Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

DLP Configuration with Outlook/Web

Hi everyone, 

 

I'm trying to configure two rules in the DLP in Sophos Central:

 

1-Just for block the transfer of Excel files through the email(outlook) or web 

2-Just for block documents excel, word, PDF with the words "Cliente", "Precio" through the email(outlook) or web 

 

When I set it up the rules and apply them to the endpoint it doesn't work, I'm actually using Windows 10 Enterprise, Office 365, and the last version of Sophos Endpoint.

 

I'm testing the rule with this simple scenario, Create new mail in outlook, attached the excel file (drag and drop) and sent the email to my personal Gmail account .

 

Someone can guide me, in order to solve this inconvenient.

 

Regards,



This thread was automatically locked due to age.
Parents
  • This can vary I went through a few cases with Sophos on it. Much of this depends on your licensing and having the ability to change Outlook (for example) in the GPO and where it will store an attachment when you drag an drop.  To run a simple test, attempt to attach a document in outlook by clicking the  attach file icon in a new email, DLP will block the attachment this way regardless of the GPO settings which will in turn let you know that your DLP rules are working.  However (simple explanation) if you drag an drop Outlook is using a different means to attach the attachment and Sophos is not capable of seeing this, so you must tell Outlook to store the attachment in a different location.  Again however this is not possible with certain licensing, most notably the Office 365 licensing Business or Business Premium since you are not able to control Office 365 with that licensing via the GPO.  I tried believe me, broke it all down with procmon to determine that Office 365 will just rewrite the registry setting when you open a new email with the business premium licensing.  But hey if you have e1 or higher for Windows 10 and Office 365 you should be great!

    Instructions to get it working can be found here-

    https://community.sophos.com/products/sophos-central/f/sophos-central/110155/dlp-email-attachment-not-being-blocked 

     

    Also I have found a good testing document is to simply create a word doc or excel spread sheet and add 5 or more fake names, with 9 digit numbers (social security), 16 digit, then 4 digit date, then 3 digit (credit card numbers) and some addresses.  Once you create this it should be flagged if you have an financial settings configured in DLP.

    Respectfully, 

     

    Badrobot

     

Reply
  • This can vary I went through a few cases with Sophos on it. Much of this depends on your licensing and having the ability to change Outlook (for example) in the GPO and where it will store an attachment when you drag an drop.  To run a simple test, attempt to attach a document in outlook by clicking the  attach file icon in a new email, DLP will block the attachment this way regardless of the GPO settings which will in turn let you know that your DLP rules are working.  However (simple explanation) if you drag an drop Outlook is using a different means to attach the attachment and Sophos is not capable of seeing this, so you must tell Outlook to store the attachment in a different location.  Again however this is not possible with certain licensing, most notably the Office 365 licensing Business or Business Premium since you are not able to control Office 365 with that licensing via the GPO.  I tried believe me, broke it all down with procmon to determine that Office 365 will just rewrite the registry setting when you open a new email with the business premium licensing.  But hey if you have e1 or higher for Windows 10 and Office 365 you should be great!

    Instructions to get it working can be found here-

    https://community.sophos.com/products/sophos-central/f/sophos-central/110155/dlp-email-attachment-not-being-blocked 

     

    Also I have found a good testing document is to simply create a word doc or excel spread sheet and add 5 or more fake names, with 9 digit numbers (social security), 16 digit, then 4 digit date, then 3 digit (credit card numbers) and some addresses.  Once you create this it should be flagged if you have an financial settings configured in DLP.

    Respectfully, 

     

    Badrobot

     

Children
No Data