Skip to main content

Control

Feature Details

warning

Please be informed that there are some restrictions on data access.
For detailed information about the file control feature,nextYou can check it at.

Overview

Automatically perform encryption and security processing on documents at the time of upload and download to external storage (OneDrive, SharePoint, etc.) to comply with the organization's information security policy.

1. Document Status Display

The security status of the document is visually indicated through the file icon.

User ScreenContentNote
imgClassification(Label) + Protection(Protect)The PowerPoint document is marked as a preview.
imgClassification (Label)PowerPoint documents are marked as preview.

1.1 Limitations

  • The MIP label (security) icon is not displayed at a specific icon size.: If you set the icon view of Windows Explorer to "Medium Icons" or larger, the MIP label icons specified by document security may not be displayed in some MIP documents. (They are displayed normally in Small Icons, List, and Details views.) In this size, a preview of the first page of the document is drawn instead of the icon.
  • Cause (Outside Document Security Control): Windows Explorer displays the preview image saved in the document over the icon if the icon is larger than a certain size. The preview image is saved in a three-letter extension format (e.g.:.ppt) Even if MIP protection is applied, the preview image remains in plaintext within the document, so at this size, the explorer renders the preview and**The MIP label icon for document security cannot be displayed.**Even with the same Microsoft Office document format, the password encryption method removes the preview by encrypting it, while MIP/IRM protection specifies that only the document body is encrypted, leaving the preview in plaintext. Document security only specifies the file icon, and this preview display behavior is due to the characteristics of the Microsoft Office document format and Windows Explorer, which are areas that document security cannot control.
  • Scope of Application: Preview image saved in three-letter extension format.ppthas been confirmed, in the same three-digit extension format.doc·.xlsThe preview can appear the same when saved. Four-digit extension format(.pptx·.docx·.xlsxSince the entire document is encrypted, there is no preview left, so the MIP label icon is displayed normally.
  • Reference (Technical Specifications)

2. When uploading to external storage

2.1 Overview

When uploading documents from a local path to external storage such as OneDrive/SharePoint, the system automatically applies security policies to encrypt and process the documents.

2.2 Security Processing Steps

  1. Upload Detection: File Move/Copy Event Detection
  2. Policy Check: Check ZTCAP policy for the original file
  3. Document Conversion: Convert to a secure document according to policy (apply MIP label or DRM conversion)
  4. Upload Execution: Upload the converted document to an external storage.
  5. Backup Storage: (When setting policies) Backup of the original document

2.3 Support Scenarios

divisionDocument Security 6Note
General Path → OneDrive/SharePointUpload after conversionZTCAP fileEvent - CopyFileTo_OneDrive - CopyFileTo_Sharepoint
General Path → General PathNot supportedSince it is an internal transfer, control does not apply.

2.4 Behavior by Authentication Status

  • DS6 Login Status: Upload the converted file according to the ZTCAP policy for the original file.
  • DS6 Logout Status: Uploading files to external storage is blocked.

3. Warning Popup Functionality During Upload

3.1 Feature Overview

When uploading a file or folder to the OneDrive path, a notification window will be displayed to inform you that the document conversion process is in progress.

3.2 Resource Application Information

  • resource key\
    img

① Title
② MainMsg
③ SubMsg1
④ SubMsg2
⑤ HelpUrl

# 리소스 파일 정보 c:\Windows\softcamp\sdk\Res\DS\ResUIKOR.rc, 버전 6.0.0.13
....
[CloudCopyMoveWarning]
Title = OneDrive 이동 / 복사 진행중
MainMsg = 작업 완료 전까지는 대상 파일(또는 폴더)을\r\n사용하지 마세요.
SubMsg1 = *대량의 파일은 시간이 오래 걸릴 수 있습니다.
SubMsg2 = *이동 / 복사가 완료되기 전 파일을 열거나 수정하면\r\n오류가 발생할 수 있습니다.
HelpUrl = (안내 사이트 주소)
....

3.4 Limitations

  • If you start another copy before the current copy is finished, duplicate windows will occur. (up to 10 windows)
  • Basically, the window will automatically close once the copy is complete, but the user can also close the window by pressing confirm.

4. Backup File Storage Function During Upload

4.1 Feature Overview

This is a feature that backs up and stores the original document uploaded to an external repository.

4.2 Limitations

  • The backup path is the path specified by the policy, or the default path (My Documents)**"CloudDrv_Backup"**A folder is created, and subfolders are created by date, after which backup files are stored in those folders.
  • When copying a folder, the folder structure is not maintained, and all converted files are saved under the date folder.

5. When downloading from external storage

5.1 Overview

When downloading documents from external storage such as OneDrive/SharePoint to a local path, the system automatically applies security policies to process the documents.

5.2 Security Processing Steps

  1. Download Detection: File Move/Copy Event Detection
  2. Policy Check: Check the security status of the download target file
  3. Document Conversion: Convert to appropriate security document according to policy
  4. Download Execution: Save the converted document to a local path

5.3 Support Scenarios

divisionDocument Security 6Note
OneDrive/SharePoint → General PathDownload after conversionZTCAP fileEvent - CopyFileFrom_OneDrive - CopyFileFrom_Sharepoint
OneDrive/SharePoint → OneDrive/SharePointNot supportedSince it is a migration between clouds, control is not applied.

5.4 Actions by Authentication Status

  • DS6 Login Status: When downloading files from external storage, the converted files are saved according to the policy.
  • DS6 Logout Status: Downloading files from external storage is blocked.

6. Security Control When Viewing Documents

6.1 Overview

When accessing the document, the system automatically checks the security policy and, if necessary, converts the document to allow for safe viewing.

6.2 Security Processing Steps

  1. Access Request Detection: Document Viewing Event Detection
  2. Policy Check: Check policies based on document path and security status
  3. Document Conversion: Convert to a secure document according to policy (if necessary)
  4. Access Permission: Safely view the converted document

6.3 Access Policy by Path

divisionDocument Security 6Note
General Path DocumentView After ConversionZTCAP fileEvent - ApplicationFileOpen custom policy - DS_MIP_SHLL : open
OneDrive Path DocumentGeneral Document: Unsupported Security Document: Access Blocked MIP Document: UnsupportedSecurity documents need to be viewed after MIP conversion.
SharePoint Path DocumentGeneral Document: View After Conversion Secure Document: View After Conversion MIP Document: View After ConversionSupport for all document type conversions

6.4 Policy Application Mechanism

img

Application of ZTCAP Policy at Document Viewing Time
Document Event - Designated as a conversion policy when viewing documents, supporting conversion to documents registered in the execution policy at the time of viewing.

  • Access Restrictions for Security Documents
    Viewing secure documents (DRM) in OneDrive is possible after converting them to MIP documents through the SHILDRM service (or by right-clicking the user menu to switch to MIP/general documents before viewing).

Cases that do not support conversion when viewing documents

  • Before Integrated Login
  • Local OneDrive path document files
  • File with a size of 0 bytes
  • If the MIP supported extension is not an Office extension

7. Document Conversion and Security Label Management

7.1 Overview

This is a feature that allows users to manually change the security level of a document or manage MIP labels.

7.2 Supported Features

  • General Document → Create MIP Label
  • Convert Security Document (DRM) to MIP Document
  • MIP Document → Delete MIP, Convert to DRM Document

7.3 Support Features by Path

divisionDocument Security 6Note
General Path DocumentGeneral Document: Create MIP Label Secure Document: Convert to MIP Document MIP Document: Delete MIP, Convert to DRM Document Multi-file/Folder SupportCustom Policy - DS_MIP_SHLL_MENU DS6 : Convert to ZTCAP Policy
OneDrive Path DocumentGeneral Document: Create MIP Label Security Document: Convert to MIP Document MIP Document: Delete MIP Multi-file/Folder SupportOneDrive Path Characteristics Limit DRM Conversion
SharePoint Path DocumentGeneral Document: Create MIP Label Security Document: Convert to MIP Document MIP Document: Delete MIP, Convert to DRM Document Multi-file/Folder SupportSupport for all transformation features

8. External Storage Upload Block (Selective Block · Notice Replacement)

8.1 Overview

When uploading documents to cloud storage such as OneDrive or SharePoint (copying or moving), documents classified as "prohibited from export" according to the company's security policy are**Replace the original with the guide file.**This is a feature that prevents sensitive documents from leaving the cloud. Allowed level documents are uploaded as is. Even if blocked, the operation ends like "success," so uploading multiple files at once does not stop midway or display an error window.

info

Summary: Quietly selectively block cloud uploads of sensitive grade documents and upload a notice instead of the original. Once the work is done, notify the results per file (move/block/error) in a single window.

The reason this feature is needed

Previously, when uploading documents to the cloud, only conversion (encryption, security level application) was performed according to policy, and**"There were no means to completely prevent raising a specific grade."**So there was a risk that sensitive documents such as confidential and proprietary information could be exported to the cloud. This feature fills that gap by selectively blocking uploads based on document classification.

Operation Method (Single Line Mechanism)

The documents identified as blocked by the server policy will be replaced with a notice (원본명_차단됨.txtThis cloud will be uploaded (quietly blocked), and the allowed documents will be uploaded normally. When the task is complete, the results for each file will be displayed in one window (only when there is at least one block or error — if everything is normal, there will be no notification).

8.2 Scope / Entry Point

Entry PointSupport Status
Local Explorer → OneDrive/SharePointcopy(Ctrl+C/V)support
Local Explorer → OneDrive/SharePointMove·Dragsupport
folderUnit MovementSupport (also replaces blocked documents in the folder)
Teams Copilot UploadDifferent integration methods are outside the scope of this document
Cloud → Cloud Migration, Downloadnon-target

8.3 User Scenario

This is a simple summary of what happens when a user does something.

What the user doesWhat happens?
Copying/Moving General (Allowed) Documents to OneDrive/SharePointIt will be uploaded normally as usual.
Copy/Move Restricted Level (e.g., Confidential) DocumentsThe original is not uploaded, and원본명_차단됨.txtThe guide file will be uploaded instead.
Uploading multiple documents at onceOnly the blocked targets will be changed to the guidance file, and the rest will be uploaded normally. Once the work is finished, it will be displayed at a glance in the results window.
Upload (Move) FolderOnly the blocked documents in the folder will be changed to a guide file, and the original folder will remain on my PC as it is.
No blocked documents (all allowed)It completes quietly without displaying the result window.

8.4 Constraints

  • Local Duplication When Folder Move is Blocked: If you move a folder that contains blocked documents, the entire original folder is preserved locally. At this time, allowed documents exist (duplicate) both locally and in the cloud — this is an intended behavior to prevent data loss.
  • Supported Extensions Only: The targets for cloud upload blocking are Office (docx/xlsx/pptx, etc.) and PDF. HWP/HWPX, etc. are not targets for blocking, and if blocking is necessary, a separate extension for supported file types is required.
  • Notice Protection Level: The notice is unencrypted plain text without a security label. It does not contain sensitive information, and the security objective (not exporting sensitive originals to the cloud) is achieved by not uploading the originals.
  • Server Policy Dependency: The blocking level determination depends on the server conditional policy. If the policy is not registered, the existing transformation and upload flow will remain unchanged.
  • excluding appAuth mode: appAuth mode does not use conditional policies, so it is not a target for this block.
  • Teams Copilot Upload: This feature is outside the scope due to the different integration method with the explorer.

8.5 User Interface (UX)

When the task is completed, the results window will appear (only when there are blocks or errors).

┌──────────────────────────────────────────────┐
│ Document Security │
│ Upload Blocked │
│ ┌────────────────────────────────────────┐ │
│ │ Target Files │ │
│ │ report.docx ✓ Moved │ │
│ │ confidential_document.docx ! Blocked │ │
│ │ revenue.xlsx ! Blocked │ │
│ └────────────────────────────────────────┘ │
│ [ Confirm ] │
└──────────────────────────────────────────────┘
  • The blocked document is in the cloud.원본명_차단됨.txt(Notice) goes up.
  • The result window is for that task'sAll filesshows the status (moved/blocked/error).
  • Tasks that are uploaded normally do not display a result window (to prevent unnecessary notifications).

8.6 Policy / Settings

  • Whether to blockServer Conditional Policy (ZTCAP)"Upload Block"uploadBlock) Controlled by the execution card.
  • The grade to be blocked (e.g., C·S grade) is specified in the policy's "Target Document Security Label Conditions." The client only checks whether there is a blocking card in the response.

8.7 Supported Scope (Extension)

  • Support: Microsoft Office (docx/xlsx/pptx, etc.) · PDF.
  • Unsupported: HWP/HWPX and other extensions are not subject to upload restrictions (8.4 constraints).

8.8 Main Flow

  • Administrator: Conditional Policy Registration (Upload Block Card ON + Block Level Designation).
  • User: Copy/Move document to OneDrive/SharePoint → (Block Level) Replace notice / (Allow) Normal upload → Result window at the end of the task.