The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Trellix Data Loss Prevention Endpoint for Windows 11.10 Update 2 (11.10.200) Release Notes

Prev Next

The Trellix DLP Endpoint for Windows 11.10 Update 2 release includes new features and resolved issues.

Rating for 11.10 Update 2 (11.10.200)

The rating defines the urgency for installing this update.

Mandatory

This release is mandatory for all environments. Failure to apply mandatory updates might result in a security breach. Mandatory updates resolve vulnerabilities that might affect product functionality and compromise security. You must apply these updates to maintain a viable and supported product.

For more information, see KB51560

Release details

Release date - December 14, 2023

Release builds:

  • Trellix Data Loss Prevention Endpoint client build 11.10.200.162

Important

We are aware of a BSoD issue with Intel 11th Gen CPUs. It is recommended not to deploy Trellix DLP Endpoint v11.9.0 to these specific systems until the issue is fixed. For more information, see KB95295.

Note

Trellix DLP Endpoint 11.10 Update 2 (11.10.200) requires Trellix DLP 11.10.201.10 extension. Trellix DLP Endpoint 11.10 Update 2 (11.10.200) client software is not compatible with earlier versions of Trellix DLP extensions.

For the specific build numbers, see Product release information in KB68147.

Note

Release to Support (RTS) releases are limited-availability releases intended for customers known to have issues resolved in the release. To align our release process with that of other Trellix product releases, the Trellix DLP team recommends that these packages should only be installed in lab environments or in limited numbers of production systems for verification of the fixes and making sure that there are no unexpected errors. Trellix does not recommend widely deploying RTS packages in production environments.

Note

Pre-Release or Beta builds are highly restricted releases that have been through partial / essential testing only. Such releases are intended for customers who have agreed to partner with us on the testing process in a more detailed and collaborative way to facilitate early access and a greater level of testing and feedback. These packages should only be installed in lab environments or on a limited number of endpoint systems in production environments. It is not recommended to use Trellix ePO - On-prem or other management tools, unless within a lab environment. To make sure that usage does not extend beyond these terms, Trellix also recommends these packages to be tightly controlled and not distributed to individuals other than those working directly with Trellix.

Data Loss Prevention (DLP) feature release

Trellix DLP 11.10.0 is a feature release version. New features, which include customer-raised product ideas are added only to the feature release versions. The most recent Long-Term Support release version of Trellix DLP Endpoint is 11.6.600. As such, version 11.10.0 doesn't end support for any previous release.

For more information about different kinds of releases, see KB91807.

Data Loss Prevention (DLP) Long-Term Support Release

Important - Trellix is enhancing its Trellix DLP release process. Each release is defined as either a Long-Term Support release or Feature Release. Feature release introduces new features. Long-Term Support (LTS) release allows customers (under tight change control) to maintain a stable Trellix DLP version without changes to functionality and existing features. The LTS release will include only security updates, bug fixes, and some optimization for the existing features using patches or hotfixes. These releases will continue to be fully installable packages.

Note

The LTS latest release for Trellix DLP Endpoint is version 11.10.200 (11.10 Update 2) to ensure high quality before becoming the stable LTS build.

For more information about LTS releases, see KB91807.

Upgrade paths not supported

Upgrade from 11.6.700, 11.9.0, 11.9.100, 11.10.0, 11.10.100 to 11.10.200 is not supported if you are running Windows 7 service pack 1, Windows 2012 R2, or Windows 8.1. However, you can still install Trellix DLP Endpoint 11.10.200 for the first time on Windows 7 service pack 1, Windows 2012 R2, or Windows 8.1.

Important

Installing Trellix DLP Endpoint 11.10.200 for the first time on Windows 7 requires the SHA-2 code signing support update, You can learn more about SHA-2 code signing support update at Microsoft support.

Updated platform, environment, or operating system support

For additional information on supported platforms, environments, and operating systems, see KB68147.

New or changed features

This release introduces new features or improves existing features:

Setting the confidence threshold in manually registered documents - Trellix Data Loss Prevention allows you to configure the number of fingerprints that must be matched in a manually fingerprinted document to trigger a violation. This helps in increasing the detection confidence as it minimizes false positives by triggering more accurate detections and reduces the analysis time.

An incident is triggered when the number of matches is equal to or higher than the set confidence threshold. You can set the Confidence Threshold percentage between 10 to 100 percentage. For example, if a fingerprinted document generates 100 signatures, and if you select 10%, then 10 signatures are matched at random in the scanned document.

To set the threshold percentage go to, Classification → Register Documents → Manual Registration → Confidence Threshold.

Note

Ignored list signatures are not considered for matching.

Adding visual labels to Microsoft Office documents- Visual labeling is a document labeling solution for Microsoft Office documents (Word, Excel, and PowerPoint) that forces users to manually select the classification before saving a document. You can use this method to display visual labels in the header, footer, and watermark of the document as supported by Microsoft Office applications to identify its sensitivity and label the document without the use of third-party tools. For more information on visual labeling, see the Classifying files manually topic in the Product Guide.

Enhanced screen capture protection - Screen capture actions performed using Universal Windows Platform apps, such as Snip & Sketch are now protected by Trellix DLP Endpoint.

Important

In Windows 11, Trellix DLP Endpoint only supports data protection with the snip option. However, it does not provide data protection if the screen is recorded.

Block Gen AI URLs - Web Application Control feature in Trellix DLP Endpoint now allows you to block access to generative AI websites. To block a new generative AI website go to, DLP Policy Manager → Definitions → URL List → Action → New.

Monitor text upload to Gen AI prompts - In the web protection page, you can now add web URL tags in order to monitor text uploads to the generative AI website. As a result, corporate devices can be monitored in order to avoid sensitive data leak. For additional information on finding tags for other websites, see KB96881.

Support for Island Browser - This beta release feature for Island browser supports the Web protection rules, Printer protection rules, Clipboard protection rules, and screen capture protection rules that monitor or protect the activities in Island browser. For additional information on the Island browser support, see KB96904.

Drag and drop - This release provides you with an option to optionally disable drag and drop of attachments from Microsoft Outlook into supported Chromium browsers.

Known issues

Trellix DLP Endpoint process crashes on Control Flow Enforcement Technology (CET) or Hardware-enforced Stack Protection (HSP) enabled endpoints when integrated with Titus or AIP. For more information, see KB96826

For a list of current known issues, see: Trellix Data Loss Prevention 11.x.x Known Issues (KB89301).

Resolved issues

This update resolves known issues and customer reported issues.

For the DLP Extension related resolved issues, see the  Trellix Data Loss Prevention Extension 11.10.201 Release Notes.

Vulnerability issues

Reference

Resolution

CVE-2023-4814

SB10407

Fixed an issue where the Trellix DLP Endpoint deleted empty folders outside the DLP logs folder when a junction point was added inside the DLP logs folder.

This issue was fixed by removing the directory junction or symbolic link present in the logs folder before cleaning up older logs. This fix broke the link between the logs folder and folders outside the logs folder. As a result, folders placed outside the DLP logs folder remain safe. The program also keeps track of temp folders and prevents the creation of directory junctions or symbolic links. For more information about vulnerability and remediation, see SB10407



Resolved issues

Reference

Resolution

DLPW-6265

Fixed an issue where web application control did not monitor or block website access in Firefox.

DLPW-7985

Fixed an issue where the web protection rules did not block the files uploaded to a website from a shared network.

DLPW-8609

Fixed an issue where the destination URL was displayed incorrectly on the DLP Incident Manager page when a file was uploaded.

DLPW-8686 and DLPW-9088

Fixed an issue where the encrypted emails were held in the DLPOutbox, even if the mails were sent from Microsoft Outlook.

DLPW-9074

Fixed an issue where the uppercase letters in the file name are changed to lowercase letters when a discovery scan is performed on Trellix DLP Endpoint.

DLPW-9099

Fixed an issue where the Outlook Background Processing resets the specified maximum analysis time.

DLPW-9252

Fixed an issue where the password sharing rule was not functioning properly when multiple password validators were used in the ruleset.

DLPW-9469

Fixed an issue where Trellix DLP Endpoint prevented files from being moved from the Local drive to Google Drive for Desktop.

DLPW-9584

Fixed an issue where Azure Information Protection (AIP) labeled emails failed to display content markings in the email when Trellix DLP add-in was running.

DLPW-9646

Fixed an issue where the GPT.ini file gets corrupted whenever a change was made to the DLP policy or to the Windows client configuration.

DLPW-9662

Fixed an issue where emails sent were held in the outbox of Microsoft Outlook.

DLPW-9665 and DLPW-9080

Fixed an issue where multiple duplicate emails were displayed in the outbox of Microsoft Outlook.

DLPW-9746

Fixed an issue that caused the DLP Incident Manager → Classifications → Unique Match Strings to display 0 rather than 1 when a definition was triggered.

DLPW-9761

Fixed an issue where zipped folders containing PNG or JPEG files were blocked, even if the folder was added as an exception.

DLPW-9806 and DLPW-8673

Fixed an issue where Trellix DLP Endpoint failed to prevent file uploads from Microsoft Edge and Google Chrome browsers using Distributed File System (DFS) paths.

DLPW-9809

Fixed an issue that prevented Microsoft Edge and Google Chrome browsers from loading websites when Trellix DLP Endpoint was installed.

DLPW-9820

Fixed an issue where Microsoft Outlook crashed and could not accept or send meeting invites when the Trellix DLP add-in was running.

DLPW-9859

Fixed an issue where Microsoft Edge and Google Chrome browsers load slowly when fcagchrome64.dll is enabled.

DLPW-9862

Fixed an issue where the print protection rule failed to trigger incidents when the content classification with file information was used.

DLPW-9912

Fixed an issue where the application access protection rules did not block the feishu.exe application.

DLPW-9972

Fixed an issue with clipboard protection that did not prevent copying and pasting into the Firefox browser when the source destination was set to Is any web URL in the Condition tab.

DLPW-9986

Fixed an issue where .dll file types were not mapped to executable file types, which caused false positive incidents.

DLPW-9991

Fixed an issue where Trellix DLP Endpoint could not be installed on Windows Virtual Desktop for Windows 10 and Windows 11 version 22H2.

DLPW-10028

Fixed an issue where Trellix DLP Endpoint was deleting empty folders using the Junction method.

DLPW-10071

Trellix DLP Endpoint for Windows now detects and reports Internet Calendar Scheduling (ICS) files.

DLPW-10148

Fixed an issue in which Trellix DLP failed to monitor credit card numbers stored in a text file.

DLPW-10187

Fixed an issue in which Microsoft Outlook messages were sent to the draft or outbox folders when using Trellix DLP Endpoint 11.10.0

DLPW-10396

Fixed an issue where false positives were generated when the application file access protection rule was configured on Microsoft Teams.

DLPW-10500

Fixed an issue where multiple users could access sensitive text files downloaded to the DLP/Temp folder.