Prerequisite: Browser API Integration with enterprise browsers

Prev Next

Trellix DLP Endpoint Trellix Data Loss Prevention Endpoint – SaaS can now integrate with Chrome Enterprise, Microsoft Edge for Business, Firefox, and Island browsers using the Content Analysis Connector SDK. This improves performance, security and enhanced browsing experience.

What are we trying to solve?

Security updates and architectural changes in enterprise browsers, such as network sandboxing can cause Trellix DLP Endpoint Trellix Data Loss Prevention Endpoint – SaaS to crash and not display the URLs in the DLP Incident Manager page. Legacy integration method requires frequent browser extension updates to maintain compatibility with browser security changes. The interval between the update of browsers and the update of compatible extensions leaves the protections vulnerable.

In addition, printing from the browser has its own challenges, including the inability to block pdf printing and the inability to block printing based on file name or extension.

Supported protection vectors for Browser API Integration

The Content Analysis Connector SDK supports the following real-time data protection capabilities across the following operational vectors:

  • File upload protection: Monitors and blocks unauthorized file actions when users upload classified documents to webforms or artificial intelligence web agents.

  • Printer protection: Intercepts and blocks browser-based print tasks that contain classified content or forbidden keywords.

  • Drag and drop monitoring: Intercepts sensitive files or data transferred through drag-and-drop actions.

  • Destination URL tracking: Captures complete matched URL metadata within incident reports when used alongside web extensions.

Advantages of enabling this integration

This API-based integration offers several advantages over the traditional integration methods, including:

Note

Trellix recommends Content analysis connector SDK as the preferred method for web protection.

  • Integrates seamlessly with enterprise browsers to ensure users remain protected during browser updates.

  • API-based approaches provide efficient and high-performance data inspection and prevention.

  • Inspect and protects data in real-time, reducing the risk of a data leak and ensures compliance with PCI, PII, HIPPA and several other regulations.

  • Scalable integration ensures continued protection during browser upgrades while reducing compatibility issues, streamlining the implementation process for both IT and DLP administrators.

  • Requires zero Dynamic-Link Library (DLL) injection hence it avoids browser crashes and application conflicts.

For more information, see KB000015107.

Limitations

  • Web Application Control (WAC) is not supported for the Island browser because WAC relies on Chromium extensions.

  • Texts manually typed in the text box cannot be monitored or blocked using the Content Analysis Connector SDK.

Clear legacy beta settings

If you previously installed a Beta version of the SDK, you must remove the following settings before utilizing the Content Analysis Connector (CAC) SDK feature:

  • Delete all Advanced Parameters associated with the browser SDK in Windows Client ConfigurationPolicy CatalogAdvanced Configuration.

  • Delete any existing registry settings specifically configured for the Microsoft Edge SDK.

  • Delete the policies.json file associated with Mozilla Firefox SDK.

Policy configuration prerequisite

  • Web Handler Maintenance: You must keep the Web Handler active. The Web Handler provides the DLL hooking functionality required for proper rule enforcement. Administrators can temporarily disable this option for troubleshooting scenarios.

  • Web Extensions: Chromium-based browsers, such as Google Chrome and Microsoft Edge, require web extensions to monitor URLs and text submissions actively.

  • Drag and drop option: You must disable drag and drop feature within your policy configuration to allow users to perform drag-and-drop actions.

Browser prerequisite

To utilize the Content Analysis Connector (CAC) SDK feature, ensure the following minimum browser versions are installed:

  • Google Chrome Enterprise: Version 138.0.7204.184 or later.

  • Microsoft Edge for Business: Version 137 or later.

  • Mozilla Firefox: Version 142 or later.

  • Mozilla Firefox ESR: Version 140.2.0 or later.

  • Island Browser: Contact the Island Support Team for the specific supported version.

Configure Chrome browser cloud management

Perform these steps to configure Chrome browser cloud management:

  1. Use the existing Google admin account or sign up for Chrome Browser Cloud Management.

  2. In the Google Chrome admin console, select Directory | Organizational Unit and click + to create a container for the devices you wish to integrate.

  3. In the Google Chrome admin console, select Chrome browser | Managed browser and select the container created in step 2 and click Enroll.

  4. Copy the token or download the .REG file and run it on your Endpoint using GPO or Intune and relaunch the Google Chrome browser.

  5. In the Google Chrome admin console, select Devices | Chrome | Settings | Users & browser settings and search for Chrome Enterprise connectors

  6. Select Trellix from the dropdown menu for Upload content analysis, Bulk text content analysis, and Print content analysis fields and click Save.

  7. Open Google Chrome, browse chrome://policy and verify if the following policies are displayed:

    • OnBulkDataEntryEnterpriseConnector

    • OnFileAttachedEnterpriseConnector

    • OnPrintEnterpriseConnector

For more information, see Chrome Browser Cloud Management.

Configure web browser content inspection API for Microsoft Edge for Business

You can configure the Web Browser Content Inspection SDK for Microsoft Edge using two options:

  1. Using Edge Management Service: You can manually configure Microsoft Edge Business using the Microsoft Edge management service. For more information, see Set up a Trellix DLP Connector.

  2. Programmatic Automation: For a seamless experience, this configuration is programmatically automated in Trellix DLP Endpoint Trellix Data Loss Prevention Endpoint – SaaS. This is enabled by selecting the option Browser API integration for Microsoft Edge for Business.

Configure web browser content inspection API for Mozilla FireFox and Island Browser

For a seamless experience, this configuration is programmatically automated in Trellix Data Loss Prevention Endpoint – SaaS Trellix DLP Endpoint. This is enabled by selecting the option Browser API integration for Firefox and Island.

Enable Content Analysis Connector SDK in Trellix DLP Endpoint Trellix Data Loss Prevention Endpoint – SaaS

Perform these steps to enable Content Analysis Connector SDK integration in enterprise browsers:

  1. In the Policy Catalog, open the current Windows Client Configuration. Select SettingsOperational Modes and Modules.

  2. Enable File upload protection for or Printer Protection for.

    Choose the browsers you want to integrate.

  3. Click Apply policy.

    Policies are applied to web protection and printer protection rules.