Users Guide

Table Of Contents
DDP Enterprise Server - VE now supports Secure Lifecycle. Secure Lifecycle provides data security, wherever it goes -
data at rest, data in motion and data in use - through encryption. Data Loss Prevention (DLP) ensures no data is lost in
motion or in flight, while Data Rights Management (DRM) defines access and usage control. Additionally, file monitoring
provides detailed data usage visibility to support forensics needs. Secure Lifecycle provides security, authority, visibility, and
cross-platform compatibility - all through a single solution - with the following features:
Auditing and reporting on file activity, files synced, files accessed by whom, where and when, and compliance reporting.
Geolocation with map visualization as well as multiple filtering options for audit events.
Enforcement of whitelists/graylists/blacklists of email domains and addresses for control over file sharing.
Enforcement of policies for access to cloud services, folders, and applications.
Management of key expirations and polling periods.
Ability of administrators to monitor all known IP addresses for cloud service providers and match them with the
application process to centrally manage encryption, encryption keys, data recovery, policies and forensics.
Secure Lifecycle Protected Office mode offers enhanced security on Office documents (Word, PowerPoint, and Excel) for
internal users.
Files remain encrypted for unauthorized users, for example, when files are attached in email, moved in a web browser or
File Explorer, or stored on removable media.
A callback beacon can be inserted into every protected Office file, when the beacon server is installed as part of the
Proxy Mode installation.
As of v9.4.1.11,DDP Enterprise Server - VE supports Advanced Threat Prevention on Mac computers. Advanced Threat
Prevention provides real-time threat detection by analyzing potential file executions for malware in both the operating
system and memory layers to prevent the delivery of malicious payloads. Control of execution at the endpoint allows for
accurate and effective detection of malicious threats - even those that have never been seen before. Advanced Threat
Prevention uses machine learning techniques that allow detection of new malware, viruses, bots and unknown future
variants, where signatures and sandboxes fail. Memory protection strengthens basic operating system protection features by
providing an additional layer to detect and deny certain behaviors that are commonly used by exploits.
Restoring from backup to DDP Enterprise Server - VE v9.5 is supported with v9.4.1.11 and later.
As of v9.5, Cloud Edition is no longer supported.
Resolved Technical Advisories v9.5
After restoring from backup, customized Compliance Reporter reports views and settings are now available as expected.
[DDPS-3832, DDPS-4199]
Searching for endpoints in the Remote Management Console using the Shield Recovery ID now returns expected results.
[DDPS-4017]
An issue is resolved that resulted in Summary Statistics in the Remote Management Console Dashboard occasionally not
updating as expected. [DDPS-4082]
A second or subsequent notification that is added in Notification Management in the Remote Management Console no longer
retains the Type and Priority values of the previously added notification. [DDPS-4178]
The Compatibility Service now starts as expected after restoring from backup to the same VE build from which the backup
was taken. Previously, in rare cases the Compatibility Service did not start. [DDPS-4209]
After the user browses for the Service Account Run As user name, the credentials now populate in the Service Runtime
Account Information dialog in the installer. [DDPS-4234]
The Advanced Threat Prevention category is now populated in Log Analyzer in the Remote Management Console.
[DDPS-4241]
An issue that resulted in failure of Advanced Threat Prevention Agent Auto Update enrollment is resolved. [DDPS-4244]
The Add User and Add Group options are removed from Domain Detail for Members of Non-Domain Users in the Remote
Management Console. These options are not applicable for non-domain users. [DDPS-4255]
Resolved Customer Issues
The Specification field in the Remote Management Console Add Endpoint Group page is now validated for length and
displays an error if more than 4,000 characters are entered. [DDPS-2953, DDPS-4260]
The TPM Enabled field in the Compliance Reporter BitLocker Manager Detail report is now accurate. [DDPS-3394]
30
Dell Security Management Server Virtual Technical Advisories