Users Guide

Table Of Contents
Endpoint Group Precedence can now be modified using drag-and-drop functionality. This functionality applies to Admin-
Defined, Rule-Defined, and Active Directory but not System-Defined Endpoint Groups. Precedence of System-Defined
Endpoint Groups for new installations and upgrades is as follows: Highest precedence is given to Non-Persistent VDI
followed by Persistent VDI Endpoint Group. Lowest precedence is given to Default followed by Opt-in Endpoint Group.
Added 7/2017 - Administrators can now bulk upload and import a CSV list of Endpoints to add to Admin-Defined Endpoint
Groups.
Advanced Threat Prevention and Dell Data Guardian events can now be exported to a syslog server or to a local file through
a streamlined Events Management screen.
New Advanced Threat Prevention policies allow Application Control folder exclusions and automatic deletion of quarantined
files after a configurable length of time.
Log Analyzer results can now be exported to Excel or CSV file.
New Enterprise Edition for Mac policies replace the need to manage some settings through .plist entries.
Secure Lifecycle is rebranded to Dell Data Guardian.
Resolved Technical Advisories v9.7
On the Client Firewall Custom Rule Specify Network page in the Remote Management Console, the Fully qualified domain
name field now validates and rejects invalid formats. Also, the Transport protocol drop-down list item ICMP and the
displayed Message type are now consistent. [DDPS-2820, DDPS-2826, DDPS-2885]
Transport Protocol values are now populated in the drop-down list in Client Firewall Custom Rules. [DDPS-3819].
AdminHelp can now be moved to avoid obscuring important fields in the Remote Management Console. [DDPS-4258]
A few Data Guardian External User Management items that were previously untranslated in the Remote Management
Console are now translated. [DDPS-4404]
The following Enterprise Port Control policies now display with Class: Storage, their parent policy: Subclass Storage: External
Drive Control, Subclass Storage: Optical Drive Control, and Subclass Storage: Floppy Drive Control. [DDPS-4682]
Added 08/2018- Administrators can log in to endpoints with the Logon Authentication Policy for Administrator policy set to
None and None. [DDPS-4739]
Filtering in the Remote Management Console Advanced Threats Protection tab is now functioning as expected.
[DDPS-4772]
The Error Validating Policy dialog that displays when an updated policy value fails validation now includes the related policy
name. [DDPS-4812]
The Data Guardian policy, Enable Callback Beacon, is now disabled by default. [DDPS-4985]
Advanced Threat Event Dashboard Notifications are now properly categorized by Type. [DDPS-4994]
Localizations of Remote Management Console are improved.
Resolved Customer Issues
Recovery of an EMS-encrypted device now proceeds as expected on a computer and Dell Server other than the original
encrypting computer and Server originally managing the device encryption, when the Servers belong to the same federation.
To configure federation, follow these steps:
1. On one of the Servers to be federated, edit <installation folder>\Enterprise Edition\Security
Server\conf\federatedservers.properties:
server.code - Replace "ENC(<Server code>)" with "CLR(<new code; string of characters you select>)". This will be a
shared code among the federated Servers.
Server.uris - List the Servers to be federated, separated with commas. Example: https://server1:8443,https://
server2:8443
2. Save federatedservers.properties.
3. Copy federatedservers.properties and save it off the Security Server.
NOTE: The file must be saved off the Security Server before restart.
4. Restart the Security Server.
After restart, "CLR(<new code; string of characters you select>)" is changed to "ENC(<new shared code>)" and the new
shared Server code is applied to the Security Server.
5. Copy the federatedservers.properties file to the \Security Server\conf folder of each Server to be federated.
6. Restart each Security Server after copying federatedservers.properties to its \conf folder.
Dell Security Management Server Technical Advisories
27