As a mandatory security requirement, reset the default Shared Password in DLP Settings. The default shared password can affect both the Identification Code (challenge key) generated from the Diagnostic tool and the DLP Release Code (response key) generated from the console as the shared password is needed to generate these codes.
Resetting the shared password also prevents a compromise between two different ePO - SaaS servers or a compromise between two different policies on the same ePO - SaaS server. You can follow these steps before applying the My Default DLP Policy:
Reset the shared password as needed.
Duplicate or create the My Default DLP Policy and apply the newly created policy.
For example, if you duplicate the My Default DLP Policy in the Policy Catalog and send it out to endpoints, Trellix DLP – SaaS Appliances, or Trellix DLP Discover – SaaS servers, any ePO - SaaS server can bypass the policy. When you apply the bypass code from the other ePO - SaaS server, the response code allows the bypass. This happens because the challenge-response codes for My Default DLP Policy are the same across all ePO - SaaS installs. Any other ePO - SaaS administrator can bypass any DLP policy that is based on My Default DLP Policy. So, it is mandatory to reset the shared password or create a policy that is anything other than My Default DLP Policy to prevent bypassing the systems not associated with the ePO - SaaS server you are working on.
To reset the Shared Password:
In ePO - SaaS, go to Menu → Data Protection → DLP Settings → General.
Update the Shared Password as needed and maintain the password in confidence.
You are prompted to save the changes when you try to navigate to a different page, click Yes to save the changes.