Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

DLP Configuration with Outlook/Web

Hi everyone, 

 

I'm trying to configure two rules in the DLP in Sophos Central:

 

1-Just for block the transfer of Excel files through the email(outlook) or web 

2-Just for block documents excel, word, PDF with the words "Cliente", "Precio" through the email(outlook) or web 

 

When I set it up the rules and apply them to the endpoint it doesn't work, I'm actually using Windows 10 Enterprise, Office 365, and the last version of Sophos Endpoint.

 

I'm testing the rule with this simple scenario, Create new mail in outlook, attached the excel file (drag and drop) and sent the email to my personal Gmail account .

 

Someone can guide me, in order to solve this inconvenient.

 

Regards,



This thread was automatically locked due to age.
Parents
  • Hi  

    Could you please provide the screenshot of rules configured under DLP policy. You can check this link to check the configurations. Also, request you to check under endpoint if the policy is being received from Sophos UI> Run Diaginistic tool> policy> Sophos Anti-Virus. Are there any events or logs created under location: C:\ProgramData\Sophos\Sophos Data Control\Logs\. 

    Shweta

    Community Support Engineer | Sophos Technical Support
    Are you a Sophos Partner? | Product Documentation@SophosSupport | Sign up for SMS Alerts
    If a post solves your question use the 'Verify Answer' link.
    The New Home of Sophos Support Videos! - Visit Sophos Techvids
  • Here's the SS of the rules configured:

    Rule 1: Block the excel files in general

     

    Rule 2: Block the excel files with personalized words: "Clientes, Cliente, Precio, Precios" 

     

    I hope it helps, 

    Regards,

  • Can you confirm with a simple rule that DLP is working correctly?  Have you tried to attach a file in Outlook via the toolbar?  It might help to create  a simple baseline that DLP is working and then attempt to block more content as you go.

    Respectfully, 

     

    Badrobot

     

  • Hi

    it work when I attached the file via the toolbar, but how I can block it when the user drag and drop the file (is the most common way).

     

    Regards,

  • Please review my above post on how to set GPO or registry changes in order to change how Outlook handles attachments when users Drag and Drop, there is also info on this here: https://community.sophos.com/products/sophos-central/f/sophos-central/101874/dlp-does-not-flag-email-attachments-in-outlook-2016-with-drag-and-drop/370516

     

    Note this will only work if Windows and Office 365 licensing is E1 or higher, due to no ability to alter Office 365 settings with the GPO in lesser licensing.  There are multiple links in the link above and my other post above that will help to resolve this.  

     

    Best!

    Respectfully, 

     

    Badrobot

     

  • Here is the specific KB on the subject: https://community.sophos.com/kb/en-us/122603

    Respectfully, 

     

    Badrobot

     

  • Thanks for your prompt reply, another question, what happens if I modify the registry and just put in the path the C: it will work with the files stored in the C: HDD?

     

     

  • Anything can work if we want right?  lol

     

    I would not, I would create a hidden folder on there desktops or somewhere in there user profile vs the root c:\ since many users may not have access to that directory or should not have access to that directory in terms of write and or execute.  For that matter than any user could see any other users attachments since they would all have read access to the C:\ root, unless you are going to do some fancy permissions but that just sounds like a headache.  Way easier to use the folder infrastructure already in place in Windows for example there desktop, create a hidden folder there, then you could simply run a power shell script every so often to delete all files in the hidden folder on the desktop.  Use an environmental variable like c:\users\%username%\desktop\outlookattachments\  to delete all files in all user profiles in that folder as well, set it with task scheduler to run once a week or month or whatever and you will have your data retention covered as well.

    On a side note, it may also be possible to create it in a personal network drive as well something everyone has but only each user has access to, to again avoid someone figuring out how to read other users attachments between deletions.

    Respectfully, 

     

    Badrobot

     

  • Were you able to get this working?  I know it is a little bit of a pain given the multiple configuration aspects but once it is up and running it works pretty well.

    Respectfully, 

     

    Badrobot

     

Reply Children