Support for Trellix DLP Classifications is available to customers of both Trellix DLP and Skyhigh Security Cloud.
Note
For instructions on enabling the Skyhigh Security Cloud integration feature and configuring the server connections, see the Trellix DLP Endpoint 11.x.x Installation Guide.
Skyhigh Security Cloud is a cloud access security broker (CASB) that can detect user behavior and apply protection rules in the cloud.
You can apply policies created in Trellix DLP to cloud content with Skyhigh Security Cloud in two ways.
To enforce consistent classification behavior in on-premises and cloud policies, apply Trellix DLP Classifications to Skyhigh Security Cloud policies
Tip
Classifications can be applied to protect content uploaded to selected cloud services such as Box Sync or Microsoft OneDrive.
To enforce consistent Email Protection rule behavior for on-premises and cloud email, apply the Trellix DLP policy directly.
Tip
Email Protection rules that include the Enforce on Skyhigh Security Cloud DLP option extend support to supported cloud email services such as Microsoft Exchange Online.
The incidents reported in Skyhigh Security Cloud can be used for analysis and reporting in the DLP Incident Manager, giving a merged view of DLP incidents occurring in both on-premises and cloud enforcement points.
The Trellix DLP administrator creates classification definitions, and adds them to a policy.
The Trellix DLP administrator applies the Trellix DLP policy to Skyhigh Security Cloud.
The Skyhigh Security Cloud administrator enables using DLP classifications in the Skyhigh Security Cloud UI and adds DLP classifications to Skyhigh Security Cloud protection rules.
The Skyhigh Security Cloud protection rules are applied to content in the customer's protected cloud service accounts.
.png)
Use the following workflow to apply a Skyhigh Security Cloud policy to Exchange Online:
The Trellix DLP administrator creates a DLP policy with email rules and associated Skyhigh Security Cloud reactions
The Trellix DLP administrator applies the Trellix DLP policy to Skyhigh Security Cloud.
The Skyhigh Security Cloud administrator enables DLP policy for Exchange Online within the Skyhigh Security Cloud UI.
The DLP Policy is applied to Exchange Online content in the customers connected account.
.png)
How Skyhigh Security Cloud incidents are reported in Trellix DLP
Trellix DLP pulls incidents periodically from Skyhigh Security Cloud and displays them in the DLP Incident Manager. Some of the Skyhigh Security Cloud incident properties have different names than the incident properties in DLP Incident Manager. These incident properties are mapped to their equivalent terms in DLP Incident Manager to guarantee consistency across all incident reports, regardless of their source.
To enable Evidence Copy from Skyhigh Security Cloud, go to Policy Settings → Send evidence files to ePO Enable. Evidence files are downloaded by Trellix DLP and copied to the on-premises DLP evidence storage.
Evidence files that are pulled from Skyhigh Security Cloud can be opened via the Trellix DLP Incident Manager, with hit highlighting also displayed.
Note
Evidence Copy is only supported for Skyhigh Security Cloud Classification Policy incidents.
For more detailed information about how each Skyhigh Security Cloud incident property is mapped to the equivalent term in DLP Incident Manager see KB90962.