Policy with Unsupported Endpoint Agent Exceptions Can lead to Missed Detection
search cancel

Policy with Unsupported Endpoint Agent Exceptions Can lead to Missed Detection

book

Article ID: 246117

calendar_today

Updated On:

Products

Data Loss Prevention Enterprise Suite

Issue/Introduction

In a mixed environment with Cloud Detection Service (CDS) and Endpoint Agents, All-in-One policies (used for both CDS and Endpoint) may not produce incidents at the Endpoint.

 

Environment

Release : 15.7 MP3

 

Cause

CDS rules used as exceptions are not supported at the Endpoint. FileReader will drop unsupported rules and send the remaining rules to the Endpoint Agent.

Resolution

In order to accomidate detection for the CDS and for Endpoint, the All-in-One policy needs to be separated into two policies in two different Policy Groups. 

Consolidate the CDS related detection rules, and exceptions, into one policy and Endpoint related detection rules, and exceptions, into a second policy.

Assign the CDS policy into a CDS branded Policy Group. Assign the Endpoint Policy Group to the appropriate Endpoint Servers.