Help Center

Third-party software Contact us

Configure process restriction policies

The process restriction policies in DataSecurity Plus prevent users from running unauthorized executables. Endpoint DLP can restrict users or groups from running executables at a particular location or stop them from running a particular executable completely.

Follow the steps below to create new process restriction policies:

  • Select the Endpoint DLP module from the drop-down menu at the top.
  • Go to Configuration > Prevention Policies > Process Restriction.
  • Click + Add Block Executable Profile in the top-right corner.
  • Provide a suitable profile name and description.
  • To create a new process restriction policy, click the + Add new Executable button in the top-right corner.
  • Specify the Executable Name.
  • Select one Block Rule from the two options:
    • Path: Enter the file path in the Executable Path field.
    • Hash: Browse and upload an executable file. Click Calculate Hashes so that the MD5 Hash, SHA256 Hash, and Size in bytes fields are filled. Click Save.
    • Note: Use Path when you have to block a process from being executed from a particular location only. Use Hash to block it from all sources.

  • Click Save to create the process restriction policy.
  • Enforce the process restriction policy on endpoints by mapping it to the corresponding DLP policy.
  • Best practice: Use both the Path and Hash methods to configure the Block Rule for the same executable, as the hash would need to be recomputed manually when the executable is updated. Create separate profiles for the same executable to use both Path and Hash methods.

    Note: For process restriction profiles to work on workstations, ensure that:
    • No conflicting rules are present in the domain controller GPO.
    • The option to push process restriction policies through the local GPO is not disabled.

Mapping process restriction policies to endpoints

To enforce process restriction policies on endpoints, created policies have to be mapped to the DLP policy linked to the targeted endpoints.

Follow the steps below to map process restriction policies to endpoints:

  • Select the Endpoint DLP module from the drop-down menu at the top.
  • Go to Configuration > DLP Policies.
  • Select the DLP policy that is linked to the endpoints to which you wish to apply the process restriction policy.
  • Under Prevention Policies, click Process Restriction.
  • Select the process restriction policy you wish to enforce on endpoints.
  • Click Save to update the process restriction policy.

Don't see what you're looking for?

  • Visit our community

    Post your questions in the forum.

     
  • Request additional resources

    Send us your requirements.