Data Loss Prevention processes rules and templates by priority. If a rule is set to "Pass", Data Loss Prevention processes the next rule in the list. If a rule is set to "Block" or "User Justification", Data Loss Prevention blocks or accepts the user action and does not process that rule/template further.
Configure the template settings:
When selecting templates:
Select multiple entries by clicking the template names which highlights the name.
Use the search feature if you have a specific template in mind. You can type the full or partial name of the template.
Each rule can contain a maximum of 200 templates.
The Data Loss Prevention Templates screen displays.
For instructions on adding templates in the Data Prevention Templates screen, see Data Loss Prevention Templates.
Configure the channel settings:
For details about channels, see Network Channels and System and Application Channels.
All transmissions
Only transmissions outside the Local Area Network
See Transmission Scope and Targets for Network Channels for details on transmission scope, how targets work depending on the transmission scope, and how to define targets correctly.
For details on monitored and non-monitored email domains, see Email Clients.
The approved list for USB devices supports the use of the asterisk (*) wildcard. Replace any field with the asterisk (*) to include all devices that satisfy the other fields.
For example, [vendor]-[model]-* places all USB devices from the specified vendor and the specified model type, regardless of serial ID, to the approved list.
Use the Device List Tool to query devices connected to endpoints. The tool provides the device vendor, model, and serial ID for each device. For details, see Device List Tool.
Configure the action settings:
For details about actions, see Data Loss Prevention Actions.
Data Loss Prevention only supports the encryption of sensitive data on removable devices and cloud storage services. Data Loss Prevention performs the "Pass" action without encryption on all channels where encryption is not supported. The target endpoint must have Endpoint Encryption installed and the user must log in to Endpoint Encryption in order to encrypt data.