Effectively deploying the DLP Agent requires a clear distinction between the capabilities of Endpoint Prevent and Endpoint Discover.
Both modules rely on the same underlying infrastructure to keep the environment secure:
Endpoint Agents: Software installed directly on computers that holds security policies and detects violations.
Endpoint Servers: The middle layer that receives incident reports from the connected agents.
Enforce Server: The central management hub that collects all data from the Endpoint Servers.
This module acts as a real-time guard, monitoring and blocking confidential data from leaving a user's computer.
Real-Time Responses: If a user attempts an unauthorized transfer, the agent can block the action, ask the user to confirm their intent, show a warning pop-up, or trigger custom responses (like forcing USB file encryption).
Always-On Protection: The agent enforces security policies even if the computer is entirely disconnected from the network.
Secure Offline Logging: If an incident occurs while offline, the data is encrypted and saved to the hard drive. It automatically uploads to the server once the computer reconnects.
The below figure presents an example flow of generating an incident.
This module acts as an internal auditor, scanning endpoint computers for stored confidential data that violates company policy.
Targeted Scanning: Administrators can configure scans across thousands of computers, applying specific filters for directories, file sizes, or modification dates.
Windows Remediation: If confidential files are found on a Windows PC, the agent can quarantine them or use the FlexResponse API to trigger custom automatic actions (such as engaging a third-party tool to encrypt the files).
Mac Remediation: On Mac computers, the agent simply logs an incident when it finds confidential data. FlexResponse and Quarantine options are not available.
Uninterrupted Scanning: Scans continue running locally even when the computer is disconnected from the corporate network or the internet.
Flexible Controls: Administrators can set strict time limits for scans or configure them to auto-terminate if the server stops receiving scan data for a set period.
As Symantec DLP keeps evolving, improvements are added with every new release and it is always good to check the new release documentation for new features.
About Endpoint Discover
About Endpoint Discover Scanning
About Endpoint Prevent Monitoring