The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Trellix Data Loss Prevention Extension 11.10 Update 12 (11.10.201) Release Notes - December 2023

Prev Next

Trellix Data Loss Prevention Extension 11.10 Update 12 (11.10.201) Release Notes

Trellix Data Loss Prevention extension release 11.10 Update 12 (11.10.201) includes new features.

Every update release is cumulative and includes all features and fixes from the previous release. We recommend that you always upgrade to the most current update.

Rating for 11.10 Update 12 (11.10.201) extension

The rating defines the urgency for installing this update.

Recommended

This release is recommended for all environments. Apply this update at the earliest convenience.

For more information, see KB51560.

Release Details

Release date: December 14, 2023

Release build: Trellix Data Loss Prevention extension 11.10.201.10

Note

Trellix Data Loss Prevention extension 11.10.201.10 is compatible with Trellix ePO - On-prem 5.10 CU15 only for the purpose of Trellix ePO - On-prem upgrade. However, it is highly recommended to install Trellix ePO - On-prem 5.10 SP1 Update 1 (CU17) or SP1 Update 2 (CU18) immediately without modifying the Trellix DLP policies.

New or Changed features

Disabling file deletion on quarantine folders - Trellix Data Loss Prevention extension is now enhanced with new functionality to prevent the automatic deletion of quarantine files based on time limits. This feature allows you to avoid the deletion of quarantine files in quarantine folders and achieve the goal of "never deleting the quarantine files". To prevent deletion of quarantine files go to, Policy Catalog → Data Loss Prevention → Windows Client Configuration → Quarantine and set the value of Quarantine duration (Days) to "0".

Adding visual labels to Microsoft Office documents - Visual labeling is a document labeling solution for Microsoft Office documents (Word, Excel, and PowerPoint) that forces users to manually select the classification before saving a document. You can use this method to display visual labels in the header, footer, and watermark of the document as supported by Microsoft Office applications to identify its sensitivity and label the document without the use of third-party tools. For more information on visual labeling, see Manual classification topic in the Product Guide.

Block Gen AI URLs - Web Application Control feature in Trellix DLP Endpoint now allows you to block access to generative AI websites. To block a new generative AI website go to, DLP Policy Manager → Definitions → URL List → Action → New.

Monitor text upload to Gen AI prompts - In the web protection page, you can now add web URL tags in order to monitor text uploads to the generative AI website. As a result, corporate devices can be monitored in order to avoid sensitive data leak. For additional information on finding tags for other websites, see KB96881.

Support for Island Browser - This beta release feature for Island browser supports the Web protection rules, Printer protection rules, Clipboard protection rules, and screen capture protection rules that monitor or protect the activities in Island browser. For additional information on the Island browser support, see KB96904.

Resolved issues

For the DLP Endpoint for Windows related resolved issues, see the Trellix Data Loss Prevention Endpoint for Windows 11.10.x Release Notes.

For the DLP Endpoint for Mac related resolved issues, see the Trellix Data Loss Prevention Endpoint for Mac 11.10.x Release Notes.

For the DLP Discover related resolved issues, see the Trellix Data Loss Prevention Discover 11.10.x Release Notes.

For the DLP Prevent related resolved issues, see the Trellix Data Loss Prevention Prevent 11.10.x Release Notes.

For the DLP Monitor related resolved issues, see the Trellix Data Loss Prevention Monitor 11.10.x Release Notes.

Resolved issues

Reference

Resolution

DLPO-13758

Fixed an issue where Edit link did not work in the Classification and Register Documents tabs when the classification was linked with other DLP items in the Classification page.

Known issues

For a list of current known issues, see Trellix Data Loss Prevention 11.x.x Known Issues (KB89301).

Trellix Data Loss Prevention Extension 11.10 Update 11 (11.10.200) Release Notes

Trellix Data Loss Prevention extension release 11.10 Update 11 (11.10.200) includes resolved issues.

Every update release is cumulative and includes all features and fixes from the previous release. We recommend that you always upgrade to the most current update.

Rating for 11.10 Update 11 (11.10.200) extension

The rating defines the urgency for installing this update.

Recommended

This release is recommended for all environments. Apply this update at the earliest convenience.

For more information, see KB51560.

Release Details

Release date: November 27, 2023

Release build: Trellix Data Loss Prevention extension 11.10.200.7

small blue note icon Note

Trellix Data Loss Prevention extension 11.10.200.7 is supported on Trellix ePO - On-prem 5.10 SP1 Update 1 (CU17) and SP1 Update 2 (CU18),

Resolved issues

For the DLP Endpoint for Windows related resolved issues, see the Trellix Data Loss Prevention Endpoint for Windows 11.10.x Release Notes.

For the DLP Endpoint for Mac related resolved issues, see the Trellix Data Loss Prevention Endpoint for Mac 11.10.x Release Notes.

For the DLP Discover related resolved issues, see the Trellix Data Loss Prevention Discover 11.10.x Release Notes.

For the DLP Prevent related resolved issues, see the Trellix Data Loss Prevention Prevent 11.10.x Release Notes.

For the DLP Monitor related resolved issues, see the Trellix Data Loss Prevention Monitor 11.10.x Release Notes.

Resolved issues

Reference

Resolution

DLPO-13757

Fixed an issue where importing evidence from Skyhigh Security Cloud displayed an error and failed to import into Trellix ePO - On-prem.

Known issues

For a list of current known issues, see Trellix Data Loss Prevention 11.x.x Known Issues (KB89301).

Trellix Data Loss Prevention Extension 11.10 Update 10 (11.10.100) Release Notes

Trellix Data Loss Prevention extension release 11.10 Update 10 (11.10.100) includes changes to the existing features and resolved issues.

Every update release is cumulative and includes all features and fixes from the previous release. We recommend that you always upgrade to the most current update.

Rating for 11.10 Update 10 (11.10.100) extension

The rating defines the urgency for installing this update.

Recommended

This release is recommended for all environments. Apply this update at the earliest convenience.

For more information, see KB51560.

Release Details

Release date: October 25, 2023

Release build: Trellix Data Loss Prevention extension 11.10.100.8

A change has been made to the versioning of Trellix Data Loss Prevention extension from 11.xx.xx to 11.xx.xxx.

Note

Trellix Data Loss Prevention extension 11.10.100.8 is supported only on Trellix ePO - On‑prem 5.10 SP1 Update 1 (CU17).

Changed features

Custom Backup & Restore - The DLP Settings → Backup & Restore page now allows you to select policies for backup and restore them into an another Trellix ePO - On‑prem.

Custom restore allows you to choose between Retain Existing and Override Existing in the event of a conflict. Choosing Retain Existing retains the current policies and rules present in the Trellix ePO - On‑prem, while choosing Override Existing replaces the existing policies and rules. In this way, you can manage conflicts and ensure that the correct policies and rules are imported.

Additionally, custom restore option can automatically display the hierarchy of configurations and highlight either the Retain Existing or Override Existing options in green.

Considering embedded files as separate files during the scan - This release introduces an update to the way embedded files or files that contain sub-files are treated during the scan:

  • The text from embedded files is extracted into a separate file and scanned in isolation.

  • Every embedded file will have its own match details uploaded if there is a match.

  • The path of the parent and the relative path of the child file is mentioned in the evidence details.

Underscore in exact data matching (EDM) - Legacy tokenization treats underscore as an alphabet and expects both scanning and indexing documents to match underscore regardless of its position. Starting with this release, the underscore in EDM is:

  • Ignored if a word is surrounded by an underscore.

  • Considered a word separator, if a word contains an underscore in between. For example, in the mail ID xxxx_yy@zz.com, underscore is considered a word breaker, and the mail ID is divided into two tokens, "xxxx" and "yy@zz.com". An incident is reported even when the sample or scanned document has an underscore anywhere in a word, but the fingerprinted document doesn't.

The enhanced EDM solution offers the following advantages:

  • Improved scanning performance and speed

  • Reduced number of false positives generated

Small blue note icon

Note

To apply the change in underscore tokenization, reindex exact data match fingerprint with the EDMTrain tool.

Setting the confidence threshold in manually registered documents - Trellix Data Loss Prevention allows you to configure the number of fingerprints that must be matched in a manually fingerprinted document to trigger a violation. This helps in increasing the detection confidence as it minimizes false positives by triggering more accurate detections and reduces the analysis time. An incident is triggered when the number of matches is equal to or higher than the set confidence threshold. You can set the Confidence Threshold percentage between 10 to 100 percentage. For example, if a fingerprinted document generates 100 signatures, and if you select 10%, then 10 signatures are matched at random in the scanned document.

To set the threshold percentage go to, Classification → Register Documents → Manual Registration → Confidence Threshold.

Small blue note icon

Note

Ignored list signatures are not considered for matching.

Resolved issues

For the DLP Endpoint for Windows related resolved issues, see the Trellix Data Loss Prevention Endpoint for Windows 11.10.x Release Notes.

For the DLP Endpoint for Mac related resolved issues, see the Trellix Data Loss Prevention Endpoint for Mac 11.10.x Release Notes.

For the DLP Discover related resolved issues, see the Trellix Data Loss Prevention Discover 11.10.x Release Notes.

For the DLP Prevent related resolved issues, see the Trellix Data Loss Prevention Prevent 11.10.x Release Notes.

For the DLP Monitor related resolved issues, see the Trellix Data Loss Prevention Monitor 11.10.x Release Notes.

Resolved issues

Reference

Resolution

DLPO-11839

Fixed an issue where a Server Task called DLP Sync users from LDAP had a run time exceeding 10 hours.

DLPO-11984

Fixed a resolution issue on the Classification page when using the zoom function in Google Chrome.

DLPO-12392

Fixed an issue where the Trellix ePO - On‑prem server task failed to display evidence details and classification details in the DLP Incident Manager page.

DLPO-12530

Fixed an issue where the Queries and Reports page displayed the following error: An unexpected error occurred when drilling down into the reports.

DLPO-12649

Fixed an issue in which there was no response after clicking the Backup to file button.

DLPO-12755

Fixed an issue where Application file access protection (AFAP) rules were not applied by DLP policies.

DLPO-12954

Fixed an issue with DLP incidents not displaying seconds information in the timestamp.

Known issues

For a list of current known issues, see Trellix Data Loss Prevention 11.x.x Known Issues (KB89301).


Trellix Data Loss Prevention Extension 11.10 Update 9 (11.10.9) Release Notes

Trellix Data Loss Prevention extension release 11.10 Update 9 (11.10.9) includes changes to the existing features and resolved issues.

Every update release is cumulative and includes all features and fixes from the previous release. We recommend that you always upgrade to the most current update.

Rating for 11.10 Update 9 (11.10.9) extension

The rating defines the urgency for installing this update.

Recommended

This release is a high-priority for all environments. Failure to apply high priority updates might result in potential business impact.

This release is recommended for all environments. Apply this update at the earliest convenience.

For more information, see KB51560.

Release Details

Release date: August 10, 2023

Release build: Trellix Data Loss Prevention extension 11.10.9.6

Note

Trellix Data Loss Prevention extension 11.10.9.6 is supported only on Trellix ePO - On-prem 5.10 CU17.

Changed features

Trellix Data Loss Prevention extension now supports CSF serialization in Classification for Manual Registration → Confidence Threshold.

4 | Trellix Data Loss Prevention Extension 11.10 Update 12 (11.10.201) Release Notes


Resolved issues

For the DLP Endpoint for Windows related resolved issues, see the Trellix Data Loss Prevention Endpoint for Windows 11.10.x Release Notes.

For the DLP Endpoint for Mac related resolved issues, see the Trellix Data Loss Prevention Endpoint for Mac 11.10.x Release Notes.

For the DLP Discover related resolved issues, see the Trellix Data Loss Prevention Discover 11.10.x Release Notes.

For the DLP Prevent related resolved issues, see the Trellix Data Loss Prevention Prevent 11.10.x Release Notes.

For the DLP Monitor related resolved issues, see the Trellix Data Loss Prevention Monitor 11.10.x Release Notes.

Resolved issues

Reference

Resolution

DLPO-11751

Fixed an issue where Trellix ePO - On-prem server's cache folder was getting full due to dlpenc evidence files.

DLPO-11842

Fixed an issue where the Server Task was edited automatically after upgrading the Trellix DLP extension.

DLPO-12266

Fixed an issue where built-in Classifications failed to detect and prevent data leaks of confidential information.

DLPO-12392

Fixed an issue in Skyhigh events where files containing new line (/n) or carriage return (/r) characters would not download to Trellix DLP and displayed an error.

DLPO-12413

Fixed an issue where the User Primary Email filed displayed blank in DLP Operations → User Information tab.

4 | Trellix Data Loss Prevention Extension 11.10 Update 12 (11.10.201) Release Notes


Known issues

For a list of current known issues, see Trellix Data Loss Prevention 11.x.x Known Issues (KB89301).

5 | Trellix Data Loss Prevention Extension 11.10 Update 12 (11.10.201) Release Notes


Trellix Data Loss Prevention Extension 11.10 Update 8 (11.10.8) Release Notes

Trellix Data Loss Prevention extension release 11.10 Update 8 (11.10.8) includes changes to the existing features.

Every update release is cumulative and includes all features and fixes from the previous release. We recommend that you always upgrade to the most current update.

Rating for 11.10 Update 8 (11.10.8) extension

The rating defines the urgency for installing this update.

Recommended

This release is a high-priority for all environments. Failure to apply high priority updates might result in potential business impact.

This release is recommended for all environments. Apply this update at the earliest convenience.

Release Details

Release date: July 25, 2023

Release build: Trellix Data Loss Prevention extension 11.10.8.3

Note

Trellix Data Loss Prevention extension 11.10.8.3 is supported only on Trellix ePO - On-prem 5.10 CU15 or later.

Changed features

  • Trellix Data Loss Prevention extension package no longer includes Microsoft Visual C++ 2010 Redistributable libraries.

  • Trellix ePO - On‑prem now supports the Microsoft JDBC driver instead of the jTDS database driver, as the jTDS database driver does not support automatic multi-subnet failover.

Resolved issues

There are no resolved issues in this release.


Trellix Data Loss Prevention Extension 11.10 Update 12 (11.10.201) Release Notes - December 2023    13

5 | Trellix Data Loss Prevention Extension 11.10 Update 12 (11.10.201) Release Notes


For the DLP Endpoint for Windows related resolved issues, see the Trellix Data Loss Prevention Endpoint for Windows 11.10.x Release Notes.

For the DLP Endpoint for Mac related resolved issues, see the Trellix Data Loss Prevention Endpoint for Mac 11.10.x Release Notes.

For the DLP Discover related resolved issues, see the Trellix Data Loss Prevention Discover 11.10.x Release Notes.

For the DLP Prevent related resolved issues, see the Trellix Data Loss Prevention Prevent 11.10.x Release Notes.

For the DLP Monitor related resolved issues, see the Trellix Data Loss Prevention Monitor 11.10.x Release Notes.

Known issues

For a list of current known issues, see Trellix Data Loss Prevention 11.x.x Known Issues (KB89301).


Trellix Data Loss Prevention Extension 11.10.7 Release Notes

Trellix Data Loss Prevention extension release 11.10.7 includes new features and resolved issues.

Every update release is cumulative and includes all features and fixes from the previous release. We recommend that you always upgrade to the most current update.

Rating for 11.10.7 extension

The rating defines the urgency for installing this update.

Recommended

This release is a high-priority for all environments. Failure to apply high priority updates might result in potential business impact.

This release is recommended for all environments. Apply this update at the earliest convenience.

Release Details

Release date: July 12, 2023

Release build: Trellix Data Loss Prevention extension 11.10.7.16

Note

Trellix Data Loss Prevention extension 11.10.7.16 is supported only on Trellix ePO - On-prem 5.10 CU14 or later.

New or changed features

Export or import rules — DLP Policy Manager → Rule sets now allows you to export or import rules as encrypted .xml files, including the conditions, exceptions, and reactions associated with the rule.

Skyhigh error logging — Skyhigh® failure is logged as an operational event and an automatic email notification is generated according to the rule criteria. You can select the rule criteria as Skyhigh Connection Error 4XX or Skyhigh Connection Error 5XX under DLP Operations → Operational Event Tasks → Rules → Rules criteria.


Resolved issues

This update resolves known issues.

For the DLP Endpoint for Windows related resolved issues, see the Trellix Data Loss Prevention Endpoint for Windows 11.10.x Release Notes.

For the DLP Endpoint for Mac related resolved issues, see the Trellix Data Loss Prevention Endpoint for Mac 11.10.x Release Notes.

For the DLP Discover related resolved issues, see the Trellix Data Loss Prevention Discover 11.10.x Release Notes

For the DLP Prevent related resolved issues, see the Trellix Data Loss Prevention Prevent 11.10.x Release Notes

For the DLP Monitor related resolved issues, see the Trellix Data Loss Prevention Monitor 11.10.x Release Notes

Resolved issues

Reference

Resolution

DLPO-11564

Fixed an issue in which changes made to a definition and saved did not display the pending changes message.

DLPO-11623

Fixed an issue where evidences download from Trellix ePO - SaaS to Trellix ePO - On-prem displayed an error message.

DLPO-11720

Fixed an issue that prevented the DLP Incident Manager → Analytics tab from displaying the information in full screen.

DLPO-12153

Fixed an issue where the exported .csv files from Queries & Reports did not match the actual list generated in Trellix ePO - On-prem.

Known issues

For a list of current known issues, see Trellix Data Loss Prevention 11.x.x Known Issues (KB89301).


Trellix Data Loss Prevention Extension 11.10.6 Release Notes

Trellix Data Loss Prevention extension release 11.10.6 includes new features and resolved issues.

Every update release is cumulative and includes all features and fixes from the previous release. We recommend that you always upgrade to the most current update.

Rating for 11.10.6 extension

The rating defines the urgency for installing this update.

Recommended

This release is a high-priority for all environments. Failure to apply high priority updates might result in potential business impact.

This release is recommended for all environments. Apply this update at the earliest convenience.

For more information, see KB51560.

Release Details

Release date: April 27, 2023

Release build: Trellix Data Loss Prevention extension 11.10.6.11

Note icon — pencil in a square Note

Trellix Data Loss Prevention extension 11.10.6.11 is supported only on Trellix ePO - On-prem 5.10 CU14 or later.

New or changed features

Classification grouping — Classification grouping enables you to construct multiple conditions based on your needs by using AND or OR operations. The previous version only enabled creating homogeneous rules, which resulted in creation of complicated and repeated rules. The current approach helps you establish a simpler and more diverse collection of Boolean rule sets. For example, you can write a custom rule that looks like ((1 AND 2) or (1 AND 3)), 1 AND (2 or 3) AND 4, and many more.

Manual fingerprint threshold — Trellix DLP Discover is supported with a new feature in which you can set a threshold for signatures or fingerprints that match sensitive information in registered documents under Manual Document registration.


Trellix Data Loss Prevention Extension 11.10 Update 12 (11.10.201) Release Notes - December 2023 17

7 | Trellix Data Loss Prevention Extension 11.10 Update 12 (11.10.201) Release Notes


Classifications with the / character — It is now possible to include a slash / in the classification name.

Resolved issues

This update resolves known issues.

For the DLP Endpoint for Windows related resolved issues, see the Trellix Data Loss Prevention Endpoint for Windows 11.10.x Release Notes.

For the DLP Endpoint for Mac related resolved issues, see the Trellix Data Loss Prevention Endpoint for Mac 11.10.x Release Notes.

For the DLP Discover related resolved issues, see the Trellix Data Loss Prevention Discover 11.10.x Release Notes

For the DLP Prevent related resolved issues, see the Trellix Data Loss Prevention Prevent 11.10.x Release Notes

For the DLP Monitor related resolved issues, see the Trellix Data Loss Prevention Monitor 11.10.x Release Notes

Resolved issues

Reference

Resolution

DLPO-11602

Fixed an issue where large properties, such as 'undefinedDeviceClassesList' field for the table 'udlp_computerproperties', with greater than 4000 characters were truncated.

DLPO-11495

Fixed an issue where Trellix ePO - On-prem displayed a Page Unresponsive message when creating a Classification.

DLPO-11530

Fixed an issue where the DLP Incident Manager → Incident list had a discrepancy in the number of incidents generated.

DLPO-10297

Fixed an issue where the evidence generated from Skyhigh® Security Cloud was not uploaded to the correct evidence share location. Instead, it was uploaded to the Trellix ePO - On-prem server cache, causing a cache overflow.

7 | Trellix Data Loss Prevention Extension 11.10 Update 12 (11.10.201) Release Notes


Known issues

For a list of current known issues, see Trellix Data Loss Prevention 11.x.x Known Issues (KB89301).


Trellix Data Loss Prevention Extension 11.10 Update 12 (11.10.201) Release Notes - December 2023

19

Trellix Data Loss Prevention Extension 11.10.5 Release Notes

Trellix Data Loss Prevention extension release 11.10.5 includes new features and resolved issues. It also addresses product rebranding changes.

Every update release is cumulative and includes all features and fixes from the previous release. We recommend that you always upgrade to the most current update.

Rating for 11.10.5 extension

The rating defines the urgency for installing this update.

Recommended

This release is a high-priority for all environments. Failure to apply high priority updates might result in potential business impact.

This release is recommended for all environments. Apply this update at the earliest convenience.

For more information, see KB51560.

Release Details

Release date: February 14, 2023 (Repost)

Release build: Trellix Data Loss Prevention extension 11.10.5.9

Note icon

Note

Trellix Data Loss Prevention extension 11.10.5.9 is supported only on Trellix ePO - On‑prem 5.10 CU14 or later.

Product rebranding changes

This is solely for informational purpose, there is no action required. You can continue to secure your organization with Trellix DLP Endpoint as usual. You will notice the following changes in the software:

As Trellix continues to evolve, you will begin to see our solutions reflect our new name and brand. In this release, you will notice the following changes in the software. This rebranding change requires an effort from your end if your enterprise manages root certificate updates manually.


Product name - McAfee Data Loss Prevention is renamed as Trellix Data Loss Prevention.

All features and options prefixed with product name are renamed with the new product name.

  • Brand logo and name - McAfee logo and name are replaced with Trellix logo and name.

  • User interface - Color and typeface are updated and provide better user experience.

  • End-User License Agreement and Copyright - The End-User License Agreement and Copyright are updated according to legal requirements. Please read the agreement for details.

Certificate update

As part of rebranding, the certificates used to sign our software have been updated. If your enterprise automatically updates root certificates, the software update or installation does not require any additional effort. However, if your enterprise manages root certificate updates manually, you need to install the new intermediate and root certificates.

For information about downloading and installing the certificates, see KB91697.

New or changed features

Ignored Processes - Trellix DLP Endpoint can now exclude processes that are specific to file tracking. To ignore a process, go to Menu → Policy → Policy Catalog → Data Loss Prevention <version> → Windows Client Configuration → Default Windows Client Configuration → Edit → Content Tracking → Ignored Processes.

Enhanced CSV file import - Trellix DLP Endpoint now supports importing user information from CSV files without including top-level domain (TLD) validation. An example for top-level domain (TLD) is .com.

Threshold Violated Details - In the DLP Incident Manager, incidents triggered by threshold violations now display a count of the recipients' domains and emails that exceeded the threshold.

DLPO 9449 - If you have upgraded to Trellix ePO - On-prem version 5.10.0 Cumulative Update (CU) 11, make sure that you use the latest version of Trellix DLP extension — 11.8.100.

Resolved issues

This update resolves known issues.

For the DLP Endpoint related resolved issues, see the Trellix Data Loss Prevention Endpoint for Windows 11.10.0 Release Notes.

Resolved issues

Reference

Resolution

DLPO-10876

Fixed an issue where DLP operations displayed user manager as none or displayed the previous

Reference

Resolution

manager's name.

DLPO-11065

Fixed an issue where Trellix DLP Endpoint failed to access and perform cleanup on pendingDelete folders.

DLPO-11078

Maximum character length for File Extension is now increased to 260 characters.

Known issues

For a list of current known issues, see Trellix Data Loss Prevention 11.x.x Known Issues (KB89301).


Trellix Data Loss Prevention Extension 11.10.4 Release Notes

Trellix Data Loss Prevention extension release 11.10.4 includes new features and resolved issues. It also addresses product rebranding changes.

Every update release is cumulative and includes all features and fixes from the previous release. We recommend that you always upgrade to the most current update.

Rating for 11.10.4 extension

The rating defines the urgency for installing this update.

Recommended

This release is a high-priority for all environments. Failure to apply high priority updates might result in potential business impact.

This release is recommended for all environments. Apply this update at the earliest convenience.

For more information, see KB51560.

Release Details

Release date: December 1, 2022

Release build: Trellix Data Loss Prevention extension 11.10.4.20

Product rebranding changes

This is solely for informational purpose, there is no action required. You can continue to secure your organization with Trellix Data Loss Prevention as usual. You will notice the following changes in the software:

  • Product name - McAfee Data Loss Prevention is renamed as Trellix Data Loss Prevention.

  • All features and options prefixed with product name are renamed with the new product name.

  • Brand logo and name - McAfee logo and name are replaced with Trellix logo and name.


Trellix Data Loss Prevention Extension 11.10 Update 12 (11.10.201) Release Notes - December 2023 23

9 | Trellix Data Loss Prevention Extension 11.10 Update 12 (11.10.201) Release Notes


  • User interface - Color and typeface are updated and provide better user experience.

  • End-User License Agreement and Copyright - The End-User License Agreement and Copyright are updated according to legal requirements. Please read the agreement for details.

Certificate update

As part of rebranding, the certificates used to sign our software have been updated. If your enterprise automatically updates root certificates, the software update or installation does not require any additional effort. However, if your enterprise manages root certificate updates manually, you need to install the new intermediate and root certificates.

For information about downloading and installing the certificates, see KB91697.

New or changed features

Encrypt short and unique match string — You can use the Encrypt the short and unique match string when stored in ePolicy Orchestrator database option in DLP Settings → Incident Manager to configure the storage of short match string and unique match string data in the Trellix ePO - On-prem database as encrypted text.

Synchronize event users from LDAP servers — You can use the DLP Sync event users from LDAP server task to update any user information associated with the incidents and operational events. This is a scheduled job, where only the existing user information is updated for any update to the user information. You can enable, disable, or change the schedule of this server task to update the user information from the LDAP server configured with Trellix ePO - On-prem.

Permission sets to prevent users from changing the incident attributes — You can now select any of these additional permission sets to enable users to change the incident attributes.

  • Users can view and edit incidents assigned to them

  • Users can view and edit incidents assigned to the following permission sets (allows you to select user groups)

  • User can view and edit all incidents

In previous releases, Trellix DLP allows you to change some of the incident attributes, even though the permission sets are shown as 'view' only. Starting with this release, you can select 'view' only permission sets to restrict users from changing the incident attributes and select 'view and edit' permission sets to enable users to change the incident attributes.

REST API calls to retrieve information — This release introduces various REST API calls to query incidents. You can run the REST API calls to:

  • Query data-in-use or data-in-motion incidents based on email message IDs.

  • Query data-in-use or data-in-motion incidents based on external IDs.

  • Query data-in-use or data-in-motion and network discovery incidents based on custom attribute values.

For more information about these features, see the Trellix Data Loss Prevention 11.10.x Product Guide.

DLPO 9449 - If you have upgraded to Trellix ePO - On-prem version 5.10.0 Cumulative Update (CU) 11, make sure that you use the latest version of Trellix DLP extension — 11.8.100.


24     Trellix Data Loss Prevention Extension 11.10 Update 12 (11.10.201) Release Notes - December 2023

9 | Trellix Data Loss Prevention Extension 11.10 Update 12 (11.10.201) Release Notes


Resolved issues

This update resolves known issues.

Resolved issues

Reference

Resolution

DLPO-9686

                This release fixes an issue where the manually registered document fingerprints were not copied to evidence share, which is defined in the Server Configuration policy. The Regdocs.dat file now shows the time stamp of all configured locations.            

DLPO-10177

                This release fixes an issue where incidents generated from Skyhigh Security Cloud were not displayed.            

DLPO-10188

                This release fixes the high CPU utilization issue that caused slowness or crashing of Chrome and Edge browsers.            

DLPO-10294

                This release fixes an issue where the Trellix ePO - On‑prem administrators with certain permission sets could not see any DLP events in Operational Events and Incident Management pages, even if the permissions were set and events were assigned to them (by group).            

DLPO-10297

                This release resolves an issue where the evidences generated from Skyhigh Security Cloud were not getting uploaded to the correct evidence share location. Instead, it was getting uploaded to the Trellix ePO - On‑prem server cache causing cache overflow, which is now fixed.            

DLPO-10316

                "DLP: Agent Status" query now shows only the count of the system's users who have access or assigned permissions, instead of showing all systems in Trellix ePO - On‑prem.            

DLPO-10689

                This release fixes an issue where Trellix DLP failed to ignore the files that were tagged with McAfee Encrypted Files.            

DLPO-11024

                After upgrading to Trellix ePO - On‑prem 5.10 CU14, evidence            



Reference

Resolution

file names containing ":" (colon) displayed the error message: An unexpected error occurred while downloading the evidence file. This issue is now fixed.

Known issues

For a list of current known issues, see Trellix Data Loss Prevention 11.x.x Known Issues (KB89301).