Sent data not triggering all expected DLP policies.
search cancel

Sent data not triggering all expected DLP policies.

book

Article ID: 444577

calendar_today

Updated On:

Products

Data Loss Prevention Core Package

Issue/Introduction

Data Loss Prevention (DLP) policies fail to trigger or generate incidents for specific users, even when content matches the policy criteria. This occurs because the user is a member of one or more groups that are explicitly excluded from the policy.

Environment

Symantec DLP (All detection channels) 

Resolution

Follow these steps to identify and resolve detection failures caused by user group exclusions:

  1. Log in to the DLP Enforce Console.
  2. Navigate to Manage > Policies > Policy List and click on the name of the policy that is not triggering.
  3. Select the Groups tab within the policy configuration.
  4. Review the Excluded Senders/Users section to identify which user groups or user patterns are prevented from triggering the policy.
  5. Cross-reference the affected user's identity with the memberships of those excluded groups or patterns 
  6. Navigate to Manage > User Groups to verify group memberships.
  7. Navigate to Manage > Policies > Sender/Recipient Patterns to verify reusable sender/recipient patterns 
  8. Remove the user from the exclusion group or reusable pattern as necessary. 
  9. Save the changes and allow time for the policy to redistribute to the detection servers.