Help Center
Quick Start
- Overview
- System requirements
- Minimum privileges required
- Default port configuration
- Installing DataSecurity Plus
- Uninstalling DataSecurity Plus
- Starting DataSecurity Plus
- Launching DataSecurity Plus
- Configuring your solution
- Licensing details
- Applying a license
File Auditing
- About File Auditing
- Domain configuration
- File server configuration
- Failover cluster configuration
- NetApp server configuration
- Nutanix server configuration
- EMC Isilon server configuration
- Workgroup configuration
- Amazon FSx configuration
Setting up File Audit
Dashboard
Reports
Alerts
Configuration
Storage Configuration
File Analysis
- About File Analysis
- Domain configuration
- File server configuration
- Workgroup configuration
- SMB File Server Configuration
- On-Demand Reports
Setting up File Analysis
Dashboard
Reports
Alerts
Configuration
Data Risk Assessment
- About Data risk assessment
Setting up Data risk assessment
Dashboard
Reports
Ownership analysis
Configuration
Endpoint DLP
- About Endpoint DLP
- Domain configuration
- Workstation configuration
- Device group configuration
- Workgroup workstation configuration
Setting up Endpoint DLP
Reports
Alerts
Prevention policies
Configuration
Cloud Protection
- About Cloud Protection
- Gateway Server Installation Steps
- Gateway Configuration in Endpoint
- Gateway Cluster Configuration
- Gateway Server Management
- Certificate Authority Configuration
- Two-way SSL configuration
- Manage Certificate Trust Store
- Threat Analytics Database
- Manage Banned Applications
- Manage Authorized Applications
- Regenerating gateway server access key
- Updating gateway server
- Gateway Server Failover
- Load Balancer Configuration
- Global Insight
- Application Insight
- User Insight
- Shadow Application Insight
- Banned Application Insight
- Cloud App Discovery
- File Upload & Download Reports
- Control Policy reports
- General Reports
- Application Insights
- Shadow Domain Insights
- Banned Domain Insights
- GenAI Insights
Setting up Cloud Protection
Dashboard
Reports
Control Policies
Storage Configuration
Policy Management
Administrative settings
- Technician configuration
- Notification filters
- Manage agent
- Agent settings
- SIEM integration
- Business hours configuration
- Two-factor authentication
- Workgroup configuration
- Security policy
Email configuration
General settings
- Connection
- Personalize
- DataSecurity Plus Server
- Privacy Settings
- Disk utilization
- Schedule Retention Policy
Release notes
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
2015
Troubleshooting
- HTTP communication failure
- Dormant DataEngine
- Secure Gateway server failure
- RPC communication failure
- Cloud Protection Gateway server failure
- Known issues and limitations
- Known errors and solutions
- Report discrepancy in File Analysis
Guides
- Agent document
- How to Migrate/Move DataSecurity Plus
- How to apply SSL certificate
- How to automate DataSecurity Plus database backup
- How to set alerts in DataSecurity Plus
- How to secure your DataSecurity Plus installation
Device configuration
Device configuration overview
Device configuration is the process of setting up and organizing endpoints so they can be used as scope for creating policies, scans, and monitoring profiles.
Endpoint-level actions—including monitoring, reporting, and policy enforcement—should be executed against a defined set of configured devices, which makes device configuration a prerequisite for all other setups.
DataSecurity Plus enables administrators to configure:
- Individual devices: Standalone endpoints that can be managed independently.
- Device groups: Logical collection of endpoints that can be managed as a single unit.
Why is configuring endpoints as device groups recommended?
Configuring endpoints in groups is beneficial, as it:
- Scales efficiently across a large numbers of devices.
- Reduces repetitive configuration effort.
- Ensures consistent settings across devices.
- Minimizes configuration errors.
- Simplifies ongoing maintenance, including onboarding new endpoints through centralized updates.
Prerequisite for creating device groups:
- Ensure that endpoints are available through configured domains or workgroups in DataSecurity Plus before creating device groups. Find the steps to configure domains here.
- You are signed in using an Admin account, with access to Admin Console.
How to create a device group
The steps below outline how to create a device group:
- Open the DataSecurity Plus console. Choose Admin Console from the Apps drop-down at the top.
- Go to Administrative Settings > Device Groups. In the Device Groups page, click + Create Group.
- On the Create Group page, enter an appropriate Group Name and Description.
- Under Assign Members, choose whether to add endpoints to the group manually or using OUs.
To add endpoints manually:
Click +Add Device. In the Select Devices pop-up, choose the domain from which you want to add devices. Use the drop-down to switch between configured domains and select the endpoints you want to add. Review your selection in the Selected Devices tab, which lists all endpoints selected across all domains, along with their canonical names. Click Create Group after review.
To add endpoints using OUs:
Click +Add OU. In the Select OUs pop-up, choose the domain from which you want to add OUs. Use the drop-down to switch between configured domains and select the OUs you want to add. Review your selection in the Selected OUs tab, which lists all OUs selected across all domains, along with their canonical name. Click Create Group after review.
- A device group can include endpoints directly or from selected OUs across multiple domains.
- Only machines from the selected root OU are added to the device group; child OU machines are excluded unless those OUs are added separately.
Device group membership constraints
A device that is already a member of an existing group cannot be added to another group, meaning a device can belong to only one group.
Likewise, if a device already belongs to a group, the OU containing that device cannot be added to another group. DataSecurity Plus displays an error listing the devices with conflicting membership. Users can either:
- Override the existing membership, wherein the device is removed from it's previous group and added to the new one
or
- Remove the conflicting OUs from the new group before creating it.
Note: Only endpoints and OUs that are not already members of another group appear in the selection list.
How to manage a device group
The steps below outline how to manage endpoints within a device group:
- Open DataSecurity Plus console. Choose Admin Console from the Apps drop-down at the top.
- Go to Administrative Settings > Device Groups. The Device Groups page lists all device groups currently configured in DataSecurity Plus, along with the number of devices in each group.
- Click the edit icon next to the group name to update the group name or description, or to add and remove endpoints. Click Update Group after making the necessary changes.
To delete device groups, select them on the Device Groups page and click the Delete icon next to Search. Click OK in the confirmation pop-up.
Note: Policies are automatically reevaluated whenever a device group's membership changes.
Best practices for grouping devices
Device groups are designed to enable precise control over a large and diverse endpoint environment, so it is important to organize endpoints into groups that reflect your organization's hierarchical structure and security requirements.
Admins can group endpoints by:
- Departments or business functions such as Human Resources, Finance, and Engineering.
- Security and risk profile, for example endpoints that handle sensitive data versus general purpose workstations.
- Region, for example APAC and EMEA, to address region specific compliance requirements.
- User roles, for example administrative systems, executive endpoints, and shared machines.
Configuring individual endpoint devices
The steps below are used to configure endpoint devices individually:
- Open DataSecurity Plus console. Choose Endpoint DLP from the Apps drop-down at the top.
- Go to Configurations > Devices. In the Configured Workstation(s) page, click +Add Workstations at the top right corner.
- In the Add Workstation(s) page select the domain or workgroup from which you want to add the endpoints.
- Click + in the Select Workstation(s) field to add the required endpoints
- In the Select Workstation(s) pop-up choose the desired endpoints and click Select.
- Choose the Security Policies you want to apply for the selected endpoints.
- In case you want to add specific folders to be monitored within the selected workstations, click Select Local Folders to Monitor and enter the path of local folder. Sample: C:\Users\admin\desktop\NewFolder or D: and click Add.
- Click Install Agent and Finish.
To add a domain that is not listed, click Domain and follow the steps listed here.
To add a workgroup that is not listed, click Workgroup and follow the steps listed here.
