Go to the table of contents Go to the previous page Go to the next page View or print as PDF
New in Forcepoint DLP
Release Notes | Forcepoint DLP | v8.4.0 | 31-July-2017
Version 8.4.0 of Forcepoint DLP offers several new features and product updates.
Forcepoint DLP New Features
Product and component renaming
In this release, Forcepoint has introduced a simplified and more descriptive product and component naming scheme. Key changes for this product include:
 
Fresh toolbar design
The Forcepoint Security Manager banner and toolbars have been combined and streamlined. The functionality has not changed, but the toolbars now have a smaller footprint, allowing more room to display the main content of the application.
Although the Appliances, Global Settings, and Help toolbar buttons have been made more compact, their functionality is still available. Find the new buttons at the top of the page, next to the name of the logged-on administrator.
Improved performance
Performance has been enhanced for the following features and functions:
*
*
*
Forcepoint DLP Cloud Applications data in motion support for Box
Forcepoint DLP Cloud Applications now includes data-in-motion support for files uploaded and shared within the Box cloud content management platform. As with Microsoft OneDrive for Business, when the Cloud Services channel is enabled in DLP policies, the cloud agent can be used to audit or remediate the uploading or sharing of sensitive data within the cloud service.
Once the cloud agent has been installed and registered, select it on the Settings > Deployment > System modules page to configure its connection to Box.
 
Incident risk ranking enhancements
*
With this feature, administrators can bring in information about known high-risk employees or contractors from external data sources (such as an HR system) and have that information factored into the incident risk ranking process.
a.
b.
In this release, only user resources can be added as high-risk resources. If a business unit added as a high-risk resource contains other types of resources, the non-user resources are not considered for risk scoring.
c.
Select Use high-risk resources for risk scoring to enable the feature.
*
*
Reporting permissions to access Incident Risk Ranking reports can now be granted or denied in administrative roles.
*
For example, if unsecured sensitive content is sent daily from several users to a business partner, the users are probably not aware that they are doing something wrong. This classification is based on factors such as recurring patterns that could indicate common behavior.
*
This gives administrators a more complete picture of a user's activity across multiple channels. It also reduces clutter in the incident risk ranking reports, allowing cases from more users to appear on the same page.
Microsoft RMS integration
Forcepoint DLP now integrates with Microsoft Azure Information Protection using Microsoft Rights Management Service (RMS). This allows Forcepoint DLP Endpoint to apply DLP policies to Microsoft RMS encrypted files on Windows endpoints.
This feature enables enterprises to maintain sensitive data visibility and control for files protected using Microsoft Azure and AD RMS. It can also be used to better understand how Microsoft RMS is being used by employees to protect sensitive data.
Data classification enhancements
Policy rule configuration now includes the option to target DLP classifiers in file metadata. This allows Forcepoint DLP to detect data classification labels applied by Forcepoint data classification partners, including Microsoft, Boldon James, and Titus.
To configure metadata and custom header analysis, edit content classifier properties on the Condition tab of a selected DLP policy rule.
Increased maximum file size for analysis
The maximum file size for files analyzed through Web Content Gateway and ICAP-based integrated proxies has been raised to 50 MB.
ICAP support for cloud-based deployments
The Forcepoint DLP Cloud Agent can now be configured to use ICAP for web proxy integration. The configuration process for cloud agent ICAP support is the same as for protector ICAP support, and is described in the Forcepoint DLP Administrator Help.
Discovery task status reports and error messages
Administrators creating or editing a discovery task can now configure the product to send a status report via email when the discovery task is complete. By default, the email message includes information about the task name and type, as well as the task start and end time, enabling administrators to keep a detailed audit log of each completed discovery task.
In order for the email report option to function, port 17514 must be open for incoming connections (inbound) in the Windows firewall on the Forcepoint management server machine.
Configure the emailed status report on the new Email Report page in the discovery task wizard:
To aid in troubleshooting, data discovery error messages have been enhanced to provide more detail about the reason for the scanning failure (for example, when an item was not found, or a connectivity error occurred). In the past, the same error message might appear differently in different places. Now, the message is consistent, regardless of where it appears.
In addition, administrators how have the option to specify whether to include all transactions or only error transactions in downloaded and email discovery reports. configure this option on the Advanced page in the discovery task wizard.
New and enhanced policies, rules, and classifiers
With the policies added in this release, Forcepoint DLP now has full PII policy coverage for EU countries. In addition, a European General Data Protection Regulation (GDPR) policy category has been added.
New
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
Enhanced
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
Removed
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
Other enhancements
*
a.
Go to the Settings > Authorization > Roles page and select or create a role.
b.
On the Role page, under Reporting > Data loss prevention, mark Hide source and destination to anonymize reports for administrators assigned to the role.
c.
Click OK to save the change.
*
*
*
*
The Microsoft Visio File classifier was also updated, and a classifier and rule for detecting Borland Reflex 2 database files were added.
Forcepoint DLP Endpoint New Features
Support for macOS 10.12.2, 10.12.3, 10.12.4, and 10.12.5 (Sierra)
Forcepoint DLP Endpoint can now run on the macOS operating systems 10.12.2, 10.12.3, 10.12.4, or 10.12.5.
Also, Mac Mail 10.3, which was introduced with macOS 10.12.4, is supported.
 
Note 
Some features are not supported in this release:
*
*
*
Support for Secure Boot mode in Windows 10, version 1607
Forcepoint DLP Endpoint can now be installed on Windows 10 endpoints with Secure Boot enabled. When Secure Boot is enabled, Windows only loads kernel mode drivers that are digitally signed by Microsoft. In this release of Forcepoint DLP Endpoint, all affected drivers are digitally signed.
This change affects all new installations of Windows 10, version 1607. Starting with Windows 10, version 1607, Microsoft has enabled Secure Boot by default for all new installations. System upgrades from an earlier Windows operating system to Windows 10, version 1607, are not affected by this change.
For more information on driver signing changes in Windows 10, version 1607, see the following Microsoft article.
Support for Windows 10 Creators Update, version 1703
Forcepoint DLP Endpoint can now be installed on the new Windows 10 Creators Update, version 1703.
 
Note 
User confirmation dialog timeout updates
The dialog box used to get confirmation from end users when they perform a disallowed endpoint operation has been updated.
Users are still given 30 seconds to respond, by default, but the time may now be customized. You may now set the timeout length, per channel, to between 9 and 58 seconds.
Also, the confirm action now works on the HTTP/HTTPS channel. The confirm action was disabled on the HTTP/HTTPS channel in TRITON AP-ENDPOINT v8.3. With the addition of HTTP/HTTPS support in v8.4, all endpoint channels are now supported.
The confirmation dialog is shown when the Confirm action is selected for one or more endpoint channels in an action plan in the Forcepoint Security Manager.
The Confirm action is only available on endpoints that are installed with Interactive mode. In Stealth mode, users are never prompted for action.

Go to the table of contents Go to the previous page Go to the next page View or print as PDF
Copyright 2017 Forcepoint. All rights reserved.