This release is applicable for on-premises installations. The Trellix DLP Endpoint for Windows 11.14.0 release includes new and enhanced features, and resolved issues.
Release details
Release date - December 9, 2025
Release builds:
Trellix Data Loss Prevention Endpoint client build 11.14.0.4142
Trellix Data Loss Prevention Endpoint OCR build 1.0.0.35
Note
Trellix DLP Endpoint 11.14.0.4142 requires Trellix DLP 11.13.0.45 extension. Trellix DLP Endpoint client software is not compatible with earlier versions of Trellix DLP extensions.
For the specific build numbers, see Product release information in KB68147.
Supported upgrade path
Upgrade from... | To |
|---|---|
11.10.100 | 11.14.0 |
11.10.200 | 11.14.0 |
11.10.300 | 11.14.0 |
11.11.0 | 11.14.0 |
11.11.1 | 11.14.0 |
11.11.2 | 11.14.0 |
11.11.3 | 11.14.0 |
11.12.0 | 11.14.0 |
11.12.1 | 11.14.0 |
Updated platform, environment, or operating system support
For additional information on supported platforms, environments, and operating systems, see KB68147.
As part of our ongoing efforts to enhance security, we have upgraded the KeyView version to 25.3.
New or changed features
This release introduces new features or improves existing features:
AI Data Risk Dashboard - This release introduces the Trellix AI Data Risk Dashboard to monitor, identify, and mitigate the risks associated with the unmanaged use of Generative AI platforms (Shadow AI) within your organization.
Leveraging your existing DLP Endpoint policies, this dashboard provides actionable, real-time insights into sensitive data being shared across key exfiltration vectors, including file uploads, copy/paste operations, and clipboard sharing with web-based AI prompts.
For more information on the key features and configuration, see Managing Incidents using AI Data Risk Dashboard in the Trellix DLP Product Guide.
Microsoft Entra ID Integration for DLP Policies - This release enhances our Data Loss Prevention capabilities by introducing native support for Microsoft Entra ID (formerly Azure AD). This integration allows IT administrators to configure DLP policies with user conditions and exceptions based on users and groups defined within Microsoft EntraID.
This feature provides a consistent policy enforcement experience. You can now extend your existing data protection, application control, and device control rules to all endpoints, whether they are synced to an on-premises Active Directory or directly to Microsoft Entra ID.
For more information on the configuration steps, see Set up Entra server and add Entra users in the Trellix DLP Product Guide.
IPv6 support - Trellix DLP Endpoint now supports IPv6, enhancing network address and communication capabilities. This feature ensures the product can seamlessly operate within modern network architectures.
Features supported:
Full IPv6 compatibility for all internal and external communications.
Compatibility for all current integrations with IPv6 networks.
Support for IPv6-only, IPv4-only, and dual-stack configurations.
Added crawling support for IPv6-based CSIF/SMB network paths.
Seamless Web Browser Content Inspection API - This release enhances DLP inspection capabilities using a Content Analysis Connector SDK for Microsoft Edge, Mozilla Firefox, and Island Browsers.
This integration enables Trellix DLP Agent to perform essential inspection tasks such as file upload and printer protection without injecting DLLs into the browser process. This out-of-process methodology improves browser stability and reduces potential application conflicts.
For more information on the advantages and configuration of integrating with browsers, see the Browser API Integration with enterprise browsers in the Trellix DLP Product Guide.
Advanced Visual Labeling for Microsoft Office and Outlook - This release enhances the visual labeling capabilities within Microsoft Office and Outlook, providing administrators with options for customization, clarity, and policy adherence.
Key Enhancements:
Customizable Label Styling: Gain full control over the appearance of classification labels, including:
Border Styling: Apply borders to classification labels for greater visual prominence.
Font Customization: Define bold font, size, and color options for improved readability.
Encapsulation: Enclose labels with customizable characters such as braces and brackets for contextual separation.
Custom color configuration for Microsoft Outlook labels.
Dual Classification Support: Simultaneously apply secondary classification labels for applicable Microsoft office applications.
Environment Variable Support for Network Share Protection - This release introduces native support for environment variables within Network Share Protection rules, enabling the creation of dynamic, user-specific path conditions.
Previously, NSP rules supported only explicit, static folder paths. This limitation increased policy complexity in large enterprise environments with dynamic paths such as those using %username% or %computername%, forcing administrators to create numerous policy permutations or rely on overly broad, less accurate rules.
With this enhancement, Trellix DLP Endpoint can now dynamically evaluate paths at the endpoint level, significantly reducing policy complexity and improving scalability. This support allows precise policy enforcement against dynamic, user-specific network share locations, effectively minimizing false positives.
Block Reaction for Network Share Protection Rules - This release introduces the ability to configure a Block reaction for Network Share Protection rules.
Resolved issues
This update resolves the following issues.
For the DLP Extension related resolved issues, see the Trellix Data Loss Prevention Extension Release Notes.
Reference | Resolution |
|---|---|
DLPW-9275, DLPW-10162 | Fixed an issue where the Save As operation was not blocked when a user opened an empty file directly on a Network share or Removable Storage, added classified data, and attempted to save it under a new file name. For more information, see Operational Mode and Modules in the Trellix DLP Product Guide. |
DLPW-10088 | Fixed an issue where Trellix DLP Endpoint failed to prevent the transfer of classified content to external devices, such as through the Save as function in applications like Adobe Reader. |
DLPW-10120 | Fixed an issue where the Printer Protection rule failed to block the printing of Non-Microsoft office files that were protected with a Titus classification. |
DLPW-14261 | Fixed an issue where Printer Protection rules failed to detect and block keywords in the Thai language, even though the same keywords were correctly detected by Web Protection rules. |
DLPW-15318 | Fixed an issue where Printer Protection rules failed to detect keywords within smart quotes (“ ”), or straight quotes (" "). |
DLPW-16241 | Fixed a resolution issue to correctly accept input up to 39 characters in the Release Code field. |
DLPW-16972 | Fixed an issue where manual classification labels or captions failed to appear as the first line of text when replying to an email in the Outlook Reading Pane. This issue occurred even when Force end-user classification and Classify email before sending were enabled. |
DLPW-17196 | Fixed a critical issue where emails classified for encryption using a method like ZedMail were sent in clear text instead of being encrypted. |
DLPW-17246 | Fixed an issue where Printer Protection rules failed to trigger when printing sensitive content from Adobe Acrobat Reader on Windows 11. |
DLPW-18462 | Fixed a conflict that caused Microsoft Edge to become unresponsive and display a blank page when accessing the M365 portal URL, specifically when the Trellix DLP agent and IP-Guard software were running concurrently. |
DLPW-18935 | Fixed an issue where users added to the exception list for Removable Media and Plug and Play device policies were incorrectly being blocked from accessing the device. |
DLPW-18995 | Fixed several issue where the DLP Optical Character Recognition (OCR) exhibited inconsistent behavior, resulting in failures in Printer Protection for image files, inaccurate match string counts in incidents, and a failure to enforce blocking policies for .BMP files. |
DLPW-19832 | Fixed a false positive issue where unencrypted .CSV files were incorrectly detected and classified under the Unsupported encryption types or password protected file definition. |
Known issues
For a list of current known issues, see: Trellix Data Loss Prevention 11.x.x Known Issues (KB89301).