Use case: Classify attachments as NEED-TO-SHARE based on their destination

Prev Next

Create classifications that allow NEED-TO-SHARE attachments to be sent to employees in the United States, Germany, and Israel.

  1. Use the Registered Servers features in ePO - SaaSto add details of the LDAP servers. For more information about registering servers, see the ePO - SaaS Product Guide.

  2. Use the LDAP Settings feature in the Users and Groups policy category to push group information to Trellix DLP Network Prevent – SaaS.

Follow these high-level steps:

  • Create a NEED-TO-SHARE classification.

  • Create a United States classification.

  • Create an Israel classification.

  • Create email address list definitions.

  • Create a rule set and a rule that classifies attachments as NEED-TO-SHARE.

  • Specify exceptions to the rule.

The example classifications in the table show how the classifications behave with different classification triggers and recipients.

Expected behavior

Classification

Recipient

Expected result

Attachment1 — NEED-TO-SHARE, Israel (.il) and United States (.us)

Attachment2 — NEED-TO-SHARE, Israel (.il) and Germany (.de)

exampleuser1@example1.com

Allow — example1.com is allowed to receive all NEED-TO-SHARE attachments

Attachment1 — NEED-TO-SHARE, Israel (.il) and United States (.us)

Attachment2 — NEED-TO-SHARE, Israel (.il) and Germany (.de)

exampleuser2@example2.com

Allow — example2.com is allowed to receive all NEED-TO-SHARE attachments

Attachment1 — NEED-TO-SHARE, Israel (.il) and United States (.us)

Attachment2 — NEED-TO-SHARE, Israel (.il) and Germany (.de)

exampleuser2@example2.com

exampleuser1@example1.com

Allow — example1.com and example2.com are allowed to receive both attachments

Attachment1 — NEED-TO-SHARE, Israel (.il) and United States (.us)

Attachment2 — NEED-TO-SHARE, Israel (.il) and Germany (.de)

exampleuser3@gov.il

Allow — gov.il is allowed for both attachments

Attachment1 — NEED-TO-SHARE, Israel (.il) and United States (.us)

Attachment2 — NEED-TO-SHARE, Israel (.il) and Germany (.de)

exampleuser4@gov.us

Block — exampleuser4 is not allowed to receive Attachment2

Attachment1 — NEED-TO-SHARE, Israel (.il) and United States (.us)

Attachment2 — NEED-TO-SHARE, Israel (.il) and Germany (.de)

exampleuser3@gov.il

exampleuser4@gov.us

Block — exampleuser4 is not allowed to receive Attachment2

Attachment1 — NEED-TO-SHARE, Israel (.il) and United States (.us)

Attachment2 — NEED-TO-SHARE, Israel (.il) and Germany (.de)

exampleuser1@example1.com

exampleuser4@gov.us

Block — exampleuser4 is not allowed to receive Attachment2

Attachment1 — NEED-TO-SHARE, Israel (.il) and United States (.us)

Attachment2 — NEED-TO-SHARE, Israel (.il) and Germany (.de)

exampleuser3@gov.il

exampleuser1@example1.com

Allow — exampleuser1 and exampleuser3 are allowed to receive both attachments

Attachment1 — NEED-TO-SHARE, Israel (.il) and United States (.us)

Attachment2 — NEED-TO-SHARE, Israel (.il) and Germany (.de)

exampleuser2@example2.com

exampleuser1@example1.com

exampleuser4@gov.us

Block — exampleuser4 cannot receive Attachment2



  1. Create an email address list definition for the domains that are exempt from the rule.

    1. In the Data Protection section in ePO - SaaS, select DLP Policy Manager and click Definitions.

    2. Select the Email Address List definition and create a duplicate copy of the built-in My organization email domain.

    3. Select the email address list definition you created, and click Edit.

    4. In Operator, select Domain name equals and set the value to example1.com.

    5. Create an entry for example2.com.

    6. Click Save.

    7. Repeat these steps to create a definition for gov.il.

    8. Repeat the steps again to create a definition for gov.us.

  2. Create a rule set that includes an Email Protection rule.

    1. Click Rule Sets, then select ActionsNew Rule Set.

    2. Name the rule set Allow NEED-TO-SHARE email to Israel and United States.

  3. Create a rule and add the NEED-TO-SHARE classification criteria.

    1. Click ActionsNew RuleEmail Protection Rule.

    2. Name the rule NEED-TO-SHARE, enable it, and enforce it on DLP Endpoint for Windows and DLP Network Prevent.

    3. Set Classification of to one of the attachments (*).

    4. Select contains one of (OR), and select the NEED-TO-SHARE classification criteria.

    5. Set the Recipient to any recipient (ALL).

    6. Leave the other settings on the Condition tab with the default settings.

  4. Add exceptions to the rule, and enable each exception.

    • Exception 1

      1. Set Classification of to matched attachment.

      2. Select contains one of (OR), and select the NEED-TO-SHARE classification criteria.

      3. Set the Recipient to matched recipient belongs to one of groups (OR), and select the email address definition that includes example.com and example2.com that you created.

    • Exception 2

      1. Set Classification of to matched attachment.

      2. Select contains all of (AND), and select the NEED-TO-SHARE and .il (Israel) classification criteria.

      3. Set the Recipient to matched recipient belongs to one of groups (OR), and select gov.il.

    • Exception 3

      1. Set Classification of to matched attachment.

      2. Select contains all of (AND), and select the NEED-TO-SHARE and .us (United States) classification criteria.

      3. Set the Recipient to matched recipient belongs to one of groups (OR), and select gov.us.

  5. Set the reaction you want to take if the rule triggers.

    1. In DLP Endpoint, set the Action to Block.

    2. In DLP Network Prevent, set the Action to Add header X-RCIS-Action, and select the BLOCK value. You can also configure to include custom headers in the email message. Using the custom header definitions you created and the built-in custom header definitions, you can configure the custom header to report the number of rules and cumulative score of the rules that violated a policy.

  6. Click Save.

  7. Apply the policy.