Data Loss Prevention

 View Only
  • 1.  DLP Incident Details attributes

    Posted Mar 15, 2012 10:42 AM

    Hi all,

    After a scan has completed and an incident created, when I access some incidents rather than having the File Owner as domain\user, I often see the following: BUILTIN\administrators.

    Any one know why this may happen, where does DLP obtain the File Owner details initially?

    Thanks



  • 2.  RE: DLP Incident Details attributes
    Best Answer

    Posted May 10, 2012 04:14 PM

    Hi Ralphg,

    The file owner is reported by the remote server that's providing the file to DLP for scanning, and it reports an owner of BUILTIN\Administrator as the 'default' username for a file that doesn't have a known owner. Generally it's either it's a file that was created on a non-NTFS system (i.e. FAT32 or NFS) and doesn't have a known owner, or it's original owner was removed (i.e. the AD account that originally owned it was deleted). This is not an uncommon issue to see with Data At Rest scans, and unfortunately there isn't a 'simple' fix.

    The best recommendation I could make would be to implement Data Insight. It watches your file systems and tracks who's doing what to the various files and then integrates into DLP to report that information. This doesn't magically get you a file owner, but it gives you powerful insight into what files are still being used (and by whom) so you can correct the ownership of the file. It also gives you better intel to identify the files that don't have an owner and aren't being used (candidates for archving/deletion).

    Hope that helps!

    - Tim