Windows client configuration

Prev Next

The Trellix DLP Endpoint - SaaS client software for Trellix Agent resides on enterprise computers and executes the defined policy. The software also monitors user activities involving sensitive content. Client configuration is stored in the policy, which is deployed to managed computers.

Note

The Policy Catalog comes with Trellix default policies for Windows and macOS endpoint configurations and DLP policy. Click Duplicate (in the Actions column) to create an editable copy as a base for your policy.

The client configuration is stored in the policy, which is deployed to managed computers by ePO - SaaS. If the configuration is updated, you must redeploy the policy.

Client Service WatchDog

Note

The Client Service WatchDog is not supported on Trellix DLP Endpoint – SaaS for Mac.

To maintain normal operation of Trellix DLP Endpoint - SaaS software even if there is malicious interference, Trellix DLP Endpoint - SaaS runs a protective service called the Client Service WatchDog. This service monitors the Trellix DLP Endpoint - SaaS software, and restarts it if it stops running for any reason. The service is enabled by default. If you want to verify that it is running, look in the Microsoft Windows Task Manager processes for the service named fcagswd.exe.

Ignore lists in client configuration

Ignore lists in the client configuration exclude the listed processes, extensions, or URLs from rules.

Setting

Ignore List

Description

Clipboard Protection

Applies to Windows clients only

Ignored Processes

Trellix DLP Endpoint - SaaS ignores clipboard operations performed by the listed applications

Content Tracking

Applies to both Windows and macOS clients only

Ignored Processes

Trellix DLP Endpoint - SaaS ignores access to files performed by the listed applications

Printing Protection

Applies to Windows clients only

Ignored Processes

Trellix DLP Endpoint - SaaS ignores printing actions performed by the listed applications

Web Protection

Applies to Windows clients only

URL Ignore list

Lists URLs excluded by the browser plug-in from all web protection rules. You can add multiple ignore lists by domain or IP address range.

Client configuration settings

Client configuration settings determine how the endpoint software operates. Most of the client configuration settings have reasonable defaults that can be used for initial setup and testing without alteration.

Tip

To verify that the client configuration settings continue to meet your requirements, review them at regular intervals.

The following table lists some of the more important settings to verify.

Endpoint configuration

Setting

Details

Description

Advanced Configuration

Run DLP client in Safe Mode

Applies to Windows clients only

Disabled by default. When enabled, Trellix DLP Endpoint - SaaS is fully functional when the computer is started in Safe Mode. A recovery mechanism exists in case the Trellix DLP Endpoint - SaaS client causes a boot failure.

DLP access protection

When enabled, activates the DLP data access protection features. Default: Enabled in both Trellix Device Control and full Trellix DLP Endpoint - SaaS.

Show challenge response on upgrade

Applies to both Windows and macOS clients

When enabled, activates the challenge/response pop-up window on upgrade.

Show challenge response on uninstall

When enabled, activates the challenge/response pop-up window on uninstall.

Run DLP client watch dog

Applies to both Windows and macOS clients

When enabled, monitors the endpoint processes and restarts them if closed. Changing this setting requires a client computer restart.

Run DLP client service watch dog

Applies to both Windows and macOS clients

When enabled, monitors the watch dog and restarts it if it closes. Changing this setting requires a client computer restart.

Agent Bypass

Applies to both Windows and macOS clients

Stops the agent bypass when a new client configuration is loaded. Deselected by default.

Advanced Pattern Settings

Applies to Windows, macOS clients and Discover

When enabled, activates regex case sensitivity. To apply case sensitivity with any regular expression, the regex pattern must begin with ?i. You can also edit the existing regex pattern and append ?i at the beginning of the pattern.

Content Tracking

Applies to both Windows and macOS clients

Use the following fallback ANSI code page

If no language is set, the fallback is the default language of the endpoint computer.

Corporate connectivity

Applies to both Windows and macOS clients

Corporate Network Detection

Corporate VPN Detection

You can apply different prevent actions to endpoint computers in the corporate network or outside the network. For some rules, you can apply different prevent actions when connected by VPN. To use the VPN option, or to determine network connectivity by corporate server rather than by connection to ePO - SaaS, set the server IP address in the relevant section.

Device Control

iPhone Protection Mode

Allows or prevents charging iPhones when the device rule action is Block.

Device Control Settings

Allows the administrator to choose whether to apply Device Control policies immediately when the policy is applied, or to apply them only when the computer is restarted or the device is physically or logically enabled or disabled.

Debugging and Logging

Log DLP events to external HTTP server

Use these settings to configure the server receiving raw data from the Trellix DLP Endpoint - SaaS client.

Syslog Server Settings

Configure a Syslog server path used for logging certain types of Trellix DLP Endpoint - SaaS events.

The events are sent whether rules are configured to trigger the events or not. The following actions are sent automatically when Send DLP Syslog events to Syslog server is enabled:

  • Printing

  • Copy to removable storage

  • Uploading a file to the web

  • Uploading a file to the cloud

  • Sending an email

  • Connect or disconnect a plu-and-play device

  • Connect or disconnect a removable storage device

Email Protection

Applies to Windows clients only

Email Caching

Stores tag signatures from emails to disk to eliminate re-parsing emails.

Email recipients

Sets the maximum number of email recipients to report. Default is 10.

Email Handling API

Outgoing email is handled by either Outlook Object Model (OOM) or Messaging Application Programming Interface (MAPI). OOM is the default API, but some configurations require MAPI.

Outlook 3rd party add-in integration

Sets integration with either Titus or Bolden James email classification software.

Outlook Background Processing (Only for DLP 11.6 & above)

Enable background processing of emails to reduce user impact when sending emails using Microsoft Outlook.

Set the maximum amount of time allowed to analyze the emails.

  • Maximum time allowed to analyze - 600 seconds

  • Maximum time allowed to analyze in foreground - 120 seconds

Enable a pop-up message that allows the end-user to either review a blocked email or to discard it. Enabling this pop-up message overrides the notification configurations defined in the Email Protection rule.

Set the action taken to either send the email or to block it if the analyzing time exceeds.

Email Timeout Strategy

Sets the maximum time to analyze an email and the action if the time is exceeded.

Outgoing Email User Notification

Sets the end user notification message and when it is displayed.

Evidence Copy Service

Applies to both Windows and macOS clients

Evidence Storage

Shows in read-only format the configurations for your Amazon S3 bucket to store evidence in the cloud. Configurations are applied in DLP Settings.

Client Settings

You can change the way hit highlighting is displayed by setting classification matches to all matches or abbreviated results.

Incident Information

You can hide or display the short match string in the incident details. The setting works in real time, that is, if you change the setting, it only affects the display for incidents collected from that point forward.

Operational Mode and Modules

Applies to both Windows and macOS clients

Operational Mode

Set Trellix Device Control or full Trellix DLP Endpoint - SaaS mode. Reset this parameter if you upgrade or downgrade licensing.

Data Protection Modules

Activate required modules.

Tip

To improve performance, deselect modules you are not using.

Operational Mode and Modules

Applies to Windows clients

Browsers

Enables the browsers you want to block or monitor data upload when using Web Protection rules.

Supported browsers are Microsoft Internet Explorer, Google Chrome, Microsoft Edge (Chromium-based), and Mozilla Firefox.

Default: All browsers are selected.

Note

We recommend not allowing Chrome guest and incognito mode to end-users. If either of these options are allowed, the active web URL on the endpoint might be unavailable to the Trellix DLP client.

Browser Address Bar URL detection

This feature is used to control a major cause of high CPU utilization. The default is to enable browser address bar URL detection. If high CPU utilization is encountered, you can disable the feature.

Plug and Play

Applies to Windows clients only

iPhone Protection Mode

Selects whether or not a blocked iPhone can be charged. This setting applies to plug and play device rules.

Web Protection

Applies to Windows clients only

Web protection evaluation

Select inputs for web request evaluation when matching web protection rules. These settings allow blocking requests sent by AJAX to a different URL from the one displayed in the address bar. At least one option must be selected.

Process HTTP GET requests

GET requests are disabled by default because they are resource-intensive. Use this option with caution.

Web Timeout strategy

Sets the web post analysis timeout, action to perform if timeout is exceeded, and optional user message.

URL Ignore List

Create ignored URL lists and select which list to exclude from web post protection rules.



Troubleshooting guidance for Trellix DLP Endpoint - SaaS

Use the Troubleshooting page in Windows client configuration for tips and guidance on actions that you can take to troubleshoot performance issues and tune policies in Trellix DLP Endpoint - SaaS.