×
×
×
×

Endpoint DLP Policy Deployment

After creating a data rule, the next crucial step is deploying it. Deploying a policy ensures that the data rules are enforced on endpoints, providing real-time protection for sensitive information across your network.

To deploy a policy:

  1. Navigate to Policy Deployment → Associate Policy.
  2. Under Select Custom Group, select the computer groups to associate with the policy.

Data Discovery

Select the relevant data rules from the data classification set up earlier to apply within the policy. Password-protected files can be classified as sensitive, with support for formats including 7z, zip, tar, Bzip2, xz, Gzip, RAR, RAR4, RAR5, WIM, ISO, ARG, and ISOUDF.

Data Discovery policy settings showing data rule selection and password-protected file classification options
Data Discovery settings showing data rule selection for policy deployment.

Data Leakage Prevention

To manage the various access controls for sensitive files, navigate to Policy Deployment → Data Loss Prevention.

File Access

The File Access feature enables admins to specify which applications are permitted to access and open sensitive files.

  • Not Configured: No restrictions or monitoring are applied. All applications can access sensitive files, and no file access activity will be audited.
  • Audit Only: All applications can access and read the data, but all activity is tracked and recorded, with detailed insights available for review.
  • Allow Within Trusted Applications: Enables admins to designate a list of trusted applications, ensuring that only approved apps can access and open files classified as sensitive.

For enhanced security, the preview pane in Windows File Explorer can be disabled.

File Access policy settings showing Not Configured, Audit Only, and Allow Within Trusted Applications options
File Access settings showing available access control options.

Email Client

The Email Client feature allows admins to define how Outlook handles sensitive files, ensuring secure file management during email communication.

  • Not Configured: File sharing is allowed without any restrictions, and no email activity will be audited.
  • Audit Only: All files can be shared, but any transfer of sensitive files is tracked and audited.
  • Allow Within Trusted Domains: Restricts the sharing of sensitive files to configured email domains only. Any attempt to transfer sensitive files outside these domains is blocked, ensuring files remain secure while enabling seamless internal collaboration.
  • Block Emails with Sensitive Content/Attachments: Completely prevents the sharing of sensitive files through the email client, ensuring that sensitive data cannot be transmitted via email.
Email Client policy settings showing Not Configured, Audit Only, Allow Within Trusted Domains, and Block options
Email Client settings showing available options for controlling sensitive file sharing via email.

Consent Settings for Email Client

Navigate to Policy Deployment → Configure Consent Settings. By enabling this consent, Endpoint Central DLP will be able to monitor the transfer of sensitive emails through the installation of Outlook add-ins. Without this consent, the add-ins will not be installed, and sensitive email transfers will go unmonitored.

Configure Consent Settings page for enabling Outlook add-in installation to monitor sensitive email transfers
Configure Consent Settings page for Outlook add-in installation.

Removable Storage Devices

Admins can control how sensitive files are managed when using removable storage devices, ensuring secure handling and preventing unauthorized data transfers.

  • Not Configured: No restrictions are applied. Sensitive files can be transferred to removable storage devices without any limitations, and no transfer activity will be audited.
  • Audit Only: Files containing sensitive data can be transferred, but all such transfers are tracked and audited.
  • Allow Within Trusted Devices: Lets admins define a list of trusted devices. Transfer of sensitive files is permitted only between these approved devices, while transfers to all other devices are blocked.
  • Block Sensitive File Transfers: Completely restricts the transfer of files containing sensitive data to removable storage devices, ensuring that sensitive data cannot be moved or copied.
Removable Storage Devices policy settings showing Not Configured, Audit Only, Allow Within Trusted Devices, and Block options
Removable Storage Devices settings showing available transfer control options.

Printers

Admins can manage the handling of sensitive files during printing, ensuring secure processing and preventing unauthorized access or distribution.

  • Not Configured: No restrictions are applied. Sensitive files can be printed without any limitations, and no print activity will be audited.
  • Audit Only: Printing of sensitive documents is allowed, but all print activities are tracked and audited.
  • Allow Within Trusted Devices: Printing of sensitive files is permitted only on trusted printers, while printing on all other devices is blocked to ensure security.
  • Block Sensitive File Prints: Printing of sensitive files is completely restricted, preventing any unauthorized printing.
Note
Printing restrictions are currently not supported for classifications based on context, such as file extension-based classification.
  • Custom watermarks can be configured to print on documents from trusted sources (applications included in File Access and Outlook), adding an extra layer of identification and security.
  • An option is available to allow users to override restrictions with business reasons, allowing the printing of sensitive content on other printers.
Printers policy settings showing Not Configured, Audit Only, Allow Within Trusted Devices, and Block Sensitive File Prints options
Printers settings showing available print control options for sensitive files.
Printer watermark and business override settings for printing sensitive content
Custom watermark and business override settings for printer policy.

File Upload

Configure settings to prevent the upload of sensitive files to the web, ensuring that critical data remains secure.

  • Not Configured: No restrictions are applied. Sensitive files can be uploaded without any limitations, and no file upload activity will be audited.
  • Audit Only: There are no restrictions on data uploads. However, when sensitive data is uploaded to non-trusted domains, the activity is audited.
  • Allow Within Trusted Domains: Permits the upload of sensitive data only to trusted domains, while uploads to untrusted domains are restricted.
  • Block Sensitive File Uploads: Completely restricts the upload of sensitive files to any domain or destination.
File Upload policy settings showing Not Configured, Audit Only, Allow Within Trusted Domains, and Block options
File Upload settings showing available options for controlling sensitive file uploads.
  • Choose the web browsers to monitor for file uploads.
  • Add a list of trusted domains where sensitive file uploads should not be tracked.
File Upload browser and trusted domain settings showing browser selection and trusted domain list configuration
Browser selection and trusted domain configuration for file upload monitoring.
Note
File uploads are restricted using browser extensions, so monitoring does not occur in Private Browsing or Guest Mode. It is recommended to disable these modes in managed browsers to ensure full tracking of file uploads.

Consent Settings for File Upload

  1. Navigate to Policy Deployment → Configure Consent Settings.
  2. Providing consent installs the browser plugin, allowing Endpoint Central DLP to block sensitive file uploads to the web. Without consent, the plugin will not be installed, and sensitive file uploads cannot be restricted.
Configure Consent Settings page for enabling browser plugin installation to block sensitive file uploads
Configure Consent Settings page for browser plugin installation.

File Download

Under the settings option, you can enable the feature to automatically mark files created from enterprise apps or downloaded from corporate web domains or emails as sensitive by default.

File Download settings showing the option to automatically mark files from enterprise apps or corporate domains as sensitive
File Download settings for automatically marking enterprise files as sensitive.

Screen Capture

The Screen Capture feature allows admins to enable or restrict screen capture.

  • Allow: Permits all users to take screenshots of sensitive data without restrictions.
  • Block Within Trusted Applications: Restricts screenshots of sensitive data within any trusted application listed under the File Access settings, ensuring enhanced data security.
Screen Capture policy settings showing Allow and Block Within Trusted Applications options
Screen Capture settings showing available options.
Note
The trusted applications for Screen Capture are taken from the application list defined in File Access.

Clipboard Restrictions

The Clipboard Restriction option prevents copying information from trusted applications to untrusted ones, while still allowing file copying within the trusted applications listed.

Clipboard Restrictions policy settings showing options to restrict clipboard access between trusted and untrusted applications
Clipboard Restrictions settings for controlling clipboard access between applications.
Scenario
When content copied from a trusted application is pasted into a browser, the paste is allowed only if the destination is a trusted domain. Content from a trusted application cannot be pasted into untrusted domains in the browser.

False Positives and Overrides

The Automatically Override if False-Positive feature allows users to bypass a block if they believe a non-sensitive file has been incorrectly flagged as sensitive. All overrides are logged in the audit for review. This option can be enabled temporarily until the DLP policy is fine-tuned, ensuring employee productivity remains unaffected.

False Positives and Overrides settings showing the Automatically Override if False-Positive toggle option
False Positives and Overrides settings with the automatic override option.

Configuring Email Alerts

The Mail Configuration feature allows you to configure email notifications that are sent to admins whenever a user raises a business override or reports a false positive. This ensures that administrators are alerted in real time and can take immediate action to review and address the incident.

Mail Configuration settings showing the option to configure email notifications for business overrides and false positives
Mail Configuration settings for admin email notifications.

Mail Notification Settings

  1. Navigate to Settings → Configure Mail Notification.
  2. Add the list of email addresses that need to be notified when an override is reported.
Mail Notification Settings page showing email address input for override notifications
Mail Notification Settings showing email address configuration for override alerts.

Related