Set up Entra ID server and add Entra ID users

Prev Next

Trellix Data Loss Prevention – SaaS capabilities include native support for Microsoft Entra ID (formerly Azure AD). This integration allows IT administrators to configure DLP policies with user conditions, and exceptions based on cloud-based users and groups.

This feature provides a seamless and consistent policy enforcement experience. You can now extend your existing data protection, application control, and device control rules to all endpoints, whether they are synced to an on-premises Active Directory or directly to Microsoft Entra ID.

Before you begin:

You must have the following details from your Microsoft Azure portal to configure this feature:

  • Tenant ID (Directory ID)

  • Client ID (Application ID)

  • Client Secret (Application Password)

For more information, see KB article 000014786.

Register Active Directory server (Optional)

Note

Perform these steps if your environment manages users via both an on-premises directory and Entra ID. If your organization uses Microsoft Entra ID exclusively, you can skip this section.

  1. In ePO - SaaS, go to MenuConfigurationDirectory Service and click New Server.

  2. In the Description page, select Directory Services in Server type, then specify a unique name and optional description and click Next.

  3. In the Details page, select Active Directory from the Directory Services list.

  4. Enter the server name, username, and password for the domain from which you want to add users.

  5. Click Test Connection to verify the connection is successful, and click Save to complete the registration.

Register Microsoft Entra ID
  1. In ePO - SaaS, go to MenuConfigurationDirectory Service and click New Server.

  2. In the Description page, select Directory Services in Server type, then specify a unique name and optional description and click Next.

  3. In the Details page, select Microsoft Entra ID from the Directory Services list.

  4. Enter the Tenant GUID, Client ID, and Client ID Secret generated in Microsoft Azure portal.

    You can set up a schedule that updates the changes in the mapped domain or Active Directory container. You can schedule it hourly or daily based on your requirements.

  5. Click Test Connection to verify the connection to confirm the communication between your Entra ID and ePO - SaaS is successful, and click Save to complete the registration.

Synchronizing On-Premises and Cloud Identities

Synchronize your on-premises and cloud identities within Microsoft Entra ID to apply consistent DLP policies across your entire infrastructure.

  1. On your local domain controller or dedicated sync server, launch the Microsoft Entra Connect wizard.

  2. Click Configure on the Welcome page.

  3. Select Customize synchronization options and click Next.

  4. Enter your Microsoft Entra ID Global Admin (or Hybrid Identity Admin) credentials and click Next.

  5. Select your on-premises directory. If prompted, ensure your Forest is selected and click Next.

  6. Navigate to the Domain and OU filtering page, click Next if no changes are needed.

  7. On the Ready to configure page, ensure the Start the synchronization process when configuration completes checkbox is selected.

  8. Click Configure to begin the synchronization.

Verifying Synchronization Status - After the configuration completes, allow several minutes for the initial synchronization to populate. Confirm the connection and user status in the Microsoft Entra admin center:

  1. Check Global Status: Go to Microsoft Entra IDHybrid managementMicrosoft Entra Connect. Ensure the Sync status is displayed as Enabled.

  2. Verify Individual Users: Go to IdentityUsersAll users.

    • Locate a specific on-premises user.

    • Confirm the On-premises sync enabled attribute is set to Yes.

Add the Microsoft Entra ID server in DLP Policy Manager
  1. In ePO - SaaS, go to DLP Policy ManagerDefinitionsIdentity ServerMicrosoft Entra ID.

  2. Enter the Tenant GUID, Client ID, and Client ID Secret generated in Microsoft Azure portal.

  3. Test the credential and click Save.

Add the users in the End-User Group
  1. In ePO - SaaS, go to DLP Policy ManagerDefinitionsEnd-User Group.

  2. Click ActionsNew Item.

  3. Select either Add Users, or Add Groups.

  4. From the Look in dropdown, select users based on the server type:

    • For Microsoft Entra ID: Click Add Users or Add Groups, select your Entra ID server, and search for specific cloud identities.

    • For Active Directory: Click Add Users or Add Groups, select your LDAP server, and browse your local Organizational Unit (OU) structure.

  5. Click Save.

Use case: Applying User Definitions to DLP Rules

Goal: Apply unified DLP policies to protect sensitive information, regardless of whether the user is managed in Microsoft Entra ID or an on-premises directory.

Create a User-Based Protection Rule
  1. In the Trellix ePO console, go to MenuDLP Policy ManagerRule Sets.

  2. Open an existing rule set or click ActionsNew Rule Set.

  3. On the Data Protection tab, click ActionsNew Rule and select a protection vector. For example, Web Protection or Printing Protection.

  4. On the Condition tab:

    • Classification: Select the classification that matches your sensitive data. For example, a "Trellix" keyword category.

    • End-User Group: Select is any user (OR) and add the Entra ID or Active Directory user definitions you created.

      Note

      In environments managing both Microsoft Entra ID or an on-premises directory, add the user or group definitions from both sources to this field. This ensures the rule triggers consistently regardless of which directory service authenticates the user.

  5. On the Reaction tab:

    • Set the Action to Block.

    • (Optional) Select User Notification to alert the user when a block occurs.

    • Ensure Report Incident is enabled.

  6. Click Save and Apply the policy.

Once the policy is applied, the Trellix DLP agent enforces the rule based on the user's identity source.

Scenario: Web and Print Enforcement

  • Web Upload: A synchronized Entra ID or an on-premises Active Directory users attempts to upload a document containing the "Trellix" keyword to a personal Gmail account. The Web Protection rule blocks the upload.

  • Context: The protection vector (Web or Print), file name, and timestamp. The same user attempts to print the document. The Printing Protection rule identifies the unauthorized user/data combination and terminates the print job.

Every blocked attempt generates an incident in the DLP Incident Manager. Administrators can drill down into each event to view:

  • User Details: The specific Entra ID or AD account name.

  • Evidence: The exact content that triggered the classification.

  • Context: The protection vector (Web or Print), file name, and timestamp.