Local Drive Channel missing in Cloud DLP Agent Configuration
search cancel

Local Drive Channel missing in Cloud DLP Agent Configuration

book

Article ID: 439829

calendar_today

Updated On:

Products

Data Loss Prevention Cloud Detection Service for Endpoint Data Loss Prevention Cloud Detection Service Data Loss Prevention Data Loss Prevention Cloud Package

Issue/Introduction

When configuring a DLP Agent Configuration within the Cloud DLP (CloudSOC) console, the Local Drive channel is not available for selection in the Channels tab under "Destinations".

Environment

Symantec Data Loss Prevention (DLP) Cloud Detection Service for Endpoint
CloudSOC (CASB) Management Console

Cause

The Local Drive channel is intentionally omitted from the Cloud DLP offering by design.
Monitoring every file operation on a local disk (e.g., file moves or modifications) is highly resource-intensive and often results in significant endpoint performance degradation. Because this feature is rarely used in cloud-managed environments and generates a high volume of noise, we have excluded it to prioritize system stability and performance.

Resolution

Security coverage for local data movement and access is provided through alternative channels that are more efficient and focused. To achieve the monitoring goals typically associated with local drive monitoring, use the following channels in your Agent Configuration:

  • Cloud Storage: Use this to monitor and prevent sensitive data from being synced or uploaded to cloud service providers (e.g., OneDrive, Google Drive, Box).
  • Copy to Local Drive: This channel monitors data being moved from network shares or monitored locations to the local disk.
  • Application File Access Control (AFAC): Use this to monitor or block specific applications from accessing, reading, or modifying sensitive files residing on the local disk.
  • Removable Storage: Monitors and prevents data transfer to USB drives and other external media.

If you have a specific use case that requires monitoring local file system activity not covered by the channels above, please contact Support to discuss alternative configuration strategies.