Control
Feature Details
Please be informed that there are some restrictions on data access.
Detailed information about the file control feature isnextYou can check it at.
Overview
Automatically perform encryption and security processing for documents at the time of upload and download to external storage (OneDrive, SharePoint, etc.) to comply with the organization's information security policy.
1. Document Status Display
The security status of the document is visually indicated through the file icon.
| User Screen | Content | Note |
|---|---|---|
| Classification(Label) + Protection(Protect) | The PowerPoint document is displayed as a preview. | |
| Classification (Label) | PowerPoint documents are marked as preview. |
2. When uploading to external storage
2.1 Overview
When uploading documents from a local path to external storage such as OneDrive/SharePoint, the system automatically applies security policies to encrypt and process the documents.
2.2 Security Processing Steps
- Upload Detection: File Move/Copy Event Detection
- Policy Check: Check ZTCAP policy for the original file
- Document Conversion: Convert to a secure document according to policy (apply MIP label or DRM conversion)
- Upload Execution: Upload the converted document to an external storage.
- Backup Storage: (When setting policies) Backup of the original document storage
2.3 Support Scenarios
| Division | Document Security 6 | Note |
| General Path → OneDrive/SharePoint | Upload after conversion | ZTCAP fileEvent - CopyFileTo_OneDrive - CopyFileTo_Sharepoint |
| General Path → General Path | Not supported | Since it is an internal transfer, control is not applied. |
2.4 Actions by Authentication Status
- DS6 Login Status: Upload the converted file according to the ZTCAP policy for the original file.
- DS6 Logout Status: Uploading files to external storage is blocked.

3. Warning Dialog Functionality on Upload
3.1 Feature Overview
When uploading files or folders to the OneDrive path, a notification window will appear to inform you that the document conversion process is in progress.
- [File Conversion Warning Dialog Design]

3.2 Resource Application Information
- resource key\

① Title
② MainMsg
③ SubMsg1
④ SubMsg2
⑤ HelpUrl
# 리소스 파일 정보 c:\Windows\softcamp\sdk\Res\DS\ResUIKOR.rc, 버전 6.0.0.13
....
[CloudCopyMoveWarning]
Title = OneDrive 이동 / 복사 진행중
MainMsg = 작업 완료 전까지는 대상 파일(또는 폴더)을\r\n사용하지 마세요.
SubMsg1 = *대량의 파일은 시간이 오래 걸릴 수 있습니다.
SubMsg2 = *이동 / 복사가 완료되기 전 파일을 열거나 수정하면\r\n오류가 발생할 수 있습니다.
HelpUrl = (안내 사이트 주소)
....
3.4 Limitations
- If you start another copy before the current copy is finished, duplicate windows will occur. (up to 10 windows)
- Basically, the window will automatically close once the copy is complete, but the user can also close the window by pressing confirm.
4. Backup File Storage Functionality During Upload
4.1 Feature Overview
This is a feature that backs up and stores the original documents uploaded to external storage.
4.2 Constraints
- The backup path is the path specified by the policy, or the default path (My Documents)**"CloudDrv_Backup"**A folder is created, and subfolders are created by date, after which backup files are stored in those folders.
- When copying a folder, the folder structure is not maintained, and all converted files are saved under the date folder.
5. When downloading from external storage
5.1 Overview
When downloading documents from external storage such as OneDrive/SharePoint to a local path, the system automatically applies security policies to process the documents.
5.2 Security Processing Steps
- Download Detection: File Move/Copy Event Detection
- Policy Check: Check the security status of the target file for download
- Document Conversion: Convert to appropriate security document according to policy
- Download Execution: Save the converted document to a local path
5.3 Support Scenarios
| Division | Document Security 6 | Note |
| OneDrive/SharePoint → General Path | Download After Conversion | ZTCAP fileEvent - CopyFileFrom_OneDrive - CopyFileFrom_Sharepoint |
| OneDrive/SharePoint → OneDrive/SharePoint | Not supported | Since it is a migration between clouds, control is not applied. |
5.4 Action by Authentication Status
- DS6 Login Status: When downloading files from external storage, converted files are saved according to policy.
- DS6 Logout Status: Downloading files from external storage is blocked.
6. Security Control When Accessing Documents
6.1 Overview
When opening a document, the system automatically checks the security policy and, if necessary, converts the document to ensure it can be viewed safely.
6.2 Security Processing Steps
- Access Request Detection: Document Viewing Event Detection
- Policy Check: Check policies based on document path and security status
- Document Conversion: Convert to a secure document according to policy (if necessary)
- Access Permission: Safely view the converted document
6.3 Access Policy by Path
| Division | Document Security 6 | Note |
| General Path Document | View After Conversion | ZTCAP fileEvent - ApplicationFileOpen custom policy - DS_MIP_SHLL : open |
| OneDrive Path Document | General Document: Unsupported Security Document: Access Blocked MIP Document: Unsupported | Security documents need to be accessed after MIP conversion. |
| SharePoint Path Document | General Document: View After Conversion Secure Document: View After Conversion MIP Document: View After Conversion | Support for all document type conversions |
6.4 Policy Application Mechanism
-

Application of ZTCAP Policy at Document Viewing Time
Document Event - Specify conversion policy when viewing documents to support conversion to documents registered in the execution policy at the time of viewing.
- Access Restrictions for Security Documents
Viewing secure documents (DRM) in OneDrive can be done after converting them to MIP documents through the SHILDRM service (or by right-clicking the user menu to switch to MIP/general documents before viewing).

Cases where conversion is not supported during document viewing
- Before Integrated Login
- Local OneDrive path document files
- File with a document size of 0 bytes
- If the MIP supported extension is not an Office extension
7. Document Conversion and Security Label Management
7.1 Overview
This is a feature that allows users to manually change the security level of a document or manage MIP labels.
7.2 Supported Features
- General Document → Create MIP Label
- Convert Security Document (DRM) to MIP Document
- MIP Document → Delete MIP, Convert to DRM Document
7.3 Support Features by Path
| Division | Document Security 6 | Note |
| General Path Document | General Document: Create MIP Label Security Document: Convert to MIP Document MIP Document: Delete MIP, Convert to DRM Document Multi-file/Folder Support | Custom Policy - DS_MIP_SHLL_MENU DS6 : Convert to ZTCAP Policy |
| OneDrive Path Document | General Document: Create MIP Label Security Document: Convert to MIP Document MIP Document: Delete MIP Multi-file/Folder Support | OneDrive path characteristics limit DRM conversion |
| SharePoint Path Document | General Document: Create MIP Label Secure Document: Convert to MIP Document MIP Document: Delete MIP, Convert to DRM Document Multi-file/Folder Support | Support for all transformation functions |
8. External Storage Upload Block (Selective Block · Notice Replacement)
8.1 Overview
When uploading documents to cloud storage such as OneDrive or SharePoint (copying or moving), documents classified under the company's security policy as "prohibited from export" are**Replace the original with the guide file.**This is a feature that prevents sensitive documents from leaving the cloud. Allowed level documents will still be uploaded as is. Even if blocked, the operation ends like a "success," so tasks that upload multiple files at once do not stop in the middle or display an error window.
Summary: Quietly selectively block cloud uploads of sensitive grade documents and upload a notice instead of the original. Once the task is complete, it informs the results per file (move/block/error) in a single window.
The reason this feature is needed
Previously, when uploading documents to the cloud, only conversion (encryption, security level application, etc.) was performed according to the policy, and**"There was no means to completely prevent a specific grade from being raised."**So there was a risk that sensitive documents such as confidential and proprietary information could be exported to the cloud. This feature fills that gap by selectively blocking uploads based on document classification.
Operation Method (Single Line Mechanism)
The documents identified as blocked by the server policy will be replaced with a notice (원본명_차단됨.txtWhen this is uploaded to the cloud (quiet block), the allowed documents will be uploaded normally. Once the task is complete, the results for each file will be displayed in one window (only when there is at least one block or error — no notification if everything is normal).
8.2 Scope / Entry Point
| Entry Point | support |
|---|---|
| Local Explorer → OneDrive/SharePointcopy(Ctrl+C/V) | support |
| Local Explorer → OneDrive/SharePointMove·Drag | support |
| folderUnit Movement | Support (also replaces blocked documents in the folder) |
| Teams Copilot Upload | Outside the scope of this document due to different integration methods |
| Cloud → Cloud Migration, Download | non-target |
8.3 User Scenarios
This is a simple summary of what happens when a user does something.
| What the user does | What happens? |
|---|---|
| Copying/Moving General (Allowed) Documents to OneDrive/SharePoint | It will be uploaded normally as usual. |
| Copy/Move Restricted Level Documents (e.g., Confidential) | The original is not uploaded, and원본명_차단됨.txtThe guide file will be uploaded instead. |
| Uploading multiple documents at once | Only the blocked targets will be changed to the guidance file, and the rest will be uploaded normally. Once the work is finished, it will be displayed at a glance in the results window. |
| Upload (Move) Folder | Only the blocked documents in the folder will be changed to the guide file, and the original folder will remain on my PC as it is. |
| No blocked documents (all allowed) | It completes quietly without displaying the result window. |
8.4 Constraints
- Blocking Folder Move Causes Local Duplication: If you move a folder that contains blocked documents, the entire original folder is preserved locally. At this time, allowed documents exist in both local and cloud (duplicate) — this is an intended action to prevent data loss.
- Supported file extensions only: The cloud upload block targets Office (docx/xlsx/pptx, etc.) and PDF. HWP/HWPX, etc. are not blocked, and if blocking is necessary, a separate extension for supported file types is required.
- Notice Protection Level: The notice is plaintext without a security label. It does not contain sensitive information, and the security objective (non-export of sensitive originals to the cloud) is achieved by not uploading the original.
- Server Policy Dependency: Block level determination depends on the server conditional policy. If the policy is not registered, the existing transformation and upload flow will remain unchanged.
- excluding appAuth mode: appAuth mode does not use conditional policies and is not subject to this block.
- Teams Copilot Upload: The integration method with the explorer is different, so this feature is outside the scope.
8.5 User Interface (UX)
When the task is complete, the results window will appear (only when there are blocks or errors).
┌──────────────────────────────────────────────┐
│ Document Security │
│ Upload Blocked │
│ ┌────────────────────────────────────────┐ │
│ │ Target Files │ │
│ │ report.docx ✓ Moved │ │
│ │ confidential_document.docx ! Blocked │ │
│ │ revenue.xlsx ! Blocked │ │
│ └────────────────────────────────────────┘ │
│ [ Confirm ] │
└──────────────────────────────────────────────┘
- Blocked documents are in the cloud
원본명_차단됨.txt(Notice) goes up. - The result window is for that task'sAll filesshows the status (moved/blocked/error).
- Tasks that are fully uploaded do not display a result window (to prevent unnecessary notifications).
8.6 Policy / Settings
- Whether to blockServer Conditional Policy (ZTCAP)"Upload Block"
uploadBlock) Controlled by the execution card. - The grade to block (e.g., C·S grade) is specified in the policy's "Target Document Security Label Conditions." The client only checks whether there is a block card in the response.
8.7 Supported Scope (Extension)
- Support: Microsoft Office (docx/xlsx/pptx, etc.) · PDF.
- Unsupported: HWP/HWPX and other extensions are not subject to upload restrictions (8.4 constraints).
8.8 Main Flow
- Administrator: Conditional Policy Registration (Upload Block Card ON + Block Level Designation).
- User: Copy/Move document to OneDrive/SharePoint → (Blocked Level) Replace notice / (Allowed) Normal upload → Result window at the end of the task.