Data Loss Prevention

 View Only
  • 1.  [DLP] Block e-mail messages with Endpoint Prevent

    Posted May 18, 2013 01:47 AM

    Hello everyone!

    I'm implementing DLP solution. My scenario is the following:

    ---------------------------------------------------------------------------------------------------------------------------------------------------

    Enforce ----------- Detection (Endpoint) -------- Altiris SMP (For deploying agent) ------- DLP Client

    ---------------------------------------------------------------------------------------------------------------------------------------------------

    I have a rule for blocking copying sensitive files to removable devices such as USB and DVD

    However, I'm looking for a response rule for e-mail. I want to block sensitive data being sent via e-mail attachments (such as OWA, or local e-mail servers)

    I do know I can use Network Prevent for Email but, in this particular case, I need to use Endpoint Prevent only

    Is it possible? Any ideas how? Thanks in advance!

     



  • 2.  RE: [DLP] Block e-mail messages with Endpoint Prevent

    Broadcom Employee
    Posted May 18, 2013 05:10 AM

    endpoint will monitor te endpoint agents.

    email prevent license is needed for the email monitoring/prevent.



  • 3.  RE: [DLP] Block e-mail messages with Endpoint Prevent
    Best Answer

    Broadcom Employee
    Posted May 18, 2013 10:08 PM

    Yes, you can use DLP agent to block email message from mail client and OWA.

    You need to select the relevant options under Agent Configuration, such as below screenshot:

    Agent_Configure.png

    And, also, as pete mentioned, you need the Endpoint Prevent license:

    Agent_Configure_2.png

     



  • 4.  RE: [DLP] Block e-mail messages with Endpoint Prevent

    Posted May 19, 2013 09:51 PM

    Thanks for the reply. 

    Can you tell me which configuration should I use on the response rule??? 



  • 5.  RE: [DLP] Block e-mail messages with Endpoint Prevent

    Posted May 21, 2013 05:03 PM

    An Endpoint Prevent response would be the correct one as this deals w/ Endpoint PRevent



  • 6.  RE: [DLP] Block e-mail messages with Endpoint Prevent

    Broadcom Employee
    Posted May 22, 2013 12:46 AM

    For the response rule, you can choose 'Endpoint Prevent: Block', such as the screenshot below:

    Endpoint_Prevent_Block.png



  • 7.  RE: [DLP] Block e-mail messages with Endpoint Prevent

    Posted May 22, 2013 12:52 AM

    Thanks yang_zhang. It worked great.

     



  • 8.  RE: [DLP] Block e-mail messages with Endpoint Prevent

    Posted May 23, 2013 01:37 AM

    Thanks Yang,

    Nice solution and explaination.



  • 9.  RE: [DLP] Block e-mail messages with Endpoint Prevent

    Posted May 24, 2013 08:32 AM

    This is exactly my configuration.  I have a policy to find social security numbers using the data identifier.  The response rule blocks send SSN through Notes, but it does not block when using web mail in IE or Firefox even though both of those options are selected.

    Any ideas?