> For the complete documentation index, see [llms.txt](https://docs.guardware.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.guardware.com/documentation/insight/policies/advanced-settings.md).

# Advanced Settings

Advanced Settings define the global monitoring parameters applied across audit reports and device policies in GuardWare INSIGHT. They function as the central control point for how monitoring is configured and enforced across the organisation.

These settings determine how INSIGHT operates on end-user devices, including the methods used to monitor the movement of sensitive data, the applications, URLs, and file extensions that are included or excluded from monitoring, and the configuration of communication between devices and the server.

## Reference Table

The table below provides an overview of every Advanced Setting and what it does.

<table><thead><tr><th width="292.8887939453125">Section</th><th>What it does</th></tr></thead><tbody><tr><td><a href="#environment-settings">Environment Settings</a></td><td>Controls the intervals, durations, timeouts, and bandwidth settings for uploading reports and downloading policies and commands.</td></tr><tr><td><a href="#applications-monitored-at-network-level">Applications Monitored at Network Level</a></td><td>Lists applications monitored for sensitive data uploads at the network level.</td></tr><tr><td><a href="#ip-addresses-not-monitored-at-network-level">IP Addresses Not Monitored at Network Level</a></td><td>Lists IP addresses that are not monitored for sensitive data.</td></tr><tr><td><a href="#websites-monitored-at-network-level">Websites Monitored at Network Level</a></td><td>Lists certificate common names for which SSL traffic is, or is not, monitored.</td></tr><tr><td><a href="#websites-monitored-by-chromium-extensions">Websites Monitored by Chromium Extensions</a></td><td>Lists URLs for which traffic is, or is not, monitored by Chromium Extensions.</td></tr><tr><td><a href="#applications-monitored-at-file-system-level">Applications Monitored at File System Level</a></td><td>Lists applications monitored for sensitive data uploads at the file system level.</td></tr><tr><td><a href="#applications-excluded-from-keystroke-monitoring">Applications Excluded from Keystroke Monitoring</a></td><td>Lists applications where keystrokes are not monitored for sensitive data.</td></tr><tr><td><a href="#websites-excluded-from-keystroke-monitoring">Websites Excluded from Keystroke Monitoring</a></td><td>Lists websites where keystrokes are not monitored for sensitive data.</td></tr><tr><td><a href="#applications-excluded-from-copypaste-monitoring">Applications Excluded from Copy/Paste Monitoring</a></td><td>Lists applications where copy/paste activity is not monitored for sensitive data.</td></tr><tr><td><a href="#websites-excluded-from-copypaste-monitoring">Websites Excluded from Copy/Paste Monitoring</a></td><td>Lists websites where copy/paste activity is not monitored for sensitive data.</td></tr><tr><td><a href="#file-extensions-monitored-at-file-system-level">File Extensions Monitored at File System Level</a></td><td>Lists file extensions that are, or are not, monitored at the file system level.</td></tr><tr><td><a href="#websites-with-end-to-end-encryption">Websites with End-to-End Encryption</a></td><td>Lists websites with end-to-end encryption.</td></tr></tbody></table>

## Create an Advanced Setting

Before configuring any monitoring parameters, an Advanced Setting policy must be created first. Once created, it starts in an Inactive state and must be configured before it can be activated and applied to devices.

<figure><img src="https://3625419753-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FrbF1elaBmiAnq9oEPmNP%2Fuploads%2FbOr45zhF5NqoyJY1oC5C%2Fimage.png?alt=media&amp;token=0fb97e0a-89f1-4366-98b8-75df19cae298" alt=""><figcaption></figcaption></figure>

1. Navigate to **INSIGHT** > **Advanced Settings**.
2. Click **+ New Advanced Setting**.

{% stepper %}
{% step %}

### Configure Policy Info

3. In the **Policy Info** tab, fill in the following fields and click **Next**:<br>

   <figure><img src="https://3625419753-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FrbF1elaBmiAnq9oEPmNP%2Fuploads%2F0UJx4tk8PYen6s6uq7p8%2Fimage.png?alt=media&amp;token=a6b6cb84-5d67-4a61-918c-4e8e5859b70e" alt="" width="563"><figcaption></figcaption></figure>

   1. **Copy Settings From (Optional):** Select an existing Advanced Setting to copy its configuration into this new one. Useful for duplicating a baseline policy instead of starting from scratch.
   2. **Setting Name:** Enter a clear, identifiable name for the setting.
   3. **Description:** Briefly describe what this setting is for, who it applies to, or how it differs from other settings.
   4. **Set as Default Setting (Optional):** Marks this as the organisation-wide default. Only one default setting can be active at a time; it is automatically assigned to all newly created users and can be duplicated to create policy variations from a common baseline.
      {% endstep %}

{% step %}

### Configure Settings

Once created, the **Advanced Setting** starts in an **Inactive** state. Configure the required settings, then activate when ready to apply to devices. Each setting can be enabled or disabled. Disabling a setting reverts it to its default state, disabling the associated functionality.

<figure><img src="https://3625419753-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FrbF1elaBmiAnq9oEPmNP%2Fuploads%2Fdn5WNR8kmkRc2U51SmpT%2Fimage.png?alt=media&amp;token=a28b3dc1-984a-48fe-b285-bdc79a5a1bf6" alt=""><figcaption></figcaption></figure>

<details open>

<summary><strong>Environment Settings</strong></summary>

Controls the intervals, durations, timeouts, and bandwidth settings for uploading reports and downloading policies and commands.

<table><thead><tr><th width="116">Setting</th><th width="100">Default</th><th width="190">Description</th><th>When to Change</th></tr></thead><tbody><tr><td><strong>Client Responsiveness</strong></td><td>Normal Operation</td><td>Determines how frequently agents download commands and settings and upload reports. Very Responsive, Responsive, and Normal Operation correspond to intervals of 1 minute, 5 minutes, and 15 minutes respectively.</td><td>Increase responsiveness if near-real-time policy enforcement is required. Be aware that shorter intervals increase network and system overhead.</td></tr><tr><td><strong>Enable Chromium Extensions</strong></td><td>Disabled</td><td>An alternative approach to monitoring browsers at the network level.</td><td>Enable if network-level browser monitoring is insufficient or unavailable in the environment.</td></tr><tr><td><strong>Incognito / Private Browsing</strong></td><td>Incognito / In Private mode browsing allowed</td><td>Controls whether users can open private browsing windows. Enable <strong>Enable Chromium Extensions</strong> to access this setting. Chromium Extensions cannot be forced to load in private windows, except in Microsoft Edge.</td><td>Block private browsing to prevent unmonitored activity. Allow it without monitoring only where appropriate. Select the Microsoft Edge option to allow and monitor Edge private windows while blocking private browsing in other browsers. Use network monitoring when users need private browsing in browsers other than Edge.</td></tr><tr><td><strong>File System Level Monitoring</strong></td><td>Enabled</td><td>Uses a file system level driver to monitor uploads through changes in the network information associated with files.</td><td>Disable if file system-level monitoring is not required or conflicts with existing endpoint software.</td></tr><tr><td><strong>Passive Monitoring of File Uploads to Cloud Drives</strong></td><td>Disabled</td><td>An alternative approach to monitoring file uploads to cloud drives at the file system level.</td><td>Enable if file system-level monitoring does not adequately capture cloud drive upload activity.</td></tr><tr><td><strong>Network Level Monitoring</strong></td><td>WFP</td><td>WFP and LSP are Windows networking technologies used to inspect network traffic.</td><td>Switch to LSP if WFP is incompatible with the environment or conflicts with other network drivers.</td></tr><tr><td><strong>USB Monitoring</strong></td><td>Enabled</td><td>Monitors insertions of, and file transfers to, USB devices.</td><td>Disable only if USB monitoring is managed by a separate solution or is not required in the environment.</td></tr><tr><td><strong>GuardWare File Protection</strong></td><td>Enabled</td><td>Prevents end users from editing or deleting files within the GuardWare Program Files and Program Data folders.</td><td>Disable temporarily for maintenance or troubleshooting only.</td></tr><tr><td><strong>GuardWare Process Protection</strong></td><td>Enabled</td><td>Prevents end users from terminating the main GuardWare processes.</td><td>Disable temporarily for maintenance or troubleshooting only.</td></tr></tbody></table>

</details>

<details>

<summary><strong>Applications Monitored at Network Level</strong></summary>

List of applications that are monitored for sensitive data uploads at the network level. The proxy can only monitor applications that are explicitly on this list. If an application is not selected, its traffic will not be captured.

<figure><img src="https://3625419753-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FrbF1elaBmiAnq9oEPmNP%2Fuploads%2FsE1JDlGQmwlIUbzlWl1a%2Fimage.png?alt=media&amp;token=457de912-f527-41d2-9711-9f3d88326ba1" alt=""><figcaption></figcaption></figure>

1. Click **+ Add Setting** to open the configuration window.
2. A default set of applications is preselected for monitoring. To add more, use the search field to find the application and select the checkbox next to it.
3. If the application does not appear in the list, enter the executable name (e.g., `chrome.exe`) in the **Add Application** field and click **Add Application**.
4. Once added, select the checkbox next to it to include it in monitoring.

</details>

<details>

<summary><strong>IP Addresses Not Monitored at Network Level</strong></summary>

List of IP addresses that are not monitored for sensitive data. The list shows excluded IP addresses used by internal applications that are considered secure and do not need monitoring for the uploading of sensitive data.

<figure><img src="https://3625419753-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FrbF1elaBmiAnq9oEPmNP%2Fuploads%2FMpvvxzCwG09Mlu9N4xoh%2Fimage.png?alt=media&amp;token=929e3ed9-48fe-4e50-8c52-303cb63246cb" alt=""><figcaption></figcaption></figure>

1. Click **+ Add Setting** to open the configuration window.
2. Enter the IP address in the **Add IP** field and click **Add IP.**
3. Confirm the IP address appears in the list and close the window

</details>

<details>

<summary><strong>Websites Monitored at Network Level</strong></summary>

List of SSL certificate common names included in or excluded from network-level monitoring.

<figure><img src="https://3625419753-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FrbF1elaBmiAnq9oEPmNP%2Fuploads%2FvPueMKEVJGSEfwDzMljp%2Fimage.png?alt=media&amp;token=e796c75a-e24e-47a8-b787-e9df147a1947" alt="" width="522"><figcaption></figcaption></figure>

1. Click **+ Add Setting** to open the configuration window.
2. Select **Include** to monitor only listed websites. Select **Exclude** to monitor every website except those listed.
3. Search for and select a website, or enter its certificate common name and click **Add Website**.
4. Confirm the website appears in the list.

</details>

<details>

<summary><strong>Websites Monitored by Chromium Extensions</strong></summary>

List of URLs included in or excluded from monitoring by Chromium Extensions.

1. Click **+ Add Setting** to open the configuration window.
2. Select **Include** to monitor only listed URLs. Select **Exclude** to monitor every URL except those listed.
3. Search for and select a website, or enter its URL and click **Add Website**.
4. Confirm the website appears in the list.

</details>

<details>

<summary><strong>Applications Excluded from Keystroke Monitoring</strong></summary>

List of applications where keystrokes are not monitored for sensitive data.

1. Click **+ Add Setting** to open the configuration window.
2. Search for an application and select its checkbox to include it.
3. To remove an application, click **X** beside it in the **Selected Applications** list.

</details>

<details>

<summary><strong>Websites Excluded from Keystroke Monitoring</strong></summary>

List of websites where keystrokes are not monitored for sensitive data.

1. Click **+ Add Setting** to open the configuration window.
2. Search for and select a website. Alternatively, enter its URL and click **Add Website**.
3. To remove a website, click **X** beside it in the **Selected Websites** list.

</details>

<details>

<summary><strong>Applications Excluded from Copy/Paste Monitoring</strong></summary>

List of applications where copy/paste activity is not monitored for sensitive data.

1. Click **+ Add Setting** to open the configuration window.
2. Search for an application and select its checkbox to include it.
3. To remove an application, click **X** beside it in the **Selected Applications** list.

</details>

<details>

<summary><strong>Websites Excluded from Copy/Paste Monitoring</strong></summary>

List of websites where copy/paste activity is not monitored for sensitive data.

1. Click **+ Add Setting** to open the configuration window.
2. Search for and select a website. Alternatively, enter its URL and click **Add Website**.
3. To remove a website, click **X** beside it in **Selected Websites**.

</details>

<details>

<summary><strong>File Extensions Monitored at File System Level</strong></summary>

List of file extensions included in or excluded from file system-level sensitive data upload monitoring.

<figure><img src="https://3625419753-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FrbF1elaBmiAnq9oEPmNP%2Fuploads%2FUTSkgumObX2v7FQOApkz%2Fimage.png?alt=media&amp;token=55edbe03-d957-483a-85f8-09a158c2f557" alt="" width="523"><figcaption></figcaption></figure>

1. Click **+ Add Setting** to open the configuration window.
2. Select **Include** to monitor only listed extensions. Select **Exclude** to monitor every extension except those listed.
3. Enter the file extension in the **Add Extension** field (e.g., `pdf`, `xlsx`, `zip`) and click **Add**.
4. Confirm the extension appears in the list.

</details>

<details>

<summary><strong>Applications Monitored at File System Level</strong></summary>

List of applications that are monitored for sensitive data uploads at the file system level.

<figure><img src="https://3625419753-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FrbF1elaBmiAnq9oEPmNP%2Fuploads%2FylpllLAKRQ0VNbeeElth%2Fimage.png?alt=media&amp;token=b7967c86-84df-406b-9c33-4c7357acd092" alt=""><figcaption></figcaption></figure>

1. Click **+ Add Setting** to open the configuration window.
2. A default set of applications is preselected for monitoring. To add more, select the checkbox next to the application in the list.
3. If the application does not appear in the list, enter the executable name (e.g., `chrome.exe`) in the **Add Application** field and click **Add Application**.
4. Once added, select the checkbox next to it to include it in monitoring.

</details>

<details>

<summary><strong>Websites with End-to-End Encryption</strong></summary>

List of websites with end-to-end encryption monitoring. For websites implementing end-to-end encryption, it is not possible to intercept file uploads using network monitoring alone.

Where end-to-end encrypted websites are permitted, and there is a concern that files containing sensitive data may be uploaded, both file system monitoring (file paths and contents) and network monitoring (destinations) are required in order to produce reports containing URL and file path information for the uploaded sensitive data.

<figure><img src="https://3625419753-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FrbF1elaBmiAnq9oEPmNP%2Fuploads%2F0UlUAXEY17tJk1Sgq6LQ%2Fimage.png?alt=media&amp;token=70bfa573-25d6-4c56-8651-65da822d8189" alt=""><figcaption></figcaption></figure>

1. Click **+ Add Setting** to open the configuration window.
2. A default set of websites is preselected. To add more, enter the website in the input field using the format `URL#Title_Substring` (e.g., `whatsapp.com#whatsapp`) and click **Add**.
3. To remove a website, click **X** next to the entry.
4. Close the window.

</details>
{% endstep %}

{% step %}

### Review & Save

1. Scroll to the top of the page and click **Review & Save**. A summary of all configured settings will appear in the side panel.

   <figure><img src="https://3625419753-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FrbF1elaBmiAnq9oEPmNP%2Fuploads%2FtTvmfDCOMEvRnOx4WzYH%2Fimage.png?alt=media&amp;token=73bc5db3-65f2-4ae7-bf90-6c6261e13941" alt="" width="563"><figcaption></figcaption></figure>
2. Review the configurations. To make any changes, close the panel, update the relevant settings, and click **Review & Save** again.

   <figure><img src="https://3625419753-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FrbF1elaBmiAnq9oEPmNP%2Fuploads%2FGqtM6SHIzIpc8s861f0G%2Fimage.png?alt=media&amp;token=0027ec81-e68e-4f52-bdf6-7605c636bf32" alt="" width="563"><figcaption></figcaption></figure>
3. Once satisfied, click **Save** to apply the configuration.
   {% endstep %}
   {% endstepper %}

## Assign Advanced Settings to Devices

After creating an Advanced Setting, it can be assigned to devices from the Advanced Settings list. Devices assigned to a deleted setting automatically revert to the default setting (if it exists), which cannot itself be deleted.

1. Navigate to **INSIGHT** > **Advanced Settings.**
2. Click **Assign Devices** next to the setting you want to assign to a device.

   <figure><img src="https://3625419753-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FrbF1elaBmiAnq9oEPmNP%2Fuploads%2FTf4zavu7KDcsNHW7lpHZ%2Fimage.png?alt=media&amp;token=544fc66a-f88d-47ce-b9d0-dad2cca2be44" alt="" width="563"><figcaption></figcaption></figure>
3. Select devices to assign the setting to, or deselect them to remove the setting.
4. Click **Add** to apply changes.

{% hint style="info" %}

* A device can have only one advanced setting assigned at a time.
* Multiple devices can be assigned to an advanced setting.
* When a new advanced setting is assigned to a device, the existing advanced setting is automatically removed and replaced.
  {% endhint %}

## Edit an Advanced Setting

1. Navigate to **INSIGHT** > **Advanced Settings.**
2. Click <i class="fa-pen-to-square">:pen-to-square:</i> **Edit** next to the relevant setting.<br>

   <figure><img src="https://3625419753-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FrbF1elaBmiAnq9oEPmNP%2Fuploads%2FWlDcglZG63kr4RRAAQz7%2Fimage.png?alt=media&amp;token=674fc51a-1ee8-42ee-b061-0ce53d72bd65" alt="" width="563"><figcaption></figcaption></figure>
3. The process follows the same steps as [**creating a new Advanced Setting**](#create-an-advanced-setting). Update the required fields and settings.
4. Click **Review & Save** to review the changes.
5. Click **Update** to confirm changes.

## Delete an Advanced Setting

1. Navigate to **INSIGHT** > **Advanced Settings**.
2. Click **Delete** <i class="fa-trash-can">:trash-can:</i> next to the relevant setting.<br>

   <figure><img src="https://3625419753-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FrbF1elaBmiAnq9oEPmNP%2Fuploads%2FFpExqeSikOQSkB7mTSLE%2Fimage.png?alt=media&amp;token=d6fb4685-0a47-44bb-9174-fc21f66245fb" alt="" width="563"><figcaption></figcaption></figure>
3. Click **Yes, Delete it!** to confirm.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.guardware.com/documentation/insight/policies/advanced-settings.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
