted with Microsoft RMS, but can't extract these files because Microsoft RMS is not currently supported. Other encrypted files can't be extracted, scanned, or matched to classifications.
Files encrypted with Adobe Primetime digital rights management (DRM) and Trellix® File and Removable Media Protection are detected as Not Encrypted.
Trellix DLP Discover – SaaS supports classification criteria options for Microsoft Purview Rights Management and Not Encrypted.