When opening a sensitive PPT file on a USB drive, It's creating an incident and a block pop-up also appears.
DLP should only perform detection when pasting or saving a sensitive file on a USB drive, not when opening a file on a USB drive. However, for PPT files DLP is also performing detection when opening the file on a USB drive.
The same thing does not happen for word files (doc, docx), excel files (xls, xlsx), and pptx files, the issue only occurs for the ppt file.
Release: DLP 15.8, 16.0
Expected behavior
When the sensitive file is opened from USB/Network Share, on file open, Microsoft PowerPoint updates metadata information resulting in a file getting modified.
Since the size of the file "at create" and "at close" are different, FSD sends it for detection, and an incident is created since a file has sensitive content.
This is application-specific behavior and by design hence closing this issue by setting the "Resolution" field as "By Design" and closing the defect.
In the meantime, you can workaround the issue by whitelisting the PPT file type in the policy exception or configuring file filters in the "Agent Configuration > Channel Filter".