As a mandatory security requirement, reset the default Shared Password in DLP Settings. The default shared password can affect both the Identification Code (challenge key) generated from the Diagnostic tool and the DLP Release Code (response key) generated from the console as the shared password is needed to generate these codes.
Resetting the shared password also prevents a compromise between two different ePO - On-prem servers or a compromise between two different policies on the same ePO - On-prem server.
Important
Make sure you reset the shared password before you apply any policy because the most recent shared password is made available to the endpoints or Trellix DLP Network when you apply a policy. For any existing policies, re-apply the policies whenever you update the shared password.
For example, if you duplicate the My Default DLP Policy in the Policy Catalog and send it out to endpoints, Trellix DLP Network, or Trellix DLP Discover servers, any ePO - On-prem server can bypass the policy. When you apply the bypass code from the other ePO - On-prem server, the response code allows the bypass. This happens because the challenge-response codes for My Default DLP Policy are the same across all ePO - On-prem installs. Any other ePO - On-prem administrator can bypass any DLP policy that is based on My Default DLP Policy. So, it is mandatory to reset the shared password before you apply the policy to prevent bypassing the systems not associated with the ePO - On-prem server you are working on.
To reset the Shared Password:
In ePO - On-prem, go to Menu → Data Protection → DLP Settings → General.
Update the Shared Password as needed and maintain the password in confidence.
You are prompted to save the changes when you try to navigate to a different page, click Yes to save the changes.