Sender Match Pattern doesn't work on Web Prevent authentication string (WinNT://domain/username)
book
Article ID: 159940
calendar_today
Updated On:
Products
Data Loss Prevention Network Prevent for Web
Issue/Introduction
You notice that when using Web Prevent, the HTTP incident includes the sender in the format of WinNT://domain/username (which reflects a Windows username). Therefore trying to utilize a rule based on Sender Match Pattern does not work as expected.
Resolution
The domain\username is actually sent in the username attribute, so the Sender Match Pattern will work based on the sender-email (like SMTP incidents).
Detection ignores the "WinNT://" portion of the sender field. Thus to get this to work you can do the following:
Create a CSV file with the email address column containing "domain/username"
Create an EDM profile using the CSV file and index the email address field as "email".
Modify the WebPrevent Directory Group Match policy adding the DGM in the GROUPS tab.