Reference Guide

Security Management Server Virtual v10.2.7 AdminHelp
105
detected on protected Office
documents but not .xen files.
Modified
Repaired tampering
Tampering was detected in the
wrapper of the protected Office
document, which contains the cover
page that opens in the cloud or on a
device that does not have Data
Guardian installed. Data Guardian
repaired the wrapper or cover page.
Attempt Access
Request Access
An external user requested a key for
a file to which they do not have
access or the access time has
expired. Audit data includes user
account, time stamp, filename, key
ID, and geolocation if enabled by
policy.
Modified
Unprotected:
A Mac user unprotected a protected
Office file or a Basic File Protected
one-time decrypt.
Windows - Opt-in mode only, for
example, a protected Office
document is open and the user
selects Save As and unprotects it.
(Opt-in mode)
Deleted
(Mac only)
Deleted
The user deleted a .xen file from the
cloud sync folder.
Accessed
(Mobile only)
Geo Blocked
A user outside the geofence tried to
access a protected document, and
the attempt was blocked.
Open
(Windows only)
Used with Email Action.
Sent
(Windows only)
Used with Email Action.
Reply
(Windows only)
Used with Email Action.
Forward
(Windows only)
Used with Email Action.
.
Column options for System (protected Office documents and Windows)
The following actions relate to the computer, so they have no corresponding Data Guardian action.
Note: The grey options apply to Windows and Data Guardian v2.7 and earlier.
Audit Event - Column options
Description
Login
If a user logged in and did a fast user switch, for example, logged in and then rebooted.
Logout
User logged out of a session.
Blocked PrintScreen
(Windows only and Data Guardian v2.7 and
earlier)
Indicates a file where a user tried to capture a screen while a protected Office document was open
and is blocked.
Blocked Process
(Windows only and Data Guardian v2.7 and
earlier)
When policy blocks a specified process executable, indicates a file where a user tried to run that
process executable.