Skip to main content

Control

Feature Details

warning

Please be informed that there are some restrictions on data access.
Detailed information about the file control feature isnextYou can check it at.

Overview

Automatically perform encryption and security processing on documents at the time of upload and download to external storage (OneDrive, SharePoint, etc.) to comply with the organization's information security policy.

1. Document Status Display

The security status of the document is visually indicated through the file icon.

User ScreenContentNote
imgClassification(Label) + Protection(Protect)The PowerPoint document is marked as a preview.
imgClassification (Label)The PowerPoint document is marked as a preview.

1.1 Constraints

  • The MIP label (security) icon is not displayed at a specific icon size.: If you set the icon view of Windows Explorer to "Medium icons" or larger, the MIP label icons specified by document security may not be displayed in some MIP documents. (They are displayed normally in small icons, list, and details view.) In this size, a preview of the first page of the document is drawn instead of the icon.
  • Cause (Outside Document Security Control): Windows Explorer displays the saved preview image in the document over the icon if the icon is larger than a certain size. The preview image is saved in a three-letter extension format (e.g.:.ppt) Even with MIP protection applied, the preview image remains in plaintext within the document, so at this size, the explorer renders the preview and**The MIP label icon for document security cannot be displayed.**Even with the same Microsoft Office document format, the password encryption method removes the preview by encrypting it, while MIP/IRM protection specifies that only the document body is encrypted, leaving the preview in plain text. Document security only designates the file icon, and this preview display behavior is due to the characteristics of the Microsoft Office document format and Windows Explorer, which are areas that document security cannot control.
  • Scope of Application: Preview image saved in three-letter extension format.pptwas confirmed, in the same three-digit extension format.doc·.xlsThe preview can appear the same when saved. Four-digit extension format(.pptx·.docx·.xlsxSince the entire document is encrypted and no preview is left, the MIP label icon is displayed normally.
  • Reference (Technical Specifications)

2. When uploading to external storage

2.1 Overview

When uploading documents from a local path to external storage such as OneDrive/SharePoint, the system automatically applies security policies to encrypt and process the documents.

2.2 Security Processing Steps

  1. Upload Detection: Detecting File Move/Copy Events
  2. Policy Check: Check ZTCAP policy for the original file
  3. Document Conversion: Convert to a secure document according to policy (apply MIP label or DRM conversion)
  4. Upload Execution: Upload the converted document to an external storage.
  5. Backup Storage: (When setting policies) Backup of the original document

2.3 Support Scenarios

divisionDocument Security 6Note
General Path → OneDrive/SharePointUpload after conversionZTCAP fileEvent - CopyFileTo_OneDrive - CopyFileTo_Sharepoint
General Path → General PathUnsupportedSince it is an internal transfer, control does not apply.

2.4 Actions by Authentication Status

  • DS6 Login Status: Upload the converted file according to the ZTCAP policy for the original file.
  • DS6 Logout Status: File uploads to external storage are blocked.

3. Warning Popup Functionality During Upload

3.1 Feature Overview

When uploading a file or folder to the OneDrive path, a notification window will be displayed to inform you that the document conversion process is in progress.

3.2 Resource Application Information

  • resource key\
    img

① Title
② MainMsg
③ SubMsg1
④ SubMsg2
⑤ HelpUrl

# 리소스 파일 정보 c:\Windows\softcamp\sdk\Res\DS\ResUIKOR.rc, 버전 6.0.0.13
....
[CloudCopyMoveWarning]
Title = OneDrive 이동 / 복사 진행중
MainMsg = 작업 완료 전까지는 대상 파일(또는 폴더)을\r\n사용하지 마세요.
SubMsg1 = *대량의 파일은 시간이 오래 걸릴 수 있습니다.
SubMsg2 = *이동 / 복사가 완료되기 전 파일을 열거나 수정하면\r\n오류가 발생할 수 있습니다.
HelpUrl = (안내 사이트 주소)
....

3.4 Constraints

  • If another copy is started before the current copy finishes, duplicate windows will occur. (up to 10 windows)
  • Basically, the window will automatically close once the copy is complete, but the user can also close the window by pressing confirm.

4. Backup File Storage Function During Upload

4.1 Feature Overview

This is a feature that backs up and stores the original documents uploaded to external storage.

4.2 Limitations

  • The backup path is either the path specified by the policy or the default path (My Documents)**"CloudDrv_Backup"**A folder is created, and subfolders are created by date, after which backup files are stored in those folders.
  • When copying a folder, the folder structure is not maintained, and all converted files are saved under the date folder.

5. When downloading from external storage

5.1 Overview

When downloading documents from external storage such as OneDrive/SharePoint to a local path, the system automatically applies security policies to process the documents.

5.2 Security Processing Steps

  1. Download Detection: Detecting File Move/Copy Events
  2. Policy Check: Check the security status of the target file for download
  3. Document Conversion: Convert to appropriate security document according to policy
  4. Download Execution: Save the converted document to a local path

5.3 Support Scenarios

divisionDocument Security 6Note
OneDrive/SharePoint → General PathDownload after conversionZTCAP fileEvent - CopyFileFrom_OneDrive - CopyFileFrom_Sharepoint
OneDrive/SharePoint → OneDrive/SharePointUnsupportedSince it is a migration between clouds, control is not applied.

5.4 Actions by Authentication Status

  • DS6 Login Status: When downloading files from external storage, the converted files are saved according to the policy.
  • DS6 Logout Status: Downloading files from external storage is blocked.

6. Security Control When Viewing Documents

6.1 Overview

When accessing the document, the system automatically checks the security policy and, if necessary, converts the document to ensure safe viewing.

6.2 Security Processing Procedure

  1. Access Request Detection: Document Viewing Event Detection
  2. Policy Check: Check policies based on document path and security status
  3. Document Conversion: Convert to a secure document according to policy (if necessary)
  4. Access Allowed: Safely view the converted document

6.3 Access Policy by Path

divisionDocument Security 6Note
General Path DocumentView After ConversionZTCAP fileEvent - ApplicationFileOpen custom policy - DS_MIP_SHLL : open
OneDrive Path DocumentGeneral Document: Unsupported Security Document: Access Blocked MIP Document: UnsupportedSecurity documents need to be accessed after MIP conversion.
SharePoint Path DocumentGeneral Document: View After Conversion Security Document: View After Conversion MIP Document: View After ConversionSupport for all document type conversions

6.4 Policy Application Mechanism

img

Application of ZTCAP Policy at Document Viewing Time
Document Event - Specify conversion policy when viewing documents to support conversion to documents registered in the execution policy at the time of viewing.

  • Access Restrictions for Security Documents
    Viewing secure documents (DRM) in OneDrive can be done after converting them to MIP documents via the SHILDRM service (or by right-clicking the user menu to switch to MIP/general documents for viewing).

Cases where conversion is not supported during document viewing

  • Before Integrated Login
  • Local OneDrive path document files
  • File with a document size of 0 bytes
  • If the MIP supported extension is not an Office extension

7. Document Conversion and Security Label Management

7.1 Overview

This is a feature that allows users to manually change the security level of a document or manage MIP labels.

7.2 Supported Features

  • General Document → Create MIP Label
  • Convert Security Document (DRM) to MIP Document
  • MIP Document → Delete MIP, Convert to DRM Document

7.3 Support Features by Path

divisionDocument Security 6Note
General Path DocumentGeneral Document: Create MIP Label Security Document: Convert to MIP Document MIP Document: Delete MIP, Convert to DRM Document Multi-file/Folder SupportCustom Policy - DS_MIP_SHLL_MENU DS6 : Convert to ZTCAP Policy
OneDrive Path DocumentGeneral Document: Create MIP Label Security Document: Convert to MIP Document MIP Document: Delete MIP Multi-file/Folder SupportOneDrive path characteristics limit DRM conversion
SharePoint Path DocumentGeneral Document: Create MIP Label Secure Document: Convert to MIP Document MIP Document: Delete MIP, Convert to DRM Document Multi-file/Folder SupportSupport for all transformation functions

8. External Storage Upload Block (Selective Block · Notice Replacement)

8.1 Overview

When uploading documents to cloud storage such as OneDrive or SharePoint (copying or moving), documents classified under the company's security policy as "prohibited from export" are**Replace the original with the guide file.**This is a feature that prevents sensitive documents from leaving the cloud. Allowed level documents are uploaded as is. Even if blocked, the operation ends like "success," so the process of uploading multiple files at once does not stop in the middle or display an error window.

info

Summary: Quietly selectively block the cloud upload of sensitive grade documents and upload a notice instead of the original. Once the task is complete, it informs the results per file (move/block/error) in a single window.

Reason for Needing This Feature

Previously, when documents were uploaded to the cloud, only conversion (encryption, security level application) was performed according to policy, and**"There were no means to completely prevent a specific grade from being raised."**Therefore, there was a risk that sensitive documents such as confidential and proprietary information could be exported to the cloud. This feature fills that gap by selectively blocking uploads based on document classification.

Operation Method (Single Line Mechanism)

Documents identified as blocked by the server policy will be replaced with a notice (원본명_차단됨.txtWhen this goes up to the cloud (quiet block), the allowed documents will be uploaded normally. Once the task is complete, the results for each file will be displayed in one window (only when there is at least one block or error — if everything is normal, there will be no notification).

8.2 Scope / Entry Point

Entry Pointsupport
Local Explorer → OneDrive/SharePointcopy(Ctrl+C/V)support
Local Explorer → OneDrive/SharePointMove·Dragsupport
folderUnit MovementSupport (also replaces blocked documents in the folder)
Teams Copilot UploadOutside the scope of this document due to different integration methods.
Cloud → Cloud Migration, Downloadnon-target

8.3 User Scenario

This is a simple summary of what happens when a user does something.

What the user doesWhat happens?
Copying/Moving General (Allowed) Documents to OneDrive/SharePointIt will be uploaded normally as usual.
Copying and moving documents with a classification level (e.g., confidential)The original is not uploaded, and원본명_차단됨.txtThe guide file will be uploaded instead.
Uploading multiple documents at onceOnly the blocked targets will be changed to the guidance file, and the rest will be uploaded normally. Once the work is completed, it will be displayed at a glance in the results window.
Upload (Move) FolderOnly the blocked documents in the folder will be changed to a guide file, and the original folder will remain on my PC as it is.
No blocked documents (all allowed)It completes quietly without displaying the result window.

8.4 Constraints

  • Local duplication when folder movement is blocked: If you move a folder that contains blocked documents, the entire original folder is preserved locally. At this time, allowed documents exist (duplicate) both locally and in the cloud — this is an intended action to prevent data loss.
  • Supported file extensions only: The targets for cloud upload blocking are Office (docx/xlsx/pptx, etc.) and PDF. HWP/HWPX, etc. are not targets for blocking, and if blocking is necessary, a separate extension for supported file types is required.
  • Notice Protection Level: The notice is plaintext without a security label. It does not contain sensitive information, and the security objective (non-export of sensitive originals to the cloud) is achieved by not uploading the originals.
  • Server Policy Dependency: The block level determination depends on the server conditional policy. If the policy is not registered, the existing transformation and upload flow will remain unchanged.
  • excluding appAuth mode: appAuth mode does not use conditional policies and is not subject to this block.
  • Teams Copilot Upload: The integration method with the explorer is different, so this feature is outside the scope.

8.5 User Interface (UX)

When the task is completed, the results window will appear (only when there are blocks or errors).

┌──────────────────────────────────────────────┐
│ Document Security │
│ Upload Blocked │
│ ┌────────────────────────────────────────┐ │
│ │ Target Files │ │
│ │ report.docx ✓ Moved │ │
│ │ confidential_document.docx ! Blocked │ │
│ │ revenue.xlsx ! Blocked │ │
│ └────────────────────────────────────────┘ │
│ [ Confirm ] │
└──────────────────────────────────────────────┘
  • Blocked documents are in the cloud원본명_차단됨.txt(Notice) goes up.
  • The result window is for that task'sAll filesshows the status (moved/blocked/error).
  • Successfully uploaded tasks do not display a results window (to prevent unnecessary notifications).

8.6 Policy / Settings

  • Whether blocked isServer Conditional Policy (ZTCAP)"Upload Block"uploadBlock) Controlled by the execution card.
  • The grade to be blocked (e.g., C·S grade) is specified in the policy's "Target Document Security Label Conditions." The client only checks whether there is a block card in the response.

8.7 Supported Scope (Extension)

  • Support: Microsoft Office (docx/xlsx/pptx, etc.) · PDF.
  • Unsupported: HWP/HWPX and other extensions are not subject to upload restrictions (8.4 constraints).

8.8 Main Flow

  • Administrator: Conditional Policy Registration (Upload Block Card ON + Block Level Designation).
  • User: Copy/Move document to OneDrive/SharePoint → Replace notice (Blocked Level) / (Allowed) Normal Upload → Result window at the end of the task.