Trellix DLP – SaaS 2408 is supported on a new platform and includes new features, and resolved issues.
Product rebranding changes
This is solely for informational purposes, there is no action required. As part of this Trellix Data Loss Prevention extension release, the following product names have been changed on the DLP Settings page and DLP Policy Manager page:
Trellix Data Loss Prevention Endpoint - SaaS is renamed as Trellix Data Loss Prevention Endpoint Complete - SaaS.
Trellix DLP Prevent - SaaS Software is renamed as Trellix Data Loss Prevention Network Prevent - SaaS.
Trellix DLP Monitor - SaaS Software is renamed as Trellix Data Loss Prevention Network Monitor - SaaS.
Trellix DLP Discover - SaaS is renamed as Trellix Data Loss Prevention Discover - SaaS.
Trellix DLP – SaaS release information
Release Date - September 5, 2024 (Republished to support Trellix DLP Network Appliances)
This release of Trellix DLP – SaaS is identified as version 2408, where the version identifier follows a YYMM convention. Trellix DLP – SaaS 2408 release, which includes minor enhancements and resolved issues.
Trellix DLP – SaaS is a unified solution and includes these products:
Trellix Device Control – SaaS
Trellix DLP Discover – SaaS
Trellix DLP Endpoint for Windows - SaaS
Trellix DLP Endpoint for macOS - SaaS
Trellix DLP Network Monitor – SaaS
Trellix DLP Network Prevent – SaaS
Product | Supported versions |
|---|---|
Trellix DLP Discover | 11.10.600.23 |
Trellix DLP Endpoint for macOS | 11.10.200.329 |
Trellix DLP Endpoint for Windows | 11.10.200.162 |
Trellix DLP Network Monitor appliance installation images | 11.10.700
|
Trellix DLP Network Prevent appliance installation images | 11.10.700
|
Every update release is cumulative and includes all features and fixes from the previous release. For the previous release information, see:
For more information about using Trellix DLP – SaaS, see the Trellix DLP – SaaS Product Guide.
Updated platform, environment, or operating system support
You can get the latest information about supported platforms, environments, and operating systems from these KB articles:
New or changed features
Trellix IAM changes — Trellix DLP Network appliance software points to the new Trellix Fully Qualified Domain Name (FQDN) and Trellix Identity and Access Management (IAM) URLs from the existing McAfee FQDN. To ensure uninterrupted service to IAM, update your firewall settings to allow the https://iam.cloud.trellix.com URL. The https://iam.mcafee-cloud.com is now changed to https://iam.cloud.trellix.com. To migrate to new Trellix IAM domains, upgrade to Trellix DLP Network Appliances version 11.10.700.
If you do not intend to upgrade to 11.10.700, see article 000013552 to migrate to the Trellix domain.
Support for Trellix DLP Network Prevent in AWS — Starting with this release, Trellix DLP Network Prevent appliance is offered as an Amazon Machine Image (AMI). This helps you deploy the appliance seamlessly on AWS EC2 instance, which can be integrated with cloud web or email gateways.
For information about deploying and installing the Trellix DLP Network Prevent - SaaS appliance in the AWS environment, see Deploy and install the Trellix DLP Network Prevent appliance in AWS using the .iso file and Deploy and install the Trellix DLP Network Prevent appliance using the Amazon Machine Image (AMI).
REST API integration support with cloud gateways — Trellix DLP Network Prevent now offers REST API based integration with Trellix Email Security - Cloud to scan outbound emails and enable Trellix Email Security - Cloud to take action based on the defined Trellix DLP policies. This API integration is also supported with other third party cloud gateways integration.
This provides seamless native integration with Trellix Email Security - Cloud and other cloud gateways without requiring to backhaul the traffic to on-prem appliances for inspection.
For more information, see Trellix DLP REST API integration with cloud gateways.
Setting the confidence threshold in manually registered documents — Trellix Data Loss Prevention Discover and Trellix DLP – SaaS Network Appliances allow you to configure the number of fingerprints that must be matched in a manually fingerprinted document to trigger a violation. This helps in increasing the detection confidence as it minimizes false positives by triggering more accurate detections and reduces the analysis time.
An incident is triggered when the number of matches is equal to or higher than the set confidence threshold. You can set the Confidence Threshold percentage between 10 to 100 percent. For example, if a fingerprinted document generates 100 signatures, and if you select 10%, then 10 signatures are matched at random in the scanned document.
To set the threshold percentage go to, Classification → Registered Documents → Manual Registration → Confidence Threshold.
Enhanced screen capture protection — Screen capture actions performed using Universal Windows Platform apps, such as Snip & Sketch are now protected by Trellix DLP Endpoint for Windows - SaaS.
Note
In Microsoft Windows 11, Trellix DLP Endpoint for Windows - SaaS only supports data protection with the snip option. However, it does not provide data protection if the screen is recorded.
Block Gen AI URLs — Web Application Control feature in Trellix DLP Endpoint for Windows - SaaS now allows you to block access to generative AI websites.
To block a new generative AI website go to DLP Policy Manager → Definitions → URL List → Action → New.
Monitor text upload to Gen AI prompts — In the Web Protection page, you can now add web URL tags in order to monitor text uploads to the generative AI website. As a result, corporate devices can be monitored in order to avoid sensitive data leaks. For additional information on finding tags for other websites, see article 000012846.
Drag and drop — This release provides an option in the Web Protection page to optionally disable drag and drop of attachments from Microsoft Outlook into supported Chromium browsers.
Disabling file deletion on quarantine folders — Trellix DLP – SaaS extension is now enhanced with new functionality to prevent the automatic deletion of quarantine files based on time limits. This feature allows you to avoid the deletion of quarantine files in quarantine folders and achieve the goal of "never deleting the quarantine files".
To prevent deletion of quarantine files go to Policy Catalog → Data Loss Prevention → Windows Client Configuration → Quarantine and set the value of Quarantine duration (Days) to "0".
The user interface in Trellix DLP – SaaS 2408 version shows the following features that will be available for use in the next release of Trellix DLP Endpoint for Windows - SaaS:
File upload protection for Chrome Enterprise and Printer Protection for Chrome Enterprise in Operational Mode and Modules page.
Manually Resolve DFS in Advance Configuration page.
Citrix Studio configuration in Device Control page.
Support for Safari browser — Using web protection rules in ,Trellix DLP Endpoint for macOS - SaaS, you can now monitor and block data uploads to Safari browser.
Block sensitive data uploads via Chromium browsers — Using web protection rules in Trellix DLP Endpoint for macOS - SaaS, you can now block data uploads to Google Chrome and Microsoft Edge browsers.
For more information about how to deploy Trellix DLP web protection extension on browsers using mobileconfig, see article 000013383.
Block sensitive emails and attachments — With Trellix DLP Endpoint for macOS - SaaS, you can now block sensitive emails and attachments sent from Microsoft Outlook.
Protect sensitive data from printing - By using printer protection rules, you can now monitor and block confidential documents from being printed on both local and network printers. For more information on Privacy Preferences Policy Control for printer protection, see KB91109.
Apply DLP rules to custom users - You can now create a Custom User List in DLP Policy Manager → Definitions page. Using the Policy Catalog → DLP Rule Set, you can now apply Data Protection and Device Control rules to local users by selecting belongs to one of the Custom User List in the Conditions → and End-User field.
Note
belongs to one of the Custom User List option is not available for email protection rules.
Support for custom Queries & Reports — Create custom queries and generate reports for the following types of events:
DLP Computer Policies
DLP Computer Properties
DLP Discover Scans
DLP Endpoint Installed version summary
DLP Operational Events
Resolved issues
This release resolves known issues and customer reported issues.
Reference | Resolution |
|---|---|
DLPN‑12932 | This release fixes an issue where the domain based AD servers synchronized frequently, which caused LDAP communication to fail and emails were not delivered. |
DLPN-12604 | This release fixes an issue where multiple cluster primaries were reported when a cluster re-election occurred. |
DLPN-13083 | DLP server for automatic registration documents could only be configured using IP address. Starting with this release, you can also configure the server using a hostname. |
DLPN-13289 | This release fixes an issue where the CA certificates were not preserved after the appliance software upgrade. |
DLPN-13562 | This release updates StorCLI to fix an issue where the DLP Capture Storage Array configuration was deleted upon upgrading and caused the appliance to boot from emergency mode. |
DLPN-13807 | When the admin password was reset using ISO installer, Graphical Configuration Wizard would stop working and this is fixed. |
Reference | Resolution |
|---|---|
DLPX-2451 | Fixed an issue where incidents were generated for folder paths containing spaces in the folder name, even when the folders were listed under Ignored Processes. |
DLPX-3532 | Fixed an issue in which the discovery scan was inconsistent when detecting .xml, .pptx, and .xls content classified files. |
DLPX-3816 | Fixed an issue in which system processes triggered the Removal Storage Protection Rule (RSPR) for unsupported encryption types or password-protected files. |
DLPX-4183 | Fixed an issue where the rules with Exceptions by Group failed to apply. |
DLPX-4196 | Fixed an issue where the discovery scan displayed an incorrect match count. |
Known issues
For a list of current known issues, see: Trellix Data Loss Prevention - SaaS Known Issues.
Comparison of Trellix DLP – SaaS with Trellix DLP on-premises
Trellix is working toward feature parity with the on-premises Trellix DLP product. To know more about the options not available in this release, see article 000012803.