Trellix DLP Endpoint - SaaS can integrate with Microsoft Azure rights management to apply protections to files that match rule classifications and to encrypt .
Important
When using Azure RMS, you must install Azure Information Protection 2.6.111 on each endpoint using RM services. The Apply RM command does not work without this version of the RM client.
You can apply an RM policy reaction to these data protection and discovery rules:
Cloud protection
Endpoint file system discovery
Removable storage protection
Network share protection
Trellix DLP Endpoint - SaaS can recognize RM protected files by adding a file encryption property to either content classification or content fingerprinting criteria. These files can be included or excluded from the classification.
How Trellix DLP Endpoint - SaaS works with rights management
Trellix DLP Endpoint - SaaS follows a workflow to apply RM policies to files.
Create and apply a data protection or discovery rule with a reaction to apply RM policy.
When a file triggers the rule, Trellix DLP Endpoint - SaaS encrypts the file using the selected RM server labels.
The RM server applies protection based on the specified policy, such as encrypting the file, limiting the users allowed to access or decrypt the file, limiting the users allowed to read or access labeled files, and limiting the conditions in which the file can be accessed.
The RM server sends the file back to the source with the applied protections.
If you have configured a classification for the file, Trellix DLP Endpoint - SaaS can monitor the file.