Application file access protection rules can be used to block file transfer via AirDrop.
Create a classification to identify the classified content. Use parameters that are relevant to your environment — keyword, text pattern, file information, and so forth.
In ePO - On-prem, select Menu → Data Protection → DLP Policy Manager.
On the Rule Sets tab, select a current rule set or select Actions → New Rule Set and define a rule set.
On the Data Protection tab, select Actions → New Rule → Application File Access Protection.
(Optional) Enter a name in the Rule Name field (required). Select options for the State and Severity fields.
On the Condition tab, in the Classification field, select the classification you created for your sensitive content.
In the End-User field, select user groups (optional).
Adding users or groups to the rule limits the rule to specific users.
In the Applications field, select, Is one of the application (OR) and select AirDrop [built-in] from the available application definitions list.
You can create your own AirDrop definition by editing the built-in definition. Editing a built-in definition automatically creates a copy of the original definition.
(Optional) On the Exceptions tab, create exceptions to the rule.
Exception definitions can include any field that is in a condition definition. You can define multiple exceptions to use in different situations. One example is to define "privileged users" who are exempt from the rule.
On the Reaction tab, set the Action to Block. Select a User Notification (optional). Click Save, then Close.
Other options are to change the default incident reporting and prevent action when the computer is disconnected from the network.
On the Policy Assignment tab, assign the rule set to a policy or policies:
Select Actions → Assign a Rule Set to policies.
Select the appropriate rule set from the drop-down list.
Select the policy or policies to assign it to.
Select Actions → Apply Selected Policies. Select policies to apply to the Trellix DLP Endpoint