Retrieve and synchronize information from registered Active Directory servers

Prev Next

Trellix DLP Network - SaaS appliances can get users and group information from Active Directory servers that are registered with ePO - SaaS.

Make sure that the Active Directory servers are registered with ePO - SaaS.

User and groups details are used when evaluating the Sender information. The Trellix DLP Network - SaaS appliance can:

  • Connect to Active Directory servers.

  • Communicate with a registered Active Directory server over SSL.

  • Configure or set the daily synchronization time of appliances with Active Directory servers as synchronizing multiple appliances with Active Directory servers at the same time can overload the Active Directory servers.

  • Connect to Global Catalog ports instead of standard LDAP ports to retrieve user and group information when querying Active Directory.

    If you configured Active Directory to use Global Catalog ports, make sure that at least one of these attributes is replicated to the Global Catalog server from the domains in the forest:

    • proxyAddresses

    • mail

    If Trellix DLP Network - SaaS appliance needs to use NTLM or WINNT authentication for analyzing web protection rules, these LDAP attributes must also be replicated:

    • configurationNamingContext

    • netbiosname

    • msDS-PrincipalName

Messages are temporarily rejected with a 451 status code when both of these conditions are met:

  • Trellix DLP Network Prevent – SaaS uses rules that specify the sender is a member of a particular LDAP user group.

  • Trellix DLP Network Prevent – SaaS is not configured to receive information from the Active Directory server that contains the specified user group.

Events are sent to the Client Events page if synchronization with the Active Directory server or a query fails.

  1. In ePO - SaaS, open the Policy Catalog.

  2. Select the DLP Appliance Management product, choose the Users and groups category, and open the policy that you want to edit.

  3. In LDAP Servers, select at least one valid Active Directory server to enable synchronization configuration.

  4. In the Initiate daily synchronization at field, set the daily synchronization time. The default synchronization start time is set to 3 a.m.

    The synchronization of the appliance with Active Directory servers happens daily at the configured time.

  5. (Optional) Select and update the Delay synchronization start by up to (hours) field to configure the delay between the synchronization start of appliances. The default synchronization delay between appliances is set to two hours. You can configure the random delay synchronization start interval between 1–10 hours.

  6. Click Save.