When Trellix DLP Endpoint - SaaS discovery finds sensitive content, it moves the affected files or email items into a quarantine folder, replacing them with placeholders. These placeholders help notify users that their files or emails have been quarantined.
To display the Trellix DLP – SaaS icon in Microsoft Outlook, the Show Release from Quarantine Controls in Outlook option must be enabled in Policy Catalog → Client Policy → Operational Mode and Modules. When disabled, both the icon and the right-click option for viewing quarantined emails are blocked, and you can't release emails from quarantine.
For quarantined email items, Trellix DLP Endpoint - SaaS discovery attaches a prefix to the Outlook Subject to indicate to users that their emails have been quarantined. Both the email body and any attachments are quarantined. Microsoft Outlook calendar items and tasks can also be quarantined.
Important
Quarantined files are deleted after the policy defined number of days (max 30 days storage).
To restore quarantined files:
In the notification area of the managed computer, click the Trellix Agent icon, and select Manage Features → DLP Endpoint Console.
The DLP Endpoint Console opens.
On the Tasks tab, select Open Quarantine Folder.
The quarantine folder opens.
Select the files to be restored. Right-click and select Release from Quarantine.
Note
The Release from Quarantine context-sensitive menu item only appears when selecting files of type *.dlpenc (DLP encrypted).
The Release Code pop-up window appears.
To restore quarantined email items, select Release from Quarantine.
In Microsoft Outlook, right-click the email or other item to be restored.
Click the Release from Quarantine icon.
The Release Code pop-up window appears.
Copy the challenge ID code from the pop-up window and send it to the DLP administrator.
The administrator generates a response code and sends it to the user.
The user enters the release code in the Release Code pop-up window and clicks OK.
The files are restored to their original location. If the release code lockout policy has been activated (in the Agent Configuration → Notification Service tab) and you enter the code incorrectly three times, the pop-up window times out for 30 minutes (default setting).
Note
For files, if the path has been changed or deleted, the original path is restored. If a file with the same name exists in the location, the file is restored as xxx-copy.abc