What is the purpose of the "Apply this justification to subsequent dialogs resulting from this actions" check box?
search cancel

What is the purpose of the "Apply this justification to subsequent dialogs resulting from this actions" check box?

book

Article ID: 404227

calendar_today

Updated On:

Products

Data Loss Prevention Core Package

Issue/Introduction

What is the purpose of the "Apply this justification to subsequent dialogs resulting from this actions" check box?

Example from DLP agent pop up message below:

Resolution

Apply justification to all pop‑ups for the same action
Select this checkbox to reuse the justification you supply for the first pop‑up across all subsequent pop‑ups generated by the same user action.

The DLP agent decides what counts as the same action based on the cache window defined in ResponseCache.<channel>_TIMEOUT.int. Every time an event occurs within that window, the timer is reset. Actions outside the window are treated as new events and will prompt for a fresh justification. The ResponseCache is tracked per policy, meaning there may be multiple timeouts / refreshes occurring which will affect when a pop up is displayed and a subsequent justification is applied.

Examples

  • Bulk copy to network share — A user copies a folder containing multiple PII‑laden files. Each file triggers a block pop‑up, but after the user supplies a justification once, the remaining pop‑ups for that copy operation do not occur and auto assign the original justification for those incidents.

  • Back‑to‑back uploads — If the user uploads File A and then uploads File B within the ResponseCache.HTTP_TIMEOUT.int window, the second upload is considered part of the same action, so no new justification is required. If File B is uploaded after the window expires, it is a new action and will prompt again even if the checkbox is ticked.

 

 

Note: The user cancel response rule does not include this checkbox because each violation has the potential to leak sensitive data and needs to be evaluated. In contrast to the Endpoint Block and Endpoint Notify rules where the data handling is independent from what the user selects.