Action on Files Placed in Vault

When a data leak is detected in a file, Avanan takes these steps:

  • Revokes the file permissions.

  • Moves the file to a secure Vault folder.

Avanan stores this vault folder on the user's local drive and cannot be shared with others.

Vault Action in Externally Shared Drives

For files stored in My Drive, access is managed by the file owner unless the file or folder is specifically shared with others.

For shared drives, when the drive is shared externally, the permissions set on the drive apply to all files within it.

Note:

If a drive is shared externally, the standard Vault process may not function as expected. It is not possible to revoke access from individual files as they inherit permissions from the shared drive.

To restrict external access, the permissions of the entire drive must be modified. However, customers often prefer to limit access to specific files flagged by a Data Loss Prevention (DLP) policy without impacting the entire drive.

Handling DLP Detections on Externally Shared Drives

To manage DLP detections on externally shared drives, these configuration options are available to control the Vault:

  • Use Vault Folder (Default): Removes direct permissions (not inherited from the shared drive) from the file and moves it to a Vault folder at the root of the drive. This ensures the file remains accessible internally while preventing external access.

  • Use Quarantine as Vault: Transfers the file to a quarantine location within Check Point's infrastructure.

  • Fail Vault Action: If a DLP detection occurs on an externally shared drive, selecting this option causes the Vault action to fail, returning an error and ensuring no changes are made if that is the preferred behavior.