Use this page to select between Trellix Device Control and full Trellix DLP Endpoint, and to activate modules.
Option definitions
Category
Option
Definition
Operational Mode
Device control and full content protection
Standard setting for full Trellix DLP Endpoint. When selected, supports all data protection, device control, and discovery rules, as well as manual tagging.
Device control and content aware removable storage protection (without tag support)
Standard setting for Trellix Device Control. When selected, supports all device control rules plus removable storage data protection rules. Manual tagging is not supported.
Device control only
When selected, supports all device control rules. Content classification is not supported.
Data Protection Modules
Device Blocking
When selected, activates device rules that are configured in the policy.
Reporting Service
When selected, activates the reporting service. (See also settings on the Shared Storage and Evidence page.)
Evidence Copy Service
When selected, activates the evidence copy service. (See also settings on the Shared Storage and Evidence page.)
Manual Classification User Interface (Trellix DLP 11.1.100 and later)
When selected, activates DLP Finder integration. Default: selected.
Note
When this option is changed the user might need to log off the endpoint then log back on for it to take effect.
Browser API Integration
When selected, activates Content Analysis Connector SDK integration in enterprise browsers and the policies are applied to web protection and printer protection rules
Save As Application Handler
When selected, Save as from Microsoft Office, Notepad, Notepad ++, and Adobe to removable storage and network shares are blocked in the following scenarios:
Saving a New Classified File: The system blocks the Save As operation when a user attempts to create a new file containing classified data directly on a Network share or Removable Storage and saves it under a new name.
Saving an Existing Classified File: The system blocks the Save operation when a user attempts to add classified data to an existing file on a Network share or Removable Storage.
Note
You must also enable Advanced file copy protection for the Save As Application Handler to function seamlessly.
The Save as operation is optimized for Block reaction. For Monitor or other reactions, disable this handler.
Limitations:
The Save as operation for Microsoft Office application is not supported when the file is saved to the legacy (97-2003) format.
To disable Save as operation for a single application, you must disable the handler for all applications, apply the policy, and re-enable only the required applications.
Data Loss Prevention (DLP) > Trellix Data Loss Prevention 11.12.x Product Guide - June 2025 > Appendix > Policy Catalog settings > Mac OS X Client Configuration
Data Loss Prevention (DLP) > Trellix Data Loss Prevention 11.12.x Product Guide - June 2025 > Appendix > Policy Catalog settings > Windows Client Configuration