Trellix Data Loss Prevention – SaaS 2408 Release Notes

Prev Next

Trellix DLP – SaaS 2408 is supported on a new platform and includes new features, and resolved issues.

Product rebranding changes

This is solely for informational purposes, there is no action required. As part of this Trellix Data Loss Prevention extension release, the following product names have been changed on the DLP Settings page and DLP Policy Manager page:

  • Trellix Data Loss Prevention Endpoint - SaaS is renamed as Trellix Data Loss Prevention Endpoint Complete - SaaS.

  • Trellix DLP Prevent - SaaS Software is renamed as Trellix Data Loss Prevention Network Prevent - SaaS.

  • Trellix DLP Monitor - SaaS Software is renamed as Trellix Data Loss Prevention Network Monitor - SaaS.

  • Trellix DLP Discover - SaaS is renamed as Trellix Data Loss Prevention Discover - SaaS.

Trellix DLP – SaaS release information

Release Date - September 5, 2024 (Republished to support Trellix DLP Network Appliances)

This release of Trellix DLP – SaaS is identified as version 2408, where the version identifier follows a YYMM convention. Trellix DLP – SaaS 2408 release, which includes minor enhancements and resolved issues.

Trellix DLP – SaaS is a unified solution and includes these products:

  • Trellix Device Control – SaaS

  • Trellix DLP Discover – SaaS

  • Trellix DLP Endpoint for Windows - SaaS

  • Trellix DLP Endpoint for macOS - SaaS

  • Trellix DLP Network Monitor – SaaS

  • Trellix DLP Network Prevent – SaaS

Trellix DLP – SaaS provides support for the following versions of Trellix DLP

Product

Supported versions

Trellix DLP Discover

11.10.600.23

Trellix DLP Endpoint for macOS

11.10.200.329

Trellix DLP Endpoint for Windows

11.10.200.162

Trellix DLP Network Monitor appliance installation images

11.10.700

  • For VMware vSphere virtual appliance — Trellix-MS-11.10.700-3675.100.ms.hw10.hdd.ova

  • For hardware appliance — Trellix-MS-11.10.700-3675.100.iso

Trellix DLP Network Prevent appliance installation images

11.10.700

  • For VMware vSphere virtual appliance — Trellix-PS-11.10.700-3675.100.ps.hw10.hdd.ova

  • For Windows Hyper-V — Trellix-PS-11.10.700-3675.100.HyperV_ps.zip

  • For hardware appliance — Trellix-PS-11.10.700-3675.100.iso

  • For AWS — Trellix DLP Network Prevent AMI

    Trellix-PS-11.10.700-3675.100.AWS_ps.zip



Every update release is cumulative and includes all features and fixes from the previous release. For the previous release information, see:

For more information about using Trellix DLP – SaaS, see the Trellix DLP – SaaS Product Guide.

Updated platform, environment, or operating system support

You can get the latest information about supported platforms, environments, and operating systems from these KB articles:

  • For Trellix DLP Discover – SaaS: 000010983

  • For Trellix DLP Endpoint - SaaS: 000006700

  • For Trellix DLP Network Monitor – SaaS: 000010052

  • For Trellix DLP Network Prevent – SaaS: 000010052

New or changed features

Trellix DLP appliance 11.10.700 or later supports the following features:
  • Trellix IAM changes — Trellix DLP Network appliance software points to the new Trellix Fully Qualified Domain Name (FQDN) and Trellix Identity and Access Management (IAM) URLs from the existing McAfee FQDN. To ensure uninterrupted service to IAM, update your firewall settings to allow the https://iam.cloud.trellix.com URL. The https://iam.mcafee-cloud.com is now changed to https://iam.cloud.trellix.com. To migrate to new Trellix IAM domains, upgrade to Trellix DLP Network Appliances version 11.10.700.

    If you do not intend to upgrade to 11.10.700, see article 000013552 to migrate to the Trellix domain.

  • Support for Trellix DLP Network Prevent in AWS — Starting with this release, Trellix DLP Network Prevent appliance is offered as an Amazon Machine Image (AMI). This helps you deploy the appliance seamlessly on AWS EC2 instance, which can be integrated with cloud web or email gateways.

    For information about deploying and installing the Trellix DLP Network Prevent - SaaS appliance in the AWS environment, see Deploy and install the Trellix DLP Network Prevent appliance in AWS using the .iso file and Deploy and install the Trellix DLP Network Prevent appliance using the Amazon Machine Image (AMI).

  • REST API integration support with cloud gatewaysTrellix DLP Network Prevent now offers REST API based integration with Trellix Email Security - Cloud to scan outbound emails and enable Trellix Email Security - Cloud to take action based on the defined Trellix DLP policies. This API integration is also supported with other third party cloud gateways integration.

    This provides seamless native integration with Trellix Email Security - Cloud and other cloud gateways without requiring to backhaul the traffic to on-prem appliances for inspection.

    For more information, see Trellix DLP REST API integration with cloud gateways.

Trellix DLP Endpoint for Windows 11.10.200 or later supports the following features:
  • Setting the confidence threshold in manually registered documentsTrellix Data Loss Prevention Discover and Trellix DLP – SaaS Network Appliances allow you to configure the number of fingerprints that must be matched in a manually fingerprinted document to trigger a violation. This helps in increasing the detection confidence as it minimizes false positives by triggering more accurate detections and reduces the analysis time.

    An incident is triggered when the number of matches is equal to or higher than the set confidence threshold. You can set the Confidence Threshold percentage between 10 to 100 percent. For example, if a fingerprinted document generates 100 signatures, and if you select 10%, then 10 signatures are matched at random in the scanned document.

    To set the threshold percentage go to, ClassificationRegistered DocumentsManual RegistrationConfidence Threshold.

  • Enhanced screen capture protection — Screen capture actions performed using Universal Windows Platform apps, such as Snip & Sketch are now protected by Trellix DLP Endpoint for Windows - SaaS.

    Note

    In Microsoft Windows 11, Trellix DLP Endpoint for Windows - SaaS only supports data protection with the snip option. However, it does not provide data protection if the screen is recorded.

  • Block Gen AI URLsWeb Application Control feature in Trellix DLP Endpoint for Windows - SaaS now allows you to block access to generative AI websites.

    To block a new generative AI website go to DLP Policy ManagerDefinitionsURL ListActionNew.

  • Monitor text upload to Gen AI prompts — In the Web Protection page, you can now add web URL tags in order to monitor text uploads to the generative AI website. As a result, corporate devices can be monitored in order to avoid sensitive data leaks. For additional information on finding tags for other websites, see article 000012846.

  • Drag and drop — This release provides an option in the Web Protection page to optionally disable drag and drop of attachments from Microsoft Outlook into supported Chromium browsers.

  • Disabling file deletion on quarantine foldersTrellix DLP – SaaS extension is now enhanced with new functionality to prevent the automatic deletion of quarantine files based on time limits. This feature allows you to avoid the deletion of quarantine files in quarantine folders and achieve the goal of "never deleting the quarantine files".

    To prevent deletion of quarantine files go to Policy CatalogData Loss PreventionWindows Client ConfigurationQuarantine and set the value of Quarantine duration (Days) to "0".

Trellix DLP Endpoint for Windows 11.11.0 or later supports the following features:

The user interface in Trellix DLP – SaaS 2408 version shows the following features that will be available for use in the next release of Trellix DLP Endpoint for Windows - SaaS:

  • File upload protection for Chrome Enterprise and Printer Protection for Chrome Enterprise in Operational Mode and Modules page.

  • Manually Resolve DFS in Advance Configuration page.

  • Citrix Studio configuration in Device Control page.

Trellix DLP Endpoint for macOS 11.10.100 and above supports the following features:
  • Support for Safari browser — Using web protection rules in ,Trellix DLP Endpoint for macOS - SaaS, you can now monitor and block data uploads to Safari browser.

  • Block sensitive data uploads via Chromium browsers — Using web protection rules in Trellix DLP Endpoint for macOS - SaaS, you can now block data uploads to Google Chrome and Microsoft Edge browsers.

    For more information about how to deploy Trellix DLP web protection extension on browsers using mobileconfig, see article 000013383.

  • Block sensitive emails and attachments — With Trellix DLP Endpoint for macOS - SaaS, you can now block sensitive emails and attachments sent from Microsoft Outlook.

  • Protect sensitive data from printing - By using printer protection rules, you can now monitor and block confidential documents from being printed on both local and network printers. For more information on Privacy Preferences Policy Control for printer protection, see KB91109.

  • Apply DLP rules to custom users - You can now create a Custom User List in DLP Policy ManagerDefinitions page. Using the Policy CatalogDLP Rule Set, you can now apply Data Protection and Device Control rules to local users by selecting belongs to one of the Custom User List in the Conditionsand End-User field.

    Note

    belongs to one of the Custom User List option is not available for email protection rules.

Trellix DLP – SaaS extension supports the following features:
  • Support for custom Queries & Reports — Create custom queries and generate reports for the following types of events:

    • DLP Computer Policies

    • DLP Computer Properties

    • DLP Discover Scans

    • DLP Endpoint Installed version summary

    • DLP Operational Events

Resolved issues

This release resolves known issues and customer reported issues.

Resolved issues in Trellix DLP Network Prevent and Trellix DLP Network Monitor

Reference

Resolution

DLPN‑12932

This release fixes an issue where the domain based AD servers synchronized frequently, which caused LDAP communication to fail and emails were not delivered.

DLPN-12604

This release fixes an issue where multiple cluster primaries were reported when a cluster re-election occurred.

DLPN-13083

DLP server for automatic registration documents could only be configured using IP address. Starting with this release, you can also configure the server using a hostname.

DLPN-13289

This release fixes an issue where the CA certificates were not preserved after the appliance software upgrade.

DLPN-13562

This release updates StorCLI to fix an issue where the DLP Capture Storage Array configuration was deleted upon upgrading and caused the appliance to boot from emergency mode.

DLPN-13807

When the admin password was reset using ISO installer, Graphical Configuration Wizard would stop working and this is fixed.



Resolved issues in DLP Endpoint for Mac

Reference

Resolution

DLPX-2451

Fixed an issue where incidents were generated for folder paths containing spaces in the folder name, even when the folders were listed under Ignored Processes.

DLPX-3532

Fixed an issue in which the discovery scan was inconsistent when detecting .xml, .pptx, and .xls content classified files.

DLPX-3816

Fixed an issue in which system processes triggered the Removal Storage Protection Rule (RSPR) for unsupported encryption types or password-protected files.

DLPX-4183

Fixed an issue where the rules with Exceptions by Group failed to apply.

DLPX-4196

Fixed an issue where the discovery scan displayed an incorrect match count.



Known issues

For a list of current known issues, see: Trellix Data Loss Prevention - SaaS Known Issues.

Comparison of Trellix DLP – SaaS with Trellix DLP on-premises

Trellix is working toward feature parity with the on-premises Trellix DLP product. To know more about the options not available in this release, see article 000012803.