cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Omriil
Level 9
Report Inappropriate Content
Message 1 of 2

How to use specific local user in DLP rules

Jump to solution
we have a few DLP rules that block file copy by some classifications, and an exclusion for a specific domain user. We have a few machines that are not part of the domain and we wish to add an exclusion for a specific local user that exists on these machines- how is it possible to do so? We tried to create that local user entry on the 'User Directory' feature that basically belongs to DE, inside the DLP rule we can see User Directory and the users inside, but when we choose the user from that list nothing happens and the rule stays empty.
1 Solution

Accepted Solutions
Corey-DLP
McAfee Employee
McAfee Employee
Report Inappropriate Content
Message 2 of 2

Re: How to use specific local user in DLP rules

Jump to solution

Hello and thank you for posting here!

Unfortunately within DLP rules, local users cannot be specified. When the "local user" option is selected in a rule, this would apply to all local user accounts on a system. As you mentioned, User Directory would not apply here either since those user accounts are applied to the MDE Preboot Authentication File System (PBFS) and are not directly linked to a local Windows user account. 

I would recommend submitting a product idea for a feature to be added in a future version of DLP which would allow identification of local user accounts. KB60021 contains details on how to submit a product idea.

View solution in original post

1 Reply
Corey-DLP
McAfee Employee
McAfee Employee
Report Inappropriate Content
Message 2 of 2

Re: How to use specific local user in DLP rules

Jump to solution

Hello and thank you for posting here!

Unfortunately within DLP rules, local users cannot be specified. When the "local user" option is selected in a rule, this would apply to all local user accounts on a system. As you mentioned, User Directory would not apply here either since those user accounts are applied to the MDE Preboot Authentication File System (PBFS) and are not directly linked to a local Windows user account. 

I would recommend submitting a product idea for a feature to be added in a future version of DLP which would allow identification of local user accounts. KB60021 contains details on how to submit a product idea.

View solution in original post

You Deserve an Award
Don't forget, when your helpful posts earn a kudos or get accepted as a solution you can unlock perks and badges. Those aren't the only badges, either. How many can you collect? Click here to learn more.

Community Help Hub

    New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.

  • Find Forum FAQs
  • Learn How to Earn Badges
  • Ask for Help
Go to Community Help

Join the Community

    Thousands of customers use the McAfee Community for peer-to-peer and expert product support. Enjoy these benefits with a free membership:

  • Get helpful solutions from McAfee experts.
  • Stay connected to product conversations that matter to you.
  • Participate in product groups led by McAfee employees.
Join the Community
Join the Community