Fortinet white logo
Fortinet white logo

FortiDLP Administration Guide

Labels

Labels

Labels allow you to associate users and managed nodes with policy groups, Agent configuration groups, and the Agent offline detection rule.

FortiDLP provides the following label types:

  • A custom label is one that an operator creates and assigns to users and managed nodes. You can remove, modify, and delete custom labels.
  • An automatic label is one that the FortiDLP Infrastructure creates and assigns to managed nodes using information from the FortiDLP Agent. Each managed node has two automatic labels, which classify them by their operating system and Agent software version. You cannot remove or delete automatic labels, but you can modify some of their properties.
  • A directory label is one that the FortiDLP Infrastructure creates and assigns to users after syncing with an Entra ID or LDAP directory. Directory labels map to the directory's user attributes. For details about generating Entra ID directory labels, see Entra ID users. For details about generating LDAP directory labels, refer to the FortiDLPLDAP Sync Tool Administration Guide. Once created, you can manage directory labels centrally, as described in Unassigning labels and Deleting labels.

You are advised to read Policies, Agent configuration groups, and Agent offline warning in their entirety to determine the labels you require for your organization. If you decide to use custom labels, see the following sections:

Labels

Labels

Labels allow you to associate users and managed nodes with policy groups, Agent configuration groups, and the Agent offline detection rule.

FortiDLP provides the following label types:

  • A custom label is one that an operator creates and assigns to users and managed nodes. You can remove, modify, and delete custom labels.
  • An automatic label is one that the FortiDLP Infrastructure creates and assigns to managed nodes using information from the FortiDLP Agent. Each managed node has two automatic labels, which classify them by their operating system and Agent software version. You cannot remove or delete automatic labels, but you can modify some of their properties.
  • A directory label is one that the FortiDLP Infrastructure creates and assigns to users after syncing with an Entra ID or LDAP directory. Directory labels map to the directory's user attributes. For details about generating Entra ID directory labels, see Entra ID users. For details about generating LDAP directory labels, refer to the FortiDLPLDAP Sync Tool Administration Guide. Once created, you can manage directory labels centrally, as described in Unassigning labels and Deleting labels.

You are advised to read Policies, Agent configuration groups, and Agent offline warning in their entirety to determine the labels you require for your organization. If you decide to use custom labels, see the following sections: