DLP Client Setting fields

   
User interface mode Select from the following 2 options:
  1. Interactive: A user interface is displayed on all endpoint machines. Users know when files have been contained and have the option to save them to an authorized location.
  2. Stealth: The Forcepoint DLP Endpoint user interface is not displayed to the user. In this mode, users do not know that Forcepoint DLP Endpoint is operating on their machine. The following features are affected in this mode:
    • The Forcepoint DLP Endpoint icon does not display in the task bar. Users could see the Forcepoint DLP Endpoint installation if they check the Windows Control Panel.
    • Users cannot view the client user interface. As a result,they do not have access to the connection status, the Contained Files viewer, the Log Viewer, or the bypass option. (Experienced users can see contained folders and files in the installation path.)

    • Users do not receive pop-up messages.
    • Although administrators can choose Confirm and Encrypt with user password in the Data Security manager as part of an action plan for the endpoint machine, these are not possible enforcement actions. When these options are selected, operations that violate policy are blocked. The Encrypt with profile key action still takes place, however.
    • When a user attempts to access a blocked page, a 404 error message displays rather than a block page.
Because users do not see any notifications, stealth mode is best reserved for discovery tasks and audit-only policies.

Note that you must reinstall the endpoint machine and deploy a new profile to switch user interface modes.

Installation Mode Applies to Windows only. Select from the following 2 options:
  1. Full: Installs Forcepoint DLP Endpoint with full policy monitoring and blocking capabilities upon a policy breach. All incidents are reported in the Forcepoint Security Manager. Full Mode installation requires a restart of the endpoint machine.
  2. Discovery Only: Configures Forcepoint DLP Endpoint to run discovery analysis but not data loss prevention. Discovery Only installation does not require a restart.