Set up Entra server and add Entra users

Prev Next

Trellix Data Loss Prevention capabilities include native support for Microsoft Entra ID (formerly Azure AD). This integration allows IT administrators to configure DLP policies with user conditions, and exceptions based on cloud-based users and groups.

This feature provides a seamless and consistent policy enforcement experience. You can now extend your existing data protection, application control, and device control rules to all endpoints, whether they are synced to an on-premises Active Directory or directly to Microsoft Entra ID.

Before you begin:

You must have the required details from your Microsoft Azure portal to configure this feature. This includes the Tenant ID (Directory ID), Client ID (Application ID), and Client Secret (Application Password). For More infomation, see KB article 000014557.

Task:
  1. Select MenuConfigurationRegistered Server and click New Server.

  2. In the Description page, select Directory Server in Server type, then specify a unique name and optional description and click Next.

  3. In the Details page, select Microsoft Entra ID from the Directory Server type list.

  4. Enter the Tenant GUID, Client ID, and Client ID Secret generated in Microsoft Azure portal.

  5. You can set up a schedule that updates the changes in the mapped domain or Active Directory container. You can schedule it hourly or daily based on your requirements.

  6. Click Test Connection to verify the connection to confirm the communication between your Entra ID and Trellix ePO On-premises is successful, and click Save to complete the registration.

Add the Microsoft Entra ID server in DLP Policy Manager:

  1. In Trellix ePO On-premises, go to DLP Policy ManagerDefinitionsIdentity ServerMicrosoft Entra ID.

  2. Enter the Tenant GUID, Client ID, and Client ID Secret generated in Microsoft Azure portal.

  3. Test the credential and click Save.

Add the users in the End-User Group:

  1. In Trellix ePO On-premises, go to DLP Policy ManagerDefinitionsEnd-User Group.

  2. Click ActionsNew Item.

  3. Select either Add Users or Add Groups.

  4. Look in Entra ID and add the users.

Use cases for Entra ID integration

  1. Use Case 1: DLP rules for Specific Entra ID Users and Groups

    This integration allows you to enforce DLP rules on specific users or groups defined in Microsoft Entra ID. By linking a DLP rule to a cloud-based group, you can ensure that only designated teams or individuals are subject to a specific policy. This provides targeted protection for sensitive data, ensuring that policies are applied consistently to the right people.

  2. Use Case 2: Exempting Specific Entra ID Users and Groups

    This integration allows you to configure exceptions to your DLPrules for specific users or groups managed in Microsoft Entra ID. By designating an Entra ID group as an exception, you can ensure that specific policies do not apply to certain individuals, such as IT administrators or legal teams, who require the flexibility to handle sensitive data without being blocked.

  3. Use Case 3: Designating Entra ID Users as Privileged

    This integration allows you to assign specific users from Microsoft Entra ID as privileged users. By adding a cloud-based user to the privileged users list, you can ensure they are exempt from all DLP rules and policies.

    To add privileged users

    1. Go to Policy CatalogData Loss PreventionDLP Policy.

    2. Create or edit a policy.

    3. Select Privileged Users

      Select either Add Users or Add Groups and select the users.

  4. Use Case 4: Manual Classification for Entra ID Users and Groups

    This integration enables administrators to provide manual classification options for specific users or groups from Microsoft Entra ID.