The Path Access Control feature protects critical files, folders, and registry paths from unauthorized access or modification. It allows you to define protected paths and ensure that only trusted processes are permitted to access them, helping safeguard sensitive system and application resources.
You can configure path protection by adding individual files, folders, registry keys, or registry values. The feature also supports importing multiple path entries from a .dat file for faster configuration.
Note: Ensure that the DLP license is assigned to the endpoint for this feature to work as expected.
Configuring Path Access Control
To configure Path Access Control:
-
Go to Policies > Feature/Container Policies.
-
Create a new policy or edit an existing policy.
-
Expand Path Access Control.
-
Turn on the Path Access Control toggle.
-
Click Add Path.
-
In the Add Path dialog box, specify the following details:
-
Type: Select the type of path to protect. Available options include Folder, File, Registry Key, and Registry Value.
-
System Macro: Select a predefined system macro to simplify path configuration. (Mandatory for registry key and registry value)
-
Protected Path: Enter the path to protect. The input varies based on the selected type:
- Enter folder path
- Enter file path
- Enter registry key path
- Enter registry value path
-
Protected Path Preview: Displays the resolved protected path based on the selected type, macro, and entered path. Verify the preview before saving the configuration.
-
-
Click Add Path.
The configured path is added to the protected path list.
Note: Verify the protected path preview before adding it to the list to ensure that the intended path is protected.
Managing Protected Paths
The Path Access Control page displays all configured protected paths.
You can perform the following actions:
| Action | Description |
|---|---|
| Search Paths | Search configured paths by using the search box. |
| Filter | Filter entries based on the selected path type. |
| Edit | Modify an existing protected path configuration. |
| Delete | Remove a protected path from the list. |
| Deny Read | Denies all the Create, Read, Update, and Delete operations to the selected protected path. |
| Deny Write | Denies the Write operation to the selected protected path. |
| Import | Import multiple path entries from a .dat file. |
| Export | Export the configured path entries for backup or reuse. |
Important: The following system-critical directories are excluded from User Protection to avoid interference with operating system functionality and ensure system stability:
- (“%SystemRoot%”),
- (“%SystemRoot%\\\\System32”),
- (“%SystemRoot%\\\\SysWOW64”),
- (“%SystemRoot%\\\\System32\\\\drivers”),
- (“%SystemRoot%\\\\Boot”),
- (“%SystemRoot%\\\\System32\\\\config”),
- (“%ProgramFiles%”),
- (“%ProgramFiles(x86)%”)
- (%SystemDrive%”)
Refer this list of macros that can be used while configuring file/folder paths and registry locations.
File and Folder Locations
- < QH_FOLDER >
- < QH_NATIVE_FOLDER>
- < WINDOWS_FOLDER>
- < SYSTEM32_FOLDER>
- < PROGRAM_FILES_FOLDER>
- < DRIVERS_FOLDER>
- < QH_ADMIN_FOLDER>
- < TEMP_FOLDER>
- < BOOT_DRIVE>
- < QH_CLIENTAGENT_FOLDER>
- < SYSTEMWOW64_DRIVE>
- < SYSTEM_DRIVE>
- < UPDMGR_FOLDER>
- < PATCH_MANAGEMENT_FOLDER>
- < PATCH_MANAGEMENT_CONTENT>
Registry Locations:
- < HKLM>
- < HKCU>
- < RUN>
- < SERVICES>
File and Folder Macros:
| Macro | Description |
|---|---|
| <QH_FOLDER> | Seqrite installation directory. |
| <QH_NATIVE_FOLDER> | Native platform-specific Seqrite installation directory. |
| <WINDOWS_FOLDER> | Windows installation directory (typically C:\Windows). |
| <SYSTEM32_FOLDER> | Windows System32 directory (typically C:\Windows\System32). |
| <PROGRAM_FILES_FOLDER> | Program Files directory (typically C:\Program Files). |
| <DRIVERS_FOLDER> | Windows drivers directory (typically C:\Windows\System32\drivers). |
| <QH_ADMIN_FOLDER> | Seqrite Admin component installation directory. |
| <TEMP_FOLDER> | System temporary files directory. |
| <BOOT_DRIVE> | Boot drive of the operating system (typically C:). |
| <QH_CLIENTAGENT_FOLDER> | Seqrite Client Agent installation directory. |
| <SYSTEMWOW64_FOLDER> | Windows SysWOW64 directory (typically C:\Windows\SysWOW64). |
| <SYSTEM_DRIVE> | Operating system drive. |
| <UPDMGR_FOLDER> | Update Manager installation directory. |
| <PATCH_MANAGEMENT_FOLDER> | Patch Management component installation directory. |
| <PATCH_MANAGEMENT_CONTENT> | Repository location used for Patch Management content/packages. |
Registry Macros:
| Macro | Description |
|---|---|
| HKLM | HKEY_LOCAL_MACHINE registry hive. |
| HKCU | HKEY_CURRENT_USER registry hive. |
| RUN | Windows Run registry key used for startup applications. |
| SERVICES | Registry path containing Windows services configuration. |
Trusted Processes
Use Trusted Processes to allow specific applications or processes to access protected paths without being restricted by Path Access Control.
To add a trusted process:
- In the Trusted Process section, enter the Application Name.
- Enter the Process Name or Path associated with the application.
- Click Add.
The configured trusted process is added to the list and is allowed to access the protected paths.
| Field | Description |
|---|---|
| Application Name | Enter the name of the application to trust. |
| Process Name or Path | Enter the process name or the path of the process that should be trusted. |
Note: Add only applications or processes that you trust. A trusted process can access protected paths and may therefore bypass the restrictions applied by Path Access Control.
Importing Path Entries
The Import option enables you to add multiple protected paths in a single operation.
To import path entries:
- Click Import.
- Browse to and select the required .dat file.
- Click Open.
The path entries from the selected file are added to the protected path list.
Exporting Path Entries
To export the configured path entries:
- Click Export.
- Save the generated .dat file to the required location.
You can use the exported file to import the same configuration into another policy or deployment.