This article outlines the Document Services and the additional features related to Data Leak Prevention by controlling attachments sent to or from your organization. They can be used to remove confidential metadata from documents or convert documents to a different format before they are delivered to a recipient. Document Services can also be used to strip revision information from documents, including:
- Document properties.
- Author credentials.
- Tracked changes.
- Comments.
- Microsoft Visual Basic for Applications macros.
Most of these are never knowingly added and, more importantly, are never intended to be viewed outside an organization.
Considerations
Consider the following before configuring a definition or policy:
- Documents can be automatically converted into PDF or ODF format. This reduces the potential risk of metadata access and secures documents against any accidental or intentional changes by the recipient.
- To aid in communicating with external organizations that may have different versions of Microsoft Word, policies can be created to convert Word documents into older or newer versions.
- You can configure a Document Services Bypass policy to override aspects of this policy. See the Document Services Bypass page for full details.
Configuring a Document Services Definition
To configure a Document Services definition:
- Log in to the Mimecast Administration Console.
- Click on the Policies | Gateway Policies menu item. The Gateway Policy Editor is displayed.
- Click on the Definitions button. A list of definition types is displayed.
- Click on the Document Services definition type from the list.
- Select a Folder in the navigator. A definition cannot be created in the Root folder.
- Either click on the:
-
-
- Definition to be changed.
- New Document Definition button to create a definition.
-
- Complete the Office Document Processing section as follows:
| Field / Option | Description |
| Description | Enter a description for the definition. |
| Metadata Profile |
If using the definition to strip metadata, select a Metadata Profile to apply. If you are using the definition to only convert documents, leave the profile as None. The profile selected determines what is stripped by us when the document is processed. The default profiles available group certain aspects that can be stripped together. Alternatively, the Custom profile can be selected to allow you to choose the items to be stripped from a list.
|
| Add Watermark |
This option adds a watermark on each page of a Word or RTF document before it is transformed to PDF. These are the only currently supported file types. Adding watermarks directly to documents that have been transformed to PDFs is currently not supported. The text entry is limited to a maximum of 212 characters. |
| Document Conversion |
If using the definition to convert documents, select one of the options below. If the definition's purpose is to strip metadata only, leave this option as Do Not Convert.
|
| Source Files |
Specify what type of source document to apply the services to. If no source file types are specified, the definition won't be applied to any outgoing documents. |
- Complete the Action on Failed Conversion section as follows:
| Field / Option | Description |
| Policy Action | Specify the action to be taken should conversion / processing fail. The available actions are Allow and Hold for Review. All the following fields are only visible if the Hold for Review option is selected. |
| Hold Type |
Restricts the view of held messages in the On Hold Message Queue. The options are:
For Data Leak Prevention (DLP) reasons a user won't be able to release outbound items that were placed on hold due to a Content Examination policy. |
| Moderator Group | Use the Lookup button to select a group of moderators who can review and action the message when placed on hold. This option is only available for User and Moderator Hold types. |
| Notify Group | Use the Lookup button to select a group of users to be notified when the policy is triggered. |
| Notify (Internal) Sender | Notifies an internal sender that the policy has been triggered. |
| Notify (External) Sender | Notifies an external sender that the policy has been triggered. |
| Notify (Internal) Recipient | Notifies an internal recipient that the policy has been triggered. |
| Notify (External) Recipient | Notifies an external recipient that the policy has been triggered. |
| Notify Overseers | Notifies the Oversight Group should a Content Overseer policy be configured for the communication pair of the message that triggered the Document Services definition. |
- Click on the Save and Exit button.
Configuring a Document Services Policy
To configure a Document Services policy:
- Log in to the Mimecast Administration Console.
- Select the Policies | Gateway Policies menu item.
- Click on Document Services.
- Either click on the:
-
-
- Policy to be changed.
- New Policy button to create a policy.
-
- Complete the Options section as required:
| Field / Option | Description |
|---|---|
| Policy Narrative | Policy Narrative |
| Select Document Services Policy | Click on the Lookup button to select the required Document Services definition for the policy. |
- Complete the Emails From and Emails To sections as required:
| Field / Option | Description |
| Addresses Based On |
Specify the email address characteristics on which the policy is based. This option is only available in the Emails From section. The options are:
|
| Applies From / To |
Specify the Sender characteristics on which the policy is based. For multiple policies, you should apply them from the most to the least specific. The options are:
|
- Complete the Validity section as required:
| Field / Option | Description |
|---|---|
| Enable / Disable | Use this to enable (default) or disable a policy. Disabling the policy allows you to prevent it from being applied without having to delete or backdate it. Should the policy's configured date range be reached, it is automatically disabled. |
| Set Policy as Perpetual | Specifies that the policy's start and end dates are set to "Eternal", meaning the policy never expires. |
| Date Range | Specify a start and end date for the policy. This automatically deselects the "Eternal" option. |
| Policy Override | Select this to override the default order in which policies are applied. If there are multiple applicable policies, this policy is applied first unless more specific policies of the same type have also been configured with an override. |
| Bi-Directional | If selected, the policy also applies when the policy's recipient is the sender and the sender is the recipient. |
| Source IP Ranges (n.n.n.n/x) | Enter any required Source IP Ranges for the policy. These only apply if the source IP address used to transmit the message data falls within or matches the range(s) configured. IP ranges should be entered in CIDR notation. |
- Click on the Save and Exit button.
Comments
Please sign in to leave a comment.