Data Loss Prevention (DLP) Policy Admin Overview

Data Loss Prevention (DLP) Policies are controls that Company Managers can enable in order to restrict what users can do in Venn's Blue Border. You may choose to put these policies in place to prevent company information and files with sensitive data from being lost, misused, or accessed by unauthorized users. 

Learn about available DLP Policies for mobile devices.

How Data Loss Prevention Policies Work

As a Company Manager, you can set Default DLP Policies, which are applied to all Venn users as a baseline. Your company's Default Policy sets the standard Data Loss Prevention (DLP) controls that apply to all Venn users by default. 

You can also create Policy Overrides, which allow you to set DLP Policies that supersede the default policy for a single user or a group of users. Policy Overrides can be created for an individual user by name, for a user group, or for an IP address.

For example, if you want to prevent contractors from copying and pasting company information from inside of Venn to outside, you could set up the following using the Move and Paste DLP Policy:

  • Default: Set your Move and Paste DLP Policy as unrestricted
  • Override: Create a policy override for your contractor group and set the Move and Paste DLP Policy to restricted for that group

If a user qualifies for more than one Policy Override, Overrides will be prioritized in the order in which they appear in the list of Overrides. Overrides listed higher on the list will supersede any Overrides listed lower on the list.

How to Configure DLP Poicies

As a Company Manager, you can manage your company's Data Loss Prevention (DLP) Policies on the DLP Policy page in Company Admin. Learn how to configure and manage Data Loss Prevention Policies for your company.

Available DLP Policies for Desktops and Laptops

Policy Settings Venn Best-Practice Recommendation

Network

Secure the network path for apps running in Blue Border.

Enabled: Users' network traffic is encrypted and routed through the Private Company Gateway except for the exception list configured by the Company Manager.

Disabled: Network traffic is not routed through by Private Company Gateway. Users' internet traffic will not be encrypted or subject to your Web Policies.

Green Check Restricted.png Enable to route users' internet traffic in Blue Border via the Private Company Gateway.

Enable exclusions and advanced options as needed. Click here to learn more.

Print

Block printing from apps running in Blue Border.

Note: This policy is only enforced on Windows devices. It does not restrict "Print to PDF" functionality.

Enabled: Users cannot print.

Disabled: Users can print to any printer.

Depending on your organization's workflows, Enable to prevent users from printing or Disable to allow printing.

Screen sharing and capture

Block or restrict the ability to share, record, or screenshot app windows open in Blue Border.

Note: This policy is only enforced on Windows devices.

Enabled: Users cannot share app windows unless you enable them to share with a business reason.

Disabled: Users can share any application window.

Green Check Restricted.png Enable to prevent users from sharing, recording, or screenshotting windows open in Blue Border.

Green Check Restricted.png Check Allow with justification to allow users to share, record, or screenshot with a business reason.

Allow employee monitoring or remote support tools to view and record inside Blue Border if needed. Click here to learn more.

Copy and paste

Block the ability to copy-and-paste or drag-and-drop from inside Blue Border to outside.

Note: This policy does not restrict the ability to drag/drop and copy/paste to move data into Blue Border.

Enabled: Users cannot move data outside of Blue Border.

Disabled: Users can move data outside of Blue Border.

Green Check Restricted.png Enable to prevent users from copying and pasting or moving data from inside Blue Border to outside.

Browser policies

Apply a custom policy to browsers running in Blue Border.

Custom: Custom browser policies have been applied.

Default: No custom browser policies have been applied.

Identify and test browser policies you would like to implement for Chrome and Edge within the Blue Border environment prior to onboarding end users.

Blue Border registry

Apply configurations to the registry in Blue Border for Windows users.

Note: This policy is only enforced on Windows devices.

Enabled: Custom registry settings have been applied for the Secure Enclave on Windows devices.

Disabled: No custom registry settings have been applied.

Identify and test registry settings you would like to implement to control or customize specific application behaviors within the Blue Border environment prior to onboarding end users.

Browser uploads

Block or restrict the ability to upload files in browsers running in Blue Border.

Note: This policy is only enforced on Windows devices.

Enabled: Users are not allowed to upload files except to domains in the exception list configured by the Company Manager.

Disabled: Users are allowed to upload files to any domain.

Depending on your organization's workflows, Enable to prevent users from uploading files (except to domains specified) or Disable to allow users to upload files to any domain.

Enable exclusions as needed. Click here to learn more.

File storage

Configure available file storage suites in Blue Border and block the ability to move files from Blue Border to outside.

Note: If you do not assign any of the file storage options, the only encrypted storage location protected by Venn on your users' devices will be Venn Disk, a temporary storage location that is not backed up to the cloud.

Enabled: Configured. A file storage assignment has been selected and/or data is not allowed to be saved or moved out of Venn.

Disabled: Not configured. No file storage assignments have been selected and data is allowed to be saved or moved out of Venn.

Depending on your organization's workflows, configure file storage options.

  • Assign file storage: Choose to assign only the required file storage platforms.
  • Set file storage default: Choose your main cloud storage platform as the default location.

Green Check Restricted.png Enable Block file movement to prevent users from moving files from inside of Blue Border to outside.

Tenant restrictions

Control the accounts that can be used to access software suites in Blue Border.

Enabled: Configured. Access to Google Workspace, Microsoft 365, ChatGPT, and/or Claude accounts is allowed in Blue Border.

Disabled: Not configured. Access to Google Workspace, Microsoft 365, ChatGPT, and/or Claude is not allowed in Blue Border.

Depending on your organization's workflows, configure account access options.

For each software suite:

  • Choose Allow access with specific business accounts if your organization uses that software suite.
  • Choose Don't allow access if your organization doesn't use that software suite.

We do not recommend choosing Allow access with any account unless this is required for your organization's workflows.

Was this article helpful?