Differences Between Stealth and Interactive DLP Endpoint Modes

Differences Between Stealth and Interactive DLP Endpoint Modes

Summary
This article goes through the differences between stealth and interactive DLP Endpoint modes
Problem
What is the difference between the Stealth mode and Interactive mode when building a DLP Endpoint installation package?
Solution

The Forcepoint DLP Endpoint Client offers 2 modes of operation, Stealth and Interactive:

Interactive Mode:

  • A Websense folder is added to the Windows Start Menu
  • Users can open and interact with the DLP Endpoint Client UI from system tray icon, enabling the ability to manually check for updates and bypass the Endpoint with a provided bypass code
  • Users can save and view files moved to quarantine by the Endpoint Client

Stealth Mode:

  • The Websense folder is not added to the Start Menu
  • The system tray icon is not present
  • No DLP Endpoint Client UI
  • User cannot save or view files moved to quarantine by the Endpoint Client
  • Manually updating the Endpoint policy can be performed through the command line
    • Related Articles

    • Toggling Windows DLP Endpoints Between Stealth and Interactive Mode

      Summary A registry value can be altered to switch between modes. Notes and Warnings Note Take caution when performing actions on the Windows registry. Problem Endpoint packages created using the Stealth Mode option have been deployed on the ...
    • Linux F1E DLP Endpoint Support

      Summary Support for the Linux environment has ceased for the time being. Problem The Linux Endpoint appears to be missing from modern F1E releases and is not present within the F1E and Forcepoint DLP Endpoint Operating System and Browser Support ...
    • Forcepoint DLP Endpoint Status "Disabled" and "Disconnected"

      Product: Forcepoint DLP Endpoint, Forcepoint Security Manager (FSM) Title: Resolving "Disabled" and "Disconnected" Status on Forcepoint DLP Endpoint Clients Overview This article provides guidance for troubleshooting Forcepoint DLP Endpoint clients ...
    • F1E DLP Inline Proxy

      Introduction to the F1E Inline Proxy The Forcepoint DLP Inline Proxy, which runs locally on the F1E Endpoint Client machine, is the preferred way to enforce web policies and is intended to replace the use of F1E browser extensions. As described in ...
    • DLP Endpoint Incidents Missing Risk Level with Neo Endpoint Installed

      Summary Upgrade the Endpoint Classifier to the latest version to resolve the issue. Problem On a DUP-enabled DLP environment with the Neo and DLP Endpoint installed on a machine, generated Risk Ranking incidents are not showing the Risk Level when ...