The available reactions for a rule vary depending on the rule type.
All data protection rules are available for Trellix DLP Endpoint. Some data protection rules are available for Trellix DLP Network Prevent and Trellix DLP Network Monitor.
Trellix Device Control rules are available for Trellix DLP Endpoint and Trellix Device Control.
Some discovery rules are available for Trellix DLP Endpoint , some are available for Trellix DLP Discover.
Reaction | Applies to rules: | Result |
|---|---|---|
No Action | All | Allows the action. |
Block and return email to sender | Email Protection (Trellix DLP Network Prevent only) | Blocks the email message when there is a policy violation. The email is sent back to the sender as an attachment with a notification. You can customize the notification and specify as to why the email was sent back. |
Add header X-RCIS-Action | Email Protection (Trellix DLP Network Prevent only) | Adds an action value to the X-RCIS-Action header. |
Add Custom Header | Email Protection (Trellix DLP Network Prevent only) | Adds custom headers in the delivered email message. The custom header can report the number of rules and the cumulative score of all rules that violated a policy, or any other defined custom header. |
Apply RM Policy |
Not supported on Trellix DLP Endpoint for Mac | Applies a rights management (RM) policy to the file. The RM policy can be applied to Microsoft RMS on-premise, Azure RMS and Seclore. |
Block |
| Blocks the action. |
Classify file |
| Applies automatic classifications and embeds the classification Tag ID into the file format. |
Copy | Network Discovery | Copies the file to the specified UNC location. |
Create Content Fingerprint | Endpoint Discovery | Applies content fingerprinting to the file. |
Encrypt |
Not supported on Trellix DLP Endpoint for Mac. | Encrypts the file. Encryption options are Trellix FRP or StormShield Data Security encryption software. |
Modify anonymous share to login required | Network Discovery Box Protection | Removes anonymous sharing for the file. |
Move | Network Discovery | Moves the file to the specified UNC location. Allows creation of a placeholder file (optional) to notify the user that the file has been moved. The placeholder file is specified by selecting a user notification definition. |
Quarantine | Endpoint Discovery | Quarantines the file. |
Read-only | Device Control | Forces read-only access. |
Remove Automatic Classification | Network Discovery | Removes embedded classification ID from the file property. |
Report Incident | All | Generates an incident entry of the violation in DLP Incident Manager. |
Request justification | Data Protection | Produces a pop-up on the end-user computer. The user selects a justification (with optional user input) or selects an optional action. |
Show file in DLP Endpoint console | Endpoint Discovery | Displays Filename and Path in the endpoint console. Filename is a link to open the file, except when the file is quarantined. Path opens the folder where the file is located. |
Store original email as evidence |
Not supported on Trellix DLP Endpoint for Mac. | Stores the original message on the evidence share. Applies to Trellix DLP Endpoint and Trellix DLP Network Prevent email protection rules only.
|
Store original file as evidence |
| Saves the file for viewing through the DLP Incident Manager.
|
User notification |
| Sends a message to the endpoint to notify the user of the policy violation.
|
Reconfigure action rules for web content.
You must reconfigure Trellix DLP Network Prevent action rules for use on proxy servers.
Note
Proxy servers can only ALLOW or BLOCK web content.
Rules | Reactions | |||||||
|---|---|---|---|---|---|---|---|---|
No action | Apply RM Policy | Block | Encrypt | Report Incident | Request justification | Store original file (email) as evidence | User notification | |
Email protection | X | X | X | X | X | X | ||
Web protection | X | X | X | X | X | X | ||
Rules | Reactions | |||||||
|---|---|---|---|---|---|---|---|---|
No action | Apply RM Policy | Block | Encrypt | Report Incident | Request justification | Store original file (email) as evidence | User notification | |
Application File Access Protection | X | X | X | X | X | |||
Clipboard protection | X | X | X | X | X | X | ||
Cloud protection | X | X | X | X | X | X | X | X |
Email protection | X | X | X | X | X | X | ||
Network communication protection | X | X | X | X | X | |||
Network share protection | X | X | X | X | X | X | ||
Printer protection | X | X | X | X | X | X | ||
Removable storage protection | X | X | X | X | X | X | X | X |
Screen capture protection | X | X | X | X | X | |||
Web protection | X | X | X | X | X | X | ||
Rules | Reactions | ||||
|---|---|---|---|---|---|
No action | Block | Read-only | |||
Citrix Virtual Apps and Desktops device | X | ||||
Fixed hard drive | X | X | X | ||
Plug-and-play device | X | X | |||
Removable storage device | X | X | X | ||
Removable storage file access | X | X | |||
TrueCrypt device | X | X | X | ||
Rules | Reactions | |||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
No action | Encrypt | Apply RM policy | Quarantine | Create content fingerprint | Classify file | |||||||||
Endpoint file system | X | X | X | X | X | X | ||||||||
Endpoint mail storage protection | X | X | X | |||||||||||
Rules | Reactions | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
No action | Copy | Move | Apply RM policy | Store original file as evidence | Classify file as | Remove Automatic Classification | Modify anonymous share to login required | ||||||||||
Box protection | X | X ¹ | X ¹ | X | X | X | X | X ² | |||||||||
File server protection | X | X ¹ | X ¹ | X | X | X | X | ||||||||||
SharePoint protection | X | X ¹ | X ¹ ³ | X ³ | X | X | X | ||||||||||
Database protection | X | X | |||||||||||||||
¹ Box, File Server, and SharePoint scans support copying and moving files only to SMB/CIFS shares.
² Trellix DLP Discover can't prevent Box users from re-enabling external sharing on their files.
³ Supported for files attached to SharePoint lists or stored in document libraries. Not supported for SharePoint lists.