Data Loss Prevention

 View Only
Expand all | Collapse all

Policies and users in specific OUs

  • 1.  Policies and users in specific OUs

    Posted Mar 14, 2013 01:36 PM

    Hello,

    Is it possible to configure DLP so that only users in specific OUs (Microsoft Active Directory) are targeted?  In particular, I am looking at endpoint policies.  Can specific policies exclude or include specific OUs.  Also, is it possible to configure DLP so that specific OUs are excluded or included for all policies?

    Thanks in advance,

    Bob



  • 2.  RE: Policies and users in specific OUs

    Posted Mar 14, 2013 01:37 PM

    When I referred to OUs, I am talking about OUs in Microsoft Active Directory.



  • 3.  RE: Policies and users in specific OUs

    Posted Mar 14, 2013 02:18 PM

    yes you can do apply specific "goups" under the groups tab in the policy you are looking to apply. you can also further exempt groups also...



  • 4.  RE: Policies and users in specific OUs

    Posted Mar 14, 2013 02:19 PM

    sorry click on manage then user groups and build the groups from AD you wish to apply or exempt them from...



  • 5.  RE: Policies and users in specific OUs

    Posted Mar 14, 2013 02:28 PM

    How about excluding an OU instead of group?  



  • 6.  RE: Policies and users in specific OUs

    Posted Mar 14, 2013 02:35 PM

    correct the group comes from a OU in AD....if AD is integrated into the system.



  • 7.  RE: Policies and users in specific OUs

    Posted Mar 14, 2013 02:37 PM

    My issue is that I want to exclude certain countries.  We do not have groups that identify what country someone is, but we do put our users in OU's specific to the country.  From what I can see in the groups part of the policy, it is based on group membership, not where someone's account is in AD (what OU).



  • 8.  RE: Policies and users in specific OUs
    Best Answer

    Posted Mar 14, 2013 02:42 PM

    correct, if it is not in AD its kinda hard... 

    the next question is can you do it by a email group do you have anything like that in in... 

    remeber DLP only reads AD info it nevers writes to AD..



  • 9.  RE: Policies and users in specific OUs

    Posted Mar 14, 2013 02:43 PM

    sorry you can manually build one, you would need to pull out every user indivually and name it... its just time consuming



  • 10.  RE: Policies and users in specific OUs

    Posted Mar 14, 2013 02:56 PM

    I think I have figured this out.  I had to create a User Group.  That group is defined by OU.  Then I can leverage that User Group in the Group tab by either clicking Add Rule or Add Exception.  



  • 11.  RE: Policies and users in specific OUs

    Posted Mar 14, 2013 02:59 PM

    correct... if the ou doesnt exist you need to build it manually...

     

    marked this resolved if it works for you please...



  • 12.  RE: Policies and users in specific OUs

    Posted Mar 14, 2013 03:46 PM

    Done.  Thanks for the quick responses.