Fortinet white logo
Fortinet white logo

FortiDLP Administration Guide

Agent configuration groups

Agent configuration groups

You can streamline configuration by defining groups of Agents that share settings, such as the activities monitored, the target version, and more.

Simply create a group, assign it labels for the nodes you want to include, and set your configuration options as needed. You can then easily switch settings on and off and upgrade to new Agent software without affecting nodes outside of the group.

Example

For example, you could create a group for on-notice employees with email, clipboard, and keystroke monitoring enabled to protect against data loss, but have this functionality disabled for other employees.

You could also create a General Data Protection Regulation (GDPR) compliance group, where web monitoring is disabled for employees in European countries.

Each configuration group you create requires a priority. This determines the configuration that takes precedence if a node belongs to multiple groups. The larger the number, the higher the precedence—so a group with a priority of 4 would prevail over groups 0–3.

A base configuration group is provided, which is assigned a priority of 0. You can use this group to apply general settings to all Agents in your deployment. Any additional configuration groups you create will automatically be assigned a higher priority which you can modify as needed. Unlike other configuration groups, the base configuration group specifies the values applied to all possible options to increase visibility of the applied configuration. For details on viewing your nodes applied settings, see Testing Agent configurations.

Caution

The base configuration group for FortiDLP Cloud tenants contains settings to install the FortiDLP Browser Extension and FortiDLP Email Plugin (Legacy) on supported OS versions out of the box—unless the tenant has been set to explicitly NOT install them.

If you use a fleet management tool for your Agent deployment, and you do not want to install the extension and/or plugin:

  • For Agent 11.0.1 or earlier, prior to enrollment, set the Browser extension installation (Agent v11.0.1 or earlier) > Agent-initiated browser extension installation option and/or Agent-initiated email plugin installation option to Off in your base configuration group and only apply settings using your fleet management tool.
  • For Agent 11.1.1 or later, prior to enrollment, set the Browser extension installation (Agent v11.1.1 or later) option to Managed with external tool and/or Agent-initiated email plugin installation option to Off in your base configuration group and only apply settings using your fleet management tool.

Agent configuration groups

Agent configuration groups

You can streamline configuration by defining groups of Agents that share settings, such as the activities monitored, the target version, and more.

Simply create a group, assign it labels for the nodes you want to include, and set your configuration options as needed. You can then easily switch settings on and off and upgrade to new Agent software without affecting nodes outside of the group.

Example

For example, you could create a group for on-notice employees with email, clipboard, and keystroke monitoring enabled to protect against data loss, but have this functionality disabled for other employees.

You could also create a General Data Protection Regulation (GDPR) compliance group, where web monitoring is disabled for employees in European countries.

Each configuration group you create requires a priority. This determines the configuration that takes precedence if a node belongs to multiple groups. The larger the number, the higher the precedence—so a group with a priority of 4 would prevail over groups 0–3.

A base configuration group is provided, which is assigned a priority of 0. You can use this group to apply general settings to all Agents in your deployment. Any additional configuration groups you create will automatically be assigned a higher priority which you can modify as needed. Unlike other configuration groups, the base configuration group specifies the values applied to all possible options to increase visibility of the applied configuration. For details on viewing your nodes applied settings, see Testing Agent configurations.

Caution

The base configuration group for FortiDLP Cloud tenants contains settings to install the FortiDLP Browser Extension and FortiDLP Email Plugin (Legacy) on supported OS versions out of the box—unless the tenant has been set to explicitly NOT install them.

If you use a fleet management tool for your Agent deployment, and you do not want to install the extension and/or plugin:

  • For Agent 11.0.1 or earlier, prior to enrollment, set the Browser extension installation (Agent v11.0.1 or earlier) > Agent-initiated browser extension installation option and/or Agent-initiated email plugin installation option to Off in your base configuration group and only apply settings using your fleet management tool.
  • For Agent 11.1.1 or later, prior to enrollment, set the Browser extension installation (Agent v11.1.1 or later) option to Managed with external tool and/or Agent-initiated email plugin installation option to Off in your base configuration group and only apply settings using your fleet management tool.