Endpoint Prevent Block does not prevent local drive file copy events. Incident still generated.
search cancel

Endpoint Prevent Block does not prevent local drive file copy events. Incident still generated.

book

Article ID: 170322

calendar_today

Updated On:

Products

Data Loss Prevention Endpoint Prevent Data Loss Prevention

Issue/Introduction

You want to prevent a file from being copied on the local drive. For example, you want to prevent a file from being copied from c:\docs\ to c:\temp\.
When the file is copied there is an incident generated in the console for the local drive event, but the file copy is successful and not blocked.
The file is blocked if the file is opened or if there is an attempt at uploading the file to an external site.

Resolution

This behavior is a known limitation of the product. Endpoint Prevent is working properly. Local drive events do not trigger Endpoint Prevent block, notify, or user cancel response rules.

See the online help pages for "About policy creation for Endpoint Prevent" for more details.

About policy creation for Endpoint Prevent - DLP 15.8

About policy creation for Endpoint Prevent - DLP 16.0