For the complete documentation index, see llms.txt. This page is also available as Markdown.

Advanced Settings

Advanced Settings define the global monitoring parameters applied across audit reports and device policies in GuardWare INSIGHT. They function as the central control point for how monitoring is configured and enforced across the organisation.

These settings determine how INSIGHT operates on end-user devices, including the methods used to monitor the movement of sensitive data, the applications, URLs, and file extensions that are included or excluded from monitoring, and the configuration of communication between devices and the server.

Reference Table

The table below provides an overview of every Advanced Setting and what it does.

Section
What It Does

Environment Settings

Controls the intervals, durations, timeouts, and bandwidth settings for uploading reports and downloading policies and commands.

Lists applications monitored for sensitive data uploads at the network level.

Lists IP addresses excluded from network-level monitoring.

Websites Not Monitored

Lists websites which do not have their SSL traffic monitored.

Lists applications monitored for sensitive data uploads at the file system level.

Specifies applications where keystroke and copy/paste monitoring is excluded.

Specifies websites where keystroke and copy/paste activity is monitored or excluded.

Filters file upload monitoring by file extension type.

Lists websites with end-to-end encryption where file system monitoring is required alongside network monitoring.

Create an Advanced Setting

Before configuring any monitoring parameters, an Advanced Setting policy must be created first. Once created, it starts in an Inactive state and needs to be configured before being activated and applied to devices.

  1. Navigate to INSIGHT > Advanced Settings.

  2. Click + New Advanced Setting.

1

Configure Policy Info

  1. In the Policy Info tab, fill in the following fields and click Next:

    1. Copy Settings From (Optional): Select an existing Advanced Setting to copy its configuration into this new one. Useful for duplicating a baseline policy instead of starting from scratch.

    2. Setting Name: Enter a clear, identifiable name for the setting.

    3. Description: Briefly describe what this setting is for, who it applies to, or how it differs from other settings.

    4. Set as Default Setting (Optional): Marks this as the organisation-wide default. Only one default setting can be active at a time; it is automatically assigned to all newly created users and can be duplicated to create policy variations from a common baseline.

2

Configure Settings

Once created, the Advanced Setting starts in an Inactive state. Configure the required settings, then activate when ready to apply to devices. Each setting can be enabled or disabled. Disabling a setting reverts it to its default state, disabling the associated functionality.

Environment Settings

Controls the intervals, durations, timeouts, and bandwidth settings for uploading reports and downloading policies and commands.

Setting
Default
Description
When to Change

Client Responsiveness

Normal Operation

Determines how frequently agents download commands and settings and upload reports. Very Responsive, Responsive, and Normal Operation correspond to intervals of 1 minute, 5 minutes, and 15 minutes respectively.

Increase responsiveness if near-real-time policy enforcement is required. Be aware that shorter intervals increase network and system overhead.

Browser Monitoring Using Chromium Extensions

Disabled

An alternative approach to monitoring browsers at the network level.

Enable if network-level browser monitoring is insufficient or unavailable in the environment.

File System Level Monitoring

Enabled

Uses a file system level driver to monitor uploads through changes in the network information associated with files.

Disable if file system-level monitoring is not required or conflicts with existing endpoint software.

Passive Monitoring of File Uploads to Cloud Drives

Disabled

An alternative approach to monitoring file uploads to cloud drives at the file system level.

Enable if file system-level monitoring does not adequately capture cloud drive upload activity.

Network Level Monitoring

WFP

WFP and LSP are Windows networking technologies used to inspect network traffic.

Switch to LSP if WFP is incompatible with the environment or conflicts with other network drivers.

USB Monitoring

Enabled

Monitors insertions of, and file transfers to, USB devices.

Disable only if USB monitoring is managed by a separate solution or is not required in the environment.

GuardWare File Protection

Enabled

Prevents end users from editing or deleting files within the GuardWare Program Files and Program Data folders.

Disable temporarily for maintenance or troubleshooting only.

GuardWare Process Protection

Enabled

Prevents end users from terminating the main GuardWare processes.

Disable temporarily for maintenance or troubleshooting only.

Applications Monitored at Network Level

List of applications that are monitored for sensitive data uploads at the network level. The proxy can only monitor applications that are explicitly on this list. If an application is not selected, its traffic will not be captured.

  1. Click View Settings to open the configuration window.

  2. A default set of applications is preselected for monitoring. To add more, use the search field to find the application and select the checkbox next to it.

  3. If the application does not appear in the list, enter the executable name (e.g., chrome.exe) in the Add Application field and click Add Application.

  4. Once added, select the checkbox next to it to include it in monitoring.

IP Addresses Not Monitored at Network Level

List of IP addresses that are not monitored for sensitive data. The list shows excluded IP addresses used by internal applications that are considered secure and do not need monitoring for the uploading of sensitive data.

  1. Click View Setting to open the configuration window.

  2. Enter the IP address in the Add IP field and click Add IP.

  3. Confirm the IP address appears in the list and close the window

Websites Not Monitored

List of websites whose SSL traffic is monitored for sensitive data uploads. To monitor SSL traffic for specific websites only, select or add their URLs to the list.

  1. Click View Setting to open the configuration window.

  2. Search for the desired websites and select them to add them to the not monitoring list.

  3. If your desired website is not on the list, enter the website URL (e.g., google.com) and click Add Website.

  4. Confirm the website appears in the list, and select it to add it to the not monitoring list.

Applications Excluded from Keystroke and Copy/Paste Monitoring

List of applications where keystrokes and copy/paste activity are not monitored for sensitive data. This is particularly useful for restricting monitoring in sensitive applications such as password managers or tools that handle confidential input.

  1. Click View Setting to open the configuration window.

  2. Select the checkboxes next to the applications to add them to the exclusion list.

Websites Excluded from Keystroke and Copy/Paste Monitoring

List of websites where keystrokes and copy/paste activity are monitored, or not monitored, for sensitive data. This list is usually used to exclude banking or similar websites where users may type personal passwords.

  1. Click View Setting to open the configuration window.

  2. Select the websites to exclude from keystroke and copy/paste monitoring.

  3. If the website is not on the list, add the website using the full URL and click Add Website.

File Extensions Not Monitored at File System Level

A list of file extensions excluded from file system-level sensitive data upload monitoring. Use this to add extensions to the exclusion list and focus monitoring on high-risk file types only.

  1. Click View Setting to open the configuration window.

  2. Enter the file extension in the Add Extension field (e.g., pdf, xlsx, zip) and click Add.

  3. Confirm the extension appears in the list.

Applications Monitored at File System Level

List of applications that are monitored for sensitive data uploads at the file system level.

  1. Click View Settings to open the configuration window.

  2. A default set of applications is preselected for monitoring. To add more, select the checkbox next to the application in the list.

  3. If the application does not appear in the list, enter the executable name (e.g., chrome.exe) in the Add Application field and click Add Application.

  4. Once added, select the checkbox next to it to include it in monitoring.

Websites with End-to-End Encryption

List of websites with end-to-end encryption monitoring. For websites implementing end-to-end encryption, it is not possible to intercept file uploads using network monitoring alone.

Where end-to-end encrypted websites are permitted, and there is a concern that files containing sensitive data may be uploaded, both file system monitoring (file paths and contents) and network monitoring (destinations) are required in order to produce reports containing URL and file path information for the uploaded sensitive data.

  1. Click View Settings to open the configuration window.

  2. A default set of websites is preselected. To add more, enter the website in the input field using the format URL#Title_Substring (e.g., whatsapp.com#whatsapp) and click Add.

  3. To remove a website, click X next to the entry.

  4. Close the window.

3

Review & Save

  1. Scroll to the top of the page and click Review & Save. A summary of all configured settings will appear in the side panel.

  2. Review the configurations. To make any changes, close the panel, update the relevant settings, and click Review & Save again.

  3. Once satisfied, click Save to apply the configuration.

Assign Advanced Settings to Devices

After creating an Advanced Setting, it can be assigned to devices, edited, or deleted from the Advanced Settings list. Devices assigned to a deleted setting automatically revert to the default setting, which cannot itself be deleted. Bulk actions are also available for deleting multiple settings or reassigning devices from one setting to another.

  1. Navigate to INSIGHT > Advanced Settings.

  2. Click Assign Devices next to the setting you want to assign to a device.

  3. Select devices to assign the setting to, or deselect them to remove the setting.

  4. Click Add to apply changes.

  • A device can have only one advanced setting assigned at a time.

  • Multiple devices can be assinged to an advanced setting.

  • When a new advanced setting is assigned to a device, the existing advanced setting is automatically removed and replaced.

Edit an Advanced Setting

  1. Navigate to INSIGHT > Advanced Settings.

  2. Click Edit next to the relevant setting.

  3. Update the required fields and settings. The process follows the same steps as creating a new Advanced Setting.

  4. Click Review & Save to review the changes.

  5. Click Update to confirm changes.

Delete an Advanced Setting

  1. Navigate to INSIGHT > Advanced Settings.

  2. Click Delete next to the relevant setting.

  3. Click Yes, Delete it! to confirm.

To delete settings in bulk, click the checkboxes next to the settings and select the Delete icon.

Last updated