Introduction
Forcepoint ONE Data Security combines Data Loss Prevention, Device Control, User activity monitoring, and Endpoint management in a single cloud delivered service that is easy to deploy and use. The service includes an endpoint agent that runs on Windows and macOS.
Features and benefits
Management portal
The management portal provides a centralized location for configuring and managing your organization's data security policies. It also allows for reviewing and investigating any related data security incidents (alerts) and the visualization and management of user activity on related endpoint devices.
Data protection
Forcepoint ONE Data Security includes best in class predefined compliance templates enabling simple single click compliance for PCI DSS, HIPAA, Intellectual Property, and PII.
Device Control
Device Control enables organizations to manage the use of removable storage devices connected to user endpoints.
User Activity Monitoring
User activity monitoring capability alerts organizations of risky user behavior so they can protect data and reduce risks.
Endpoint management
Endpoint management enables organizations to centrally manage all their related endpoints through the Forcepoint ONE Data Security portal, streamlining management and ensuring consistent security throughout the organization.
Help and support
Access Forcepoint help and support services for assistance and troubleshooting on support.forcepoint.com.
Product updates
Details of new and updated features, as well as known issues.
Sign into the management portal
Signing into the management portal with multi-factor authentication ensures that your account remains secure.
Supported browsers
The management portal is supported only on certain web browsers.
Enabling multi-factor authentication
When you first sign in, you will be prompted to select an authentication method.
Changing the password
You can change your password at any time when you are signed into Forcepoint ONE Data Security portal.
SAML SSO Configuration
Forcepoint ONE Data Security portal supports login via SAML compliant identity providers. This helps the user to log in to the portal using SSO.
Login with SAML SSO
The cloud portal supports login via SAML identity providers like Okta and Azure.
Endpoint management
Endpoint management dashboard is used to view and manage your Forcepoint endpoints.
My Endpoints
The My Endpoints tab lists the endpoints, the agents status on the endpoint, and other details such as the operating system running on the endpoint, the domain and logged in user information, etc.
Profiles
Profiles are a set of attributes that define the endpoint agent behavior. The Default profile can be configured by each tenant to support its sepcific needs. Profiles can also be used to set different behavior for different segments in the same tenant.
Agent installation
This section captures the steps for installing the agent on the endpoints in your organization.
Release code
Agent update
If you have previously installed the agent on your endpoints, you can update to the latest version manually or automatically when a new version is available, or on demand to meet your schedule.
Agent status
The Endpoint management dashboard and Details panel display the status of the agent running on each endpoint.
Agent Interoperability
Dashboards
Dashboards provide overview on Users, Endpoints, and Devices.
Users
Use the Users dashboard to gain a high-level view of user activities in your organization.
Endpoints
Use the Endpoints dashboard to gain a high-level view on the status of agents in your organization.
Devices
Investigation
Investigation displays a list of all your end-users, alerts or devices allowing you to view and filter related activities to drill down for further information.
Users
In the Users panel, you can view per user details on risk level, most recent activity, alerts, and other details.
Alerts
The Alerts tab displays detailed information on alerts recorded in the organization. For each alert the severity, reporting time, rule name, category, user, reporting products, and other details are displayed in a tabular view.
Devices
Devices investigation provides advanced tool to search, analyze, and obtain the device usage insights based on the correlation of users and endpoints.​
User Details
The Forcepoint agent has the ability to automatically retrieve attributes from Active Directory to enrich user information reported to the Forcepoint ONE Data Security service. The following table displays the Active Directory attributes used. This information displays on the Overview panel.
Policy
Forcepoint ONE Data Security policies enable monitoring and control of the flow of sensitive data throughout an organization.
Data protection
Data protection comes with a rich set of predefined policies that cover the data requirements for a wide variety of organizations. Policies can be customized to meet an organization's specific needs, ensuring that sensitive data is always protected from unauthorized access, use, and disclosure.
Device control
Device control is a measure of protection that restricts user access to removable storage devices.
User activity monitoring
Using the User activity monitoring tab, administrators can customize the IOBs (modify the IoB predefined severity and exclude or include certain users and groups).
Policy Elements
Policy elements are the building blocks which include the resources and classifiers.
Settings
The Settings dashboard provides access to user configuration for your organization. Administrators can use this dashboard to set up accounts and view tenant information. Analysts or Helpdesk admins do not have access to this dashboard.
Admins
Three types of users have access to the cloud portal: administrators, analysts, and Helpdesk.
Email
Forcepoint DLP for Cloud Email helps prevent data leaks via the email channel.
Audit log
Audit logs are generated when a create, edit, or delete of a new user, password change​, generation of master, endpoint, or bypass release code​, deleting an endpoint​, exporting data​, changes to OTA update configurations​, changes to device control policy​ etc. happen.
Advanced
The Advanced tab allows the administrators to integrate with Amazon Replication Service and External Identity Providers.
Download Agent
The Download Neo option on all Settings tabs allows administrators to download the specific agent versions.
Integrating with on-premise DLP for Risk-Adaptive DLP
User Activity Monitoring can be integrated with On-Premise DLP to enable Risk-Adaptive DLP for on-premise DLP policies. This automates DLP policy enforcement based on the user's risk level.
Integrating with Forcepoint Cloud Security Gateway
The Forcepoint ONE Data Security Agent provides the capability to send data to Forcepoint Web Security Cloud for analysis through either a proxy connection or a direct connection.