Skip to main content

Conditional Policy - Endpoint(DS6)

※ Last updated: 2025-05-21

Endpoint conditional policies are features that allow you to set conditional policies in Document Security 6 installed on a local PC and control the security processing of documents. It is possible to convert regular documents into AIP documents or DRM documents, or to interchange between AIP documents and DRM documents. This guide explains the components and configuration methods of Endpoint conditional policies.

Endpoint Conditional Policy Configuration Components

Click on the Conditional Policy menu in the SHIELD DRM Admin Page to access the Endpoint screen.

Policy List Table Structure

  • Priority: Indicates the order of policy implementation.
  • Policy Name: This is the unique name of the policy.
  • Description: The purpose of the policy or a brief description.
  • Members: Specifies the users, groups, or policy groups to which the policy applies.
  • Target Document: Document types to which the policy applies (General Document, DRM, AIP)
  • Document Path: Specifies the file path where the policy is applied.
  • Event Trigger: Event types where the policy is executed (e.g., file save, move, etc.)
  • Document Encryption Policy: This is the document encryption policy applied in the policy.
  • Modified date: This is the date when the policy was last modified.

How to Register Endpoint Conditional Policies

1. Policy Registration

Click the [Policy Registration] button to enter the policy creation screen.

2. Enter Basic Policy Information

  • Policy Name(Required): Enter the unique name of the policy.
  • Policy Description: You can enter the purpose of the policy or a brief description.
  • Member Designation(Required): Select the user or group to which the policy will be applied. It can be specified as [All Users], specific users, groups, or policy groups.
  • Specify Document Type(Required): Select the document type to which the conditional policy will be applied.Multiple selection available(e.g.: General Document + DRM Document)

The available document types and supported extensions are as follows:

Document TypeDescriptionSupported Extensions
General DocumentUnencrypted plaintext documentdoc, docx, xls, xlsx, xlsb, xlsm, ppt, pptx, pps, ppsx, pptm, pdf
DRM DocumentDocument Security(DS) based DRM applied documentdoc, docx, xls, xlsx, xlsb, xlsm, ppt, pptx, pps, ppsx, pptm, pdf
AIP DocumentMicrosoft Azure Information Protection based documentdoc, docx, xls, xlsx, xlsb, xlsm, ppt, pptx, pps, ppsx, pptm, pdf

(+) Additional settings when selecting the specified DRM document:

itemDescription
Check Constructor InformationCheck if the document creator is the same as the logged-in user. Options: Same / Not the same
DRM Document Encryption TypesSelect from DAC(ACL), MAC(category), GRADE(level). Depending on the selected type, you can enter the related ID.
DRM Document Permission AssignmentCheck document permissions for logged-in users, creators, and added groups. Permission types: read, edit, output, check-out, release, change permissions, print marking, validity period
File Extension SpecificationSpecify the extension of the target DRM document

Document Path Specification(Required): You can specify the document path or set it to target the entire path. For example:C:\Users\Documents, %TEMP%

Document Event Specification(Required): Set the event when the policy will be executed.

  • Right-click the mouse and click the [Encrypt Document] menu.
  • Right-click the mouse and click the [Document Conversion] menu.
  • Document Viewing/Editing and Exit (or Save)
  • Document Viewing
  • Moving / Copying Files in OneDrive
  • Moving / Copying Files to OneDrive
  • Moving / Copying Files in SharePoint
  • Moving / Copying Files in SharePoint
  • Downloading Files from the Cloud

3. Setting Conditions

  • Location (IP): You can specify the range of IP addresses to which the policy will be applied.
    • Selecting all registered locations will apply the policy to the entire network.
    • You can specify a specific IP range through selection at the registered location.
    • You can set an exception IP so that the policy does not apply to specific IPs.
  • time: You can specify the time zone in which the policy will be applied.
    • If you select no time limit, the policy will always apply.
    • You can specify a specific time zone by selecting from the registered times.
    • You can set exception times so that the policy does not apply during specific time zones.

4. Document Policy Enforcement Settings

The document enforcement policies that can be set in the endpoint policy are as follows:

  • Encryption with DRM: Encrypt the document in DRM format to enhance security. You can choose the type of DRM encryption (DAC, MAC, GRADE). DAC permission settings: You can specify reading, editing, releasing, exporting, outputting, marking, changing permissions, etc.
  • Encryption with AIP: You can encrypt documents and apply labels through Microsoft AIP. Select an AIP label to assign a label to the document. Labels can be selected from a predefined list of AIP labels.
  • Maintain State: The encryption status of the existing document is maintained as is, and no transformation work is performed.

5. Policy Settings

You can set the usage and validity period of the policy.

  • Usage status: You can set the activation or deactivation of the policy through the toggle button.
  • Expiration Date: You can specify a start date and an expiration date, and the expiration date willindefiniteYou can set it to.

6. Save and Complete

When all settings are complete,SaveClick the button. It will be registered in the policy list, and afterwardsEdit/DeleteIt is possible.

Editing Endpoint Conditional Policy

You can click on the policy to edit in the policy list to change the detailed settings. Changing the order of the policies resets the priority.

Caution

  • The policy name must be unique and cannot be duplicated.
  • Required fields (*) must be filled in for the policy to be saved.
  • For DRM and AIP documents, you need to check and configure the list of convertible file extensions.
  • Items with higher priority in the policy will be executed first.
  • When editing the policy, the changes will be applied by clicking the save button.