Trellix DLP Endpoint and Trellix DLP Discover support two Rights Management (RM) systems: Microsoft Windows Rights Management Services (RMS) and Seclore FileSecure™. To use these systems, configure the server providing the RM policies in ePO - On-prem.
Set up the RM servers according to the Microsoft or Seclore instructions and create users and policies. Obtain the URL and password for all servers — policy template, certification, and licensing.
If you are adding an Azure server for integration with Azure Information Protection, you need to first register a client application with Azure Active Directory. See article 000007114 for details about registering a client application with Microsoft Azure.
For Seclore, you need the Hot Folder Cabinet ID and passphrase, and information about advanced licenses, if any.
Verify that you have permission to view, create, and edit Microsoft RMS and Seclore servers. In ePO - On-prem, select Menu → User Management → Permission Sets, and verify that you belong to a group that has the needed permissions in Registered Servers.
Install Active Directory Rights Management Services Client 2.1 build 1.0.2004.0 on each endpoint using RM services. The Apply RM command doesn't work without this version of the RM client.
In Trellix ePolicy Orchestrator - On-premises, select Menu → Registered Servers.
Click New Server.
The Registered Servers description page opens.
From the Server type drop-down list, select the type of server you want to configure: Microsoft RMS Server, Azure Server, or Seclore Server.
Type a name for the server configuration, then click Next.
Enter the required details. When you have entered the required fields, click Test Connectivity to verify the data entered.
RMS settings also include a DLP enforcement settings section. The Local path to RMS template field is optional, but the URL fields for certification and licensing are needed unless you choose the AD auto-service discovery option.
Seclore requires HotFolder Cabinet information, but more license information is optional.
Azure Server settings require:
Rights management owner is the user that owns all files that are protected with Azure RMS rule reaction.
Application (Client) ID, Directory (Tenant) ID, and Client Secret as defined in the Azure application registration details.
Azure Label IDs and Names as it appears in your Azure account. These labels can be selected for protection in rule reactions.
Click Save when you have completed the configuration.