Trellix DLP integrates with several third-party software products.
Third-party products require different installation/registration steps to work with Trellix DLP.
Titus Classification Suite — install the SDK on each endpoint.
Boldon James Classifier — install the API on each endpoint.
Microsoft Rights Management Service (RMS), including RMS on-premises and Azure RMS, and FileSecure must be set up in Trellix ePO - On-prem Registered Servers.
Perform these preliminary steps first:
Set up the RM servers according to the Microsoft instructions and create users and policies. Obtain the URL and password for all servers - policy template, certification, and licensing.
If you are adding an Azure server for integration with Azure Information Protection, you need to first register a client application with Azure Active Directory. See KB91833 for details about registering a client application with Microsoft Azure.
Verify that you have permission to view, create, and edit Microsoft RMS servers. In Trellix ePO - On-prem, select Menu → User Management → Permission Sets and verify that you belong to a group that has the needed permissions in Registered Servers.
For Microsoft RMS on-premises only, install Active Directory Rights Management Services Client 2.1 build 1.0.2004.0 on each endpoint using RM services.
Note
The Apply RM command doesn't work without this version of the RM client.
For Azure RMS only, install Azure Information Protection 2.12.62.0 on each endpoint using RM services.
Note
The Apply RM command doesn't work without this version of the RM client.
In Trellix ePO - On-prem, select Menu → Registered Servers.
Click New Server.
The Registered Servers description page opens.
From the Server type drop-down list, select the type of server you want to configure: Microsoft RMS Server, or Azure Server.
Type a name for the server configuration, then click Next.
Enter the needed details. When you have entered the needed fields, click Test Connectivity to verify the data entered.
RMS settings also include a DLP enforcement settings section. The Local path to RMS template field is optional, but the URL fields for certification and licensing are needed unless you choose the AD auto-service discovery option.
Azure Server settings require:
A Rights management owner. This is the user that owns all files that are protected with the Azure RMS rule reaction.
Application (Client) ID, Directory (Tenant) ID, and Client Secret as defined in your Azure application registration details.
Azure Label ID and Azure Label Names as it appears in your Azure account. These labels can be selected for protection in rule reactions.
Note
Azure RMS is supported with Trellix DLP Endpoint 11.5 and onwards. To use Azure RMS configurations in policies, go to DLP Settings → General tab and from the create policy and definitions compatibility list, select 11.5.0.0 and later.
Click Save when you have completed the configuration.