Your organization wants to block all content from leaking to the web from cloud services, such as Dropbox and Google Drive. The Sales team needs access and copy rights to their shared folder on Google Drive.
An administrator needs to perform these tasks.
Note
To allow non-tenant administrators to add users, groups, or organizational units, they must have the permission to browse the configured Active Directory. To assign the permission, add a new role or edit an existing role for the non-tenant administrator and assign the Browse Active Directory permission. You can set the permission from Menu → Configuration → Users & Roles → Select specific user or role → Trellix ePolicy Orchestrator → Cloud Directory Services → Browse Active Directory.
Block Dropbox and Google Drive services with the Cloud Protection Rule.
In ePO - SaaS , select Menu → Data Protection → DLP Policy Manager.
On the Rule Sets tab, select or create a rule set. For new rule sets, you must assign a policy.
On the Data Protection tab, select Actions → New Rule → Cloud Protection Rule.
Enter a name for the rule and select State → Enabled.
On the Condition tab, in the Classification field, select the classification you created for your confidential content.
In the Cloud Services field, select Dropbox and GoogleDrive.
Specify the user group and folder that you want to exclude from the rule.
Select Exceptions, click Actions → Add Rule Exception, and name it
Sales.Set the State to Enabled.
In Classification of, select contains any data (ALL).
In End-User, select Belongs to one of end-user groups (OR).
Select New Item, and create an end-user group called
Sales team.Click the add group button, select Sales team, and click OK.
In the top-level Subfolder name, select equals, and type the name of the folder (for example, Sales pitch).
Add the Google Drive URL you want to block content from leaking.
Select Menu → Data Protection → DLP Policy Manager. → Definitions.
In the left pane, select URL List, then select Actions → New.
Name the URL
Google Drive URL.Enter the Host details, and optionally, the Protocol, Port, and Path, then click Add.
Click Save.
Block Dropbox and Google Drive from leaking to the web with the Web Protection Rule.
On the Data Protection tab of your rule set, select Actions → New Rule → Web Protection Rule.
Enter a name for the rule and select State → Enabled.
On the Condition tab, in the Classification field, select the classification you created for your confidential content. This must be the same classification selected for the Cloud Protection Rule.
In the Web address (URL) field, select is one of (OR) and choose Dropbox (built-in) and Google Drive URL, created in previous step.
On the Reaction tab, set the Action to Block.
In the User Notification field, select Default web protection user notification.
Click OK, then Save.