Skip to main content

System Parameters

Device Types and Notifications

From this section you can view and manage device types and notifications, view and enable default notifications and their translations, and define custom notifications for Content Aware Protection policies and Device Control User Remediation.

Manage device types and notifications

List of Device Types and Notifications

On the List of Device Types and Notifications, you can view the Device Types available in the system along with their availability for each operating system and whether the Content Aware Protection module can inspect those devices.

You can enable and edit the notification messages that appear on the Endpoint Protector Client from the Actions column.

List of Device Types and Notifications

You can enable or disable messages from the Default Notifications list and edit custom notification translations.

note

You can enable Custom Client Notifications globally from Device Control, Global Settings or individually for computers or groups, from their specific Settings sections.

Enable/disable a message from the list of Default Notifications or edit the custom notifications translations

Custom Content Aware Protection Notifications

With Endpoint Protector, you can create informative notifications that users see when a Content Aware Policy blocks or reports a file. These notifications provide context about the triggered policy and the affected file.

In the past, Endpoint Protector delivered Content Aware Protection Notifications in plain text. Starting from Agent version 6.2.3.1 (Windows), 3.0.3.1 (Mac), and 2.4.3.1 (Linux), users can use HTML code to format notifications. By using HTML, administrators can highlight key information such as threat names or affected files with bold, italics, or underlining, making it easier for users to understand. In addition, you can use colors to differentiate sections or emphasize critical details within the notification. This results in visually engaging notifications that capture user attention and ensure users don't miss important information.

To create a notification:

Step 1 – Click the Create button.

Step 2 – Assign a descriptive Template Name for easy identification later.

Step 3 – Craft a clear and informative Title for the notification.

Step 4 – Within the Body text editor, compose your message using the provided placeholders:

  • {fileName}: The actual blocked or reported file name.
  • {type}: Either "blocked" or "reported", based on the policy type.
  • {threatName}: The identified threat name (if applicable).
  • {threatMatch}: The specific text that triggered the policy (if applicable).

Step 5 – Click Save to finalize your custom notification.

Custom Content Aware Protection Notifications

For example, a Content Aware Policy classified the file named 'financial_report.xlsx' (\{fileName\}) as 'Confidential' (\{type\}) because it contains confidential data.

After you create the notification, you can associate it with a specific Content Aware Policy using the Notification Template dropdown menu.

To ensure notifications display correctly and securely, Endpoint Protector supports a limited set of HTML elements. The following list shows the supported elements you can use in your notifications.

  • Basic Formatting:

    • <b></b> (bold)
    • <i></i> (italic)
    • <u><u> (underline)
    • </br> (line break)
  • Text Styling:

    • <span style="color: #rrggbb;">Text</span> (color) - Replace #rrggbb with a hexadecimal color code (e.g., style="color: red;" for red text)
    • <span style="font-size: xxpx;">Text<span> (font size) - Replace xxpx with the font size you want, in pixels (e.g., style="font-size: 16px;" for 16px font)
  • Links:

    • <a href="URL">Text</a> - Replace URL with the actual website address and Text with the clickable link text (e.g., <a href="https://www.netwrix.com">Netwrix Website</a>)

To create notifications using HTML code:

Step 1 – As described in the previous steps, create a new notification by clicking Create and entering a name, title, and body text.

Step 2 – Within the body text editor, directly enter the HTML code you want to use to format your message.

Custom Device Control User Remediation Notifications

This section is available only if you enable the Device Control User Remediation setting in the User Remediation section. In this section you can add, edit, and delete custom notifications for Device Control User Remediation.

You can add a maximum of 100 custom notifications. You can't delete the default entry.

To add a new custom notification:

Step 1 – Click Create.

Step 2 – Use these parameters to create your custom message:

  • {deviceName}
  • {action}

Step 3 – Click Save.

Example: USB Driver(deviceName) is blocked(action)

After you create the notification, you can select the custom notification from the User Remediation Notification Template dropdown in the Device Control section, Global Settings, Users, Computers, and Groups.

Custom Device Control User Remediation Notifications

Contextual Detection

note

Version 5.9.6.0 removes Global Contextual Detection. You now configure contextual detection rules at the policy level only. Each policy can have its own set of up to 15 contextual detection rules with independent AND/OR logic.

To configure contextual detection for a Content Aware Protection policy, go to Content Aware Protection > Content Aware Policy > edit a policy > Contextual Detection tab. For eDiscovery policies, see eDiscovery policies and scans.

Advanced Scanning Detection

Because Windows and installed applications are constantly updated, you can allow specific applications and processes to prevent interference with the Endpoint Protector Client.

The Advanced Scanning Exceptions feature lets you exclude applications from scanning on endpoints with the Advanced Printing and MTP Scanning feature enabled.

This feature maintains a list of applications into which Endpoint Protector will not inject its DLL when you enable “Advanced Printer and MTP Scanning”. For instance, many applications that can't print or copy files to MTP devices don't require the injection of the Endpoint Protector DLL. Adding such applications to the exceptions list improves performance and avoids unexpected interactions with Endpoint Protector.

note

This feature applies globally to all Windows endpoints with the Advanced Printing and MTP Scanning features enabled.

Advanced Scanning Detection

Rights

This subsection displays a list of all access rights you can assign to devices.

Displays a list of all access rights you can assign to devices

Events

In this section, you can view, manage, and export the events list logged by Endpoint Protector. You can also edit event names and descriptions, or enable/disable logging for specific events from the Actions column.

View, manage, and export the events list logged by Netwrix Endpoint Protector

Events Types and Descriptions

This subsection displays a comprehensive list of events that administrators use to manage and monitor their data protection policies. Events include EasyLock deployment, printer activity, user information updates, transfer limits, external repository uploads, content remediation, forced uninstall attempts, device remediation sessions, certificate management, unplanned client terminations, artifact receipts, and deep packet inspection (DPI) bypassed traffic. These events provide granular insight into system activities, helping organizations maintain robust security and compliance measures.

For a detailed view of all events and their descriptions, see the following table.

Event NameDescriptionAdditional Explanations
ConnectedDevice Connected
DisconnectedDevice Disconnected
File ReadFile read from device
File WriteFile written to device
File Read-WriteFile read and write from device
File RenameFile from device renamed
File DeleteFile deleted from device
Device TDTrusted Device™ connected
DeletedFile deleted from device
Enable Read-OnlyDevice Read-Only Enabled
Enable if TD Level 1Allows access when a Trusted Device™ is connected (e.g., a USB stick with EasyLock installed, which is automatically launched)
Enable if TD Level 2Allows access when Trust Level 2 device is connected
Enable if TD Level 3Allows access when Trust Level 3 device is connected
Enable if TD Level 4Allows access when Trust Level 4 device is connected
AD SynchronizationAD Synchronization
BlockedDevice or port blocked
UnblockedDevice or port unblocked
Offline Temporary Password UsedOffline Temporary Password Used
User LoginUser Login
File EncryptFile encrypted using EasyLock
File DecryptFile decrypted using EasyLock
File Encrypt (offline)File encrypted using EasyLock when not communicating with the Endpoint Protector Server
File Decrypt (offline)File decrypted using EasyLock when not communicating with the Endpoint Protector Server
Content Threat DetectedContent Aware Protection
  • Threat Detected
Content Threat BlockedContent Aware Protection
  • Threat Blocked
File CopyA file was copied to or from a removable device
Content Threat DiscoveredeDiscovery
  • Threat Discovered
eDiscovery Client ActioneDiscovery
  • Action received successfully
User LogoutUser Logout
Client Integrity OKEndpoint Protector Client Integrity okLogged when the EPP Client starts and all component files and their signatures pass verification. Signature validation applies to Windows only.
Client Integrity FailEndpoint Protector Client Integrity failedLogged when the EPP Client starts and one or more component files are missing or their signatures fail verification. Signature validation applies to Windows only.
Policies ReceivedEndpoint Protector Client received policy successfullyLogged when the EPP Client downloads updated settings from the server. Any change to Computer or User settings — such as configuration items, rights, or policies — updates the configuration XML and its hash. When the EPP Client connects to the EPP Server, it presents its current XML hash. If the hash differs from what the server holds, the server sends the updated configuration for the client to download automatically.
Uninstall AttemptEndpoint Protector Client uninstall attemptLogged when someone initiates a deliberate uninstall of the EPP Client — either directly on the endpoint (for example, via Add/Remove Programs) or from the EPP Server using the Uninstall Client action.
EasyLock – successfully deployedEasyLock
  • successfully deployed
EasyLock
  • deployment failed
EasyLock
  • deployment failed
File PrintedFile sent to printer successfully
User Information UpdatedUser information updated successfully
Transfer Limit ReachedTransfer Limit Reached
External Repository UploadFile Shadow uploaded to Repository successfully
External Repository Upload FailFile Shadow uploaded to Repository failed
Content Remediation Session ActiveContent Aware Protection
  • Threat Remediated
Content Remediation Request Canceled by UserContent Aware Protection
  • User Remediation dialog was closed by the user
Forced Uninstall AttemptEndpoint Protector Client forced uninstall attemptLogged when the EPP Client service stops or terminates and one or more component files, registry keys, or drivers remain in an unexpected state.
Device Remediation Request Canceled by UserDevice Control - Remediation dialog was closed by the user
Device Remediation Session CanceledDevice Temporarily Unlock with User Remediation canceled
Device Remediation Session ActiveDevice Temporarily Unlocked with User Remediation
Device Remediation Session EndedDevice Temporarily Unlock with User Remediation ended
Certificate added to Keychain/storeCertificate added to Keychain/store successfully
Unplanned Client TerminationUnplanned Client TerminationLogged when the EPP Client service stops or is terminated unexpectedly, but all component files, registry keys, and drivers are intact.
Artifact ReceivedArtifact Received
DPI Bypassed TrafficDPI Bypassed Traffic

User Remediation

User remediation lets end users apply a justification and self-remediate a policy violation or a restricted-access device.

Allows the end-users to apply a justification and self-remediate a policy violation or a restricted-access device

User Remediation Settings

In this section, you can customize the User Remediation notification, manage settings, and enable User Remediation for Device Control.

  • Display Custom Logo – select a 200x200 pixels image to display on the pop-up notification

  • Display Custom URL – add a URL to direct the end-user to a specific web page, and then add a label for the URL

    note

    Endpoint Protector accepts the following URL formats:

  • Require Credentials – request the end-user to use their local account or Active Directory credentials

    note

    Endpoint Protector accepts the following credential formats for login:

    • Local user - computer_name\username (John-PC\John)
    • LDAP/AD user
    • domain_name\username (epp.com\John)
    • ip\username (192.168.14.140\John)
  • Time Interval – enter the time interval in which the end-user can remediate a Block and Remediated threat or a restricted-access device

  • Maximum Time Interval – enter the maximum time interval in which the end-user can remediate a Block and Remediated threat or restricted-access device

    note

    The maximum time interval you can enter is 1440 minutes (24 hours).

  • Enable User Remediation for Device Control – enable the setting to use the user remediation feature for the Device Control module.

    note

    Endpoint Protector disables the Enable User Remediation for Device Control setting by default. When you enable this feature, Endpoint Protector applies all the User Remediation settings to both the Content Aware Protection and Device Control modules.

User Remediation Settings

Justifications List

In this section, you can view, add, edit, export, and remove justifications. The justification represents the reason the end-user selects to justify the threat or device remediation.

To add a new justification, click Add, fill in the mandatory fields and then click Save. You can add a maximum of 10 justifications. By default, Endpoint Protector already includes several justifications, but ensure that at least one justification stays enabled at all times.

To enable and enforce the end-user to view User Remediation pop-up notifications, manage the option from Device Control, Global Settings, Device Control.

Justifications List

Enabling User Remediation

To use User Remediation for Device Control:

Step 1 – Enable the User Remediation for Device Control feature from User Remediation Settings

Enabling User Remediation

Step 2 – Customize the User Remediation notifications for Device Control.

To do so, go to the Devices Types and Notifications, Custom Device Control User Remediation Notifications section, click Create, fill in the mandatory fields and Save.

Custom Device Control User Remediation Notifications

Step 3 – Enable the User Remediation Pop-up setting from the Device Control topic and then select the customized notification from the User Remediation Notification Template dropdown list;

User Remediation Pop-up

Step 4 – Navigate to Device Control, Device Types section and enable User Remediation for devices with limited access – devices that have full access permission can't benefit from the User Remediation feature.

note

For built-in devices, such as Webcam and Network share, the User Remediation feature is not available.

These are device types that apply in General

User Remediation Usage

To remediate the device:

Step 1 – Open the Endpoint Protector notifier and go to the Device Control tab.

Step 2 – Select the device for remediation and click Self Remediate.

User Remediation Usage

Step 3 – On the Self Remediate section:

  1. Select a justification from the dropdown list.

  2. Add a reason for the justification (if required).

  3. Navigate to the custom URL situated under the logo.

  4. Add your credentials if you enabled the Require Credentials setting (click the username icon to refresh your current username).

    1. When you reopen the dialog, if you authenticated with a different username, EPP Notifier will automatically switch back to the username of the logged-in user.
    2. Usernames aren't case sensitive.
  5. Add the number of minutes needed to remediate the device (you can hover over the default number to view the maximum time interval)

  6. Click Authorize.

note

You can manage more settings for the Self Remediate feature from System Preferences and User Remediation sections.

Self Remediate section

To stop the device remediation session at any time during the time interval, select the device from the Device Control tab in the Endpoint Protector notifier and then click Revoke Remediation.

 Stopping the device remediation session