Help Center
Quick Start
- Overview
- System requirements
- Minimum privileges required
- Default port configuration
- Installing DataSecurity Plus
- Uninstalling DataSecurity Plus
- Starting DataSecurity Plus
- Launching DataSecurity Plus
- Configuring your solution
- Licensing details
- Applying a license
File Auditing
- About File Auditing
- Domain configuration
- File server configuration
- Failover cluster configuration
- NetApp server configuration
- Nutanix server configuration
- EMC Isilon server configuration
- Workgroup configuration
- Amazon FSx configuration
Setting up File Audit
Dashboard
Reports
Alerts
Configuration
Storage Configuration
File Analysis
- About File Analysis
- Domain configuration
- File server configuration
- Workgroup configuration
- SMB File Server Configuration
- On-Demand Reports
Setting up File Analysis
Dashboard
Reports
Alerts
Configuration
Data Risk Assessment
- About Data risk assessment
Setting up Data risk assessment
Dashboard
Reports
Ownership analysis
Configuration
Endpoint DLP
- About Endpoint DLP
- Domain configuration
- Workstation configuration
- Device group configuration
- Workgroup workstation configuration
Setting up Endpoint DLP
Reports
Alerts
Prevention policies
Configuration
Cloud Protection
- About Cloud Protection
- Gateway Server Installation Steps
- Gateway Configuration in Endpoint
- Gateway Cluster Configuration
- Gateway Server Management
- Certificate Authority Configuration
- Two-way SSL configuration
- Manage Certificate Trust Store
- Threat Analytics Database
- Manage Banned Applications
- Manage Authorized Applications
- Regenerating gateway server access key
- Updating gateway server
- Gateway Server Failover
- Load Balancer Configuration
- Global Insight
- Application Insight
- User Insight
- Shadow Application Insight
- Banned Application Insight
- Cloud App Discovery
- File Upload & Download Reports
- Control Policy reports
- General Reports
- Application Insights
- Shadow Domain Insights
- Banned Domain Insights
- GenAI Insights
Setting up Cloud Protection
Dashboard
Reports
Control Policies
Storage Configuration
Policy Management
Administrative settings
- Technician configuration
- Notification filters
- Manage agent
- Agent settings
- SIEM integration
- Business hours configuration
- Two-factor authentication
- Workgroup configuration
- Security policy
Email configuration
General settings
- Connection
- Personalize
- DataSecurity Plus Server
- Privacy Settings
- Disk utilization
- Schedule Retention Policy
Release notes
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
2015
Troubleshooting
- HTTP communication failure
- Dormant DataEngine
- Secure Gateway server failure
- RPC communication failure
- Cloud Protection Gateway server failure
- Known issues and limitations
- Known errors and solutions
- Report discrepancy in File Analysis
Guides
- Agent document
- How to Migrate/Move DataSecurity Plus
- How to apply SSL certificate
- How to automate DataSecurity Plus database backup
- How to set alerts in DataSecurity Plus
- How to secure your DataSecurity Plus installation
Setting up DLP Policies
Data loss prevention (DLP) policy management involves identifying sensitive data to be monitored and enforcing controls that govern how such data is processed or transferred across your environment.
Common use cases include blocking instantly when:
- Credit card numbers are sent in outbound emails.
- A user uploads files containing classified documents to a SaaS platform.
- Large datasets are copied to external devices after hours.
Current scope limitations
At present, DLP policy enforcement is limited to Outlook email. Support for additional communication channels will be added in subsequent releases.
Prerequisites for setting up a DLP policy
Ensure the following components are configured before creating a DLP policy.
Data source
Add a data source such as a domain or workgroup before proceeding, as DLP policies cannot inspect or enforce controls unless a target environment is defined.
Device group
Define the set of endpoint devices the DLP policy must apply to. Without a device group, the DLP policy has no scope and cannot be enforced on any endpoint.
Find the steps to add and manage a device group here.
Data identifier group
A data identifier group defines sensitive data to be secured by configuring detection logic using regex patterns and keyword sets along with match conditions. A data identifier group tells the policy which sensitive data to secure—without it, detection cannot occur.
Steps to create a DLP policy
The steps below outline how to configure a DLP policy that prevents credit card information from being transmitted in Outlook email subject lines and body content:
- Open the DataSecurity Plus console. On the Apps page, beside Best Practices, select Policy Management.
- Select +Add Policy in the top right-corner of the page.
- In the Pre-requisites for DLP Policy Configuration pop-up, verify that all required components are configured:
- If all components are configured, click Continue Creating Policy.
- If any components are not yet configured, configure them before proceeding.
- On the Enter Policy Details page, enter the policy name, description, and select the severity level.
Sample:
Name: Protect Cardholder Data via Outlook for PCI-DSS
Description: Restricts transmission of cardholder data through Outlook email for FIN-OPS, HR-Process, and Admin-Core endpoint groups.
Severity: High
- Click Next in the bottom right-corner of the page.
- On the Define Policy Scope page, click +Add Device Group in the top right-corner.
- In the Select Device pop-up, select the desired device groups and click Add.
- Click Next.
- On the Choose Detection Criteria page, click +Add Identifier Group in the top right-corner.
- In the Choose Identifier Group pop-up, select the desired identifier group and click Add.
Sample: Cardholder Data
- Click Next.
- On the Enforce Exit Point Control page, select Email Client as the communication channel. Under Supported Clients choose Outlook.
Note: Only Outlook email clients are currently supported. Additional email clients will be added in future releases. Need support for a different email client? Let us know here.
- Use the Response drop-down to select the desired action: Allow, Warn, or Block.
- Use the toggle to enable or disable the use of additional filters for precise control. Using additional filters for granular protection, you can refine which emails containing sensitive data trigger the policy.
For example, choose to act only on emails that:
- Contain attached files with the classification label of Restricted or Confidential.
- Include specific From, To, or CC addresses.
- Contain specific keywords such as Critical or Intellectual Property in the subject line.
- Have attachments above a specific file size or type.
Note: When multiple filters are selected, all conditions must be met for the policy to respond.
- Click Next. Review all details on the Finalize Policy page.
- Click Save.
Now, the policy is active and will be listed under the DLP Policy page.
What happens when a policy is violated?
When an active event matches the conditions defined in a policy, the policy is considered to be violated and the configured response is carried out. The event is then raised as an incident in the Incident Management console for review and resolution.
Based on the number of false positives generated, you can tighten policy accuracy by adding more criteria or exclusion entities.
For more details on how the Incident Management console works, click here.
Managing DLP policies
You can edit, enable, disable, or delete existing policies from the DLP Policy page.
Note: Once deleted, policies cannot be recovered. If you plan to reuse a policy later, disable it instead of deleting it.
Managing multiple DLP policies
When you have more than one DLP policy configured, each policy is assigned a priority that determines the order in which they are evaluated. The policy at the top of the list holds the highest priority and is evaluated first. When a new policy is created, it is automatically assigned the highest priority, and all existing policies are moved down by one position accordingly. You can reorder policies at any time to reflect your preferred priority.
To update policy priority:
- On the Apps page, beside Best Practices, click Policy Management.
- On the DLP Policy page, use the drag handle on the left side of any policy to reorder it into the desired position.
You can also refer to the Priority column in the DLP policies table to understand the current order.
How to handle conflicting DLP policies
When an event matches more than one policy, each match is raised as a separate incident in the Incident Management console. When the configured responses between the matched policies differ, only the most restrictive response applies—for example, if one policy is set to Warn and another to Block, the Block response takes effect.
