> For the complete documentation index, see [llms.txt](https://docs.guardware.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.guardware.com/insight/policies/advanced-settings.md).

# Advanced Settings

Advanced Settings define the global monitoring parameters applied across audit reports and device policies in GuardWare INSIGHT. They function as the central control point for how monitoring is configured and enforced across the organisation.

These settings determine how INSIGHT operates on end-user devices, including the methods used to monitor the movement of sensitive data, the applications, URLs, and file extensions that are included or excluded from monitoring, and the configuration of communication between devices and the server.

## Reference Table

The table below provides an overview of every Advanced Setting and what it does.

<table><thead><tr><th width="244">Section</th><th>What It Does</th></tr></thead><tbody><tr><td><a href="#environment-settings"><strong>Environment Settings</strong></a></td><td>Controls the intervals, durations, timeouts, and bandwidth settings for uploading reports and downloading policies and commands.</td></tr><tr><td><a href="#applications-monitored-at-network-level"><strong>Applications Monitored at Network Level</strong></a></td><td>Lists applications monitored for sensitive data uploads at the network level.</td></tr><tr><td><a href="#ip-addresses-not-monitored-at-network-level"><strong>IP Addresses Not Monitored at Network Level</strong></a></td><td>Lists IP addresses excluded from network-level monitoring.</td></tr><tr><td><a href="#websites-with-monitored-ssl-traffic"><strong>Websites Not Monitored</strong></a></td><td>Lists websites which do not have their SSL traffic monitored.</td></tr><tr><td><a href="#applications-monitored-at-file-system-level"><strong>Applications Monitored at File System Level</strong></a></td><td>Lists applications monitored for sensitive data uploads at the file system level.</td></tr><tr><td><a href="#applications-with-monitored-keystrokes-and-copy-paste"><strong>Applications Excluded from Keystrokes and Copy/Paste</strong></a><a href="#applications-with-monitored-keystrokes-and-copy-paste"><strong>Monitor</strong> </a></td><td>Specifies applications where keystroke and copy/paste monitoring is excluded.</td></tr><tr><td><a href="#websites-with-monitored-keystrokes-and-copy-paste"><strong>Websites Excluded from Keystrokes and Copy/Paste Monitoring</strong></a></td><td>Specifies websites where keystroke and copy/paste activity is monitored or excluded.</td></tr><tr><td><a href="#file-extensions-monitored-at-file-system-level"><strong>File Extensions Monitored at File System Level</strong></a></td><td>Filters file upload monitoring by file extension type.</td></tr><tr><td><a href="#websites-with-end-to-end-encryption"><strong>Websites with End-to-End Encryption</strong></a></td><td>Lists websites with end-to-end encryption where file system monitoring is required alongside network monitoring.</td></tr></tbody></table>

## Create an Advanced Setting

Before configuring any monitoring parameters, an Advanced Setting policy must be created first. Once created, it starts in an Inactive state and needs to be configured before being activated and applied to devices.

<figure><img src="/files/A5D103xvTes4h1FtazAa" alt=""><figcaption></figcaption></figure>

1. Navigate to **INSIGHT** > **Advanced Settings**.
2. Click **+ New Advanced Setting**.

{% stepper %}
{% step %}

### Configure Policy Info

3. In the **Policy Info** tab, fill in the following fields and click **Next**:<br>

   <figure><img src="/files/xmSB8uzjcg2G2onLQela" alt="" width="563"><figcaption></figcaption></figure>

   1. **Copy Settings From (Optional):** Select an existing Advanced Setting to copy its configuration into this new one. Useful for duplicating a baseline policy instead of starting from scratch.
   2. **Setting Name:** Enter a clear, identifiable name for the setting.
   3. **Description:** Briefly describe what this setting is for, who it applies to, or how it differs from other settings.
   4. **Set as Default Setting (Optional):** Marks this as the organisation-wide default. Only one default setting can be active at a time; it is automatically assigned to all newly created users and can be duplicated to create policy variations from a common baseline.
      {% endstep %}

{% step %}

### Configure Settings

Once created, the **Advanced Setting** starts in an **Inactive** state. Configure the required settings, then activate when ready to apply to devices. Each setting can be enabled or disabled. Disabling a setting reverts it to its default state, disabling the associated functionality.

<figure><img src="/files/2f9RvuLlRfGmq1XMcnBe" alt=""><figcaption></figcaption></figure>

<details open>

<summary><strong>Environment Settings</strong></summary>

Controls the intervals, durations, timeouts, and bandwidth settings for uploading reports and downloading policies and commands.

<table><thead><tr><th width="116">Setting</th><th width="100">Default</th><th width="190">Description</th><th>When to Change</th></tr></thead><tbody><tr><td><strong>Client Responsiveness</strong></td><td>Normal Operation</td><td>Determines how frequently agents download commands and settings and upload reports. Very Responsive, Responsive, and Normal Operation correspond to intervals of 1 minute, 5 minutes, and 15 minutes respectively.</td><td>Increase responsiveness if near-real-time policy enforcement is required. Be aware that shorter intervals increase network and system overhead.</td></tr><tr><td><strong>Browser Monitoring Using Chromium Extensions</strong></td><td>Disabled</td><td>An alternative approach to monitoring browsers at the network level.</td><td>Enable if network-level browser monitoring is insufficient or unavailable in the environment.</td></tr><tr><td><strong>File System Level Monitoring</strong></td><td>Enabled</td><td>Uses a file system level driver to monitor uploads through changes in the network information associated with files.</td><td>Disable if file system-level monitoring is not required or conflicts with existing endpoint software.</td></tr><tr><td><strong>Passive Monitoring of File Uploads to Cloud Drives</strong></td><td>Disabled</td><td>An alternative approach to monitoring file uploads to cloud drives at the file system level.</td><td>Enable if file system-level monitoring does not adequately capture cloud drive upload activity.</td></tr><tr><td><strong>Network Level Monitoring</strong></td><td>WFP</td><td>WFP and LSP are Windows networking technologies used to inspect network traffic.</td><td>Switch to LSP if WFP is incompatible with the environment or conflicts with other network drivers.</td></tr><tr><td><strong>USB Monitoring</strong></td><td>Enabled</td><td>Monitors insertions of, and file transfers to, USB devices.</td><td>Disable only if USB monitoring is managed by a separate solution or is not required in the environment.</td></tr><tr><td><strong>GuardWare File Protection</strong></td><td>Enabled</td><td>Prevents end users from editing or deleting files within the GuardWare Program Files and Program Data folders.</td><td>Disable temporarily for maintenance or troubleshooting only.</td></tr><tr><td><strong>GuardWare Process Protection</strong></td><td>Enabled</td><td>Prevents end users from terminating the main GuardWare processes.</td><td>Disable temporarily for maintenance or troubleshooting only.</td></tr></tbody></table>

</details>

<details>

<summary><strong>Applications Monitored at Network Level</strong></summary>

List of applications that are monitored for sensitive data uploads at the network level. The proxy can only monitor applications that are explicitly on this list. If an application is not selected, its traffic will not be captured.

<figure><img src="/files/9CUeqTwaFYJgeP0ktEZZ" alt=""><figcaption></figcaption></figure>

1. Click **View Settings** to open the configuration window.
2. A default set of applications is preselected for monitoring. To add more, use the search field to find the application and select the checkbox next to it.
3. If the application does not appear in the list, enter the executable name (e.g., `chrome.exe`) in the **Add Application** field and click **Add Application**.
4. Once added, select the checkbox next to it to include it in monitoring.

</details>

<details>

<summary><strong>IP Addresses Not Monitored at Network Level</strong></summary>

List of IP addresses that are not monitored for sensitive data. The list shows excluded IP addresses used by internal applications that are considered secure and do not need monitoring for the uploading of sensitive data.

<figure><img src="/files/CT5ly9YaPj18djj3jBv0" alt=""><figcaption></figcaption></figure>

1. Click **View Setting** to open the configuration window.
2. Enter the IP address in the **Add IP** field and click **Add IP.**
3. Confirm the IP address appears in the list and close the window

</details>

<details>

<summary><strong>Websites Not Monitored</strong></summary>

List of websites whose SSL traffic is monitored for sensitive data uploads. To monitor SSL traffic for specific websites only, select or add their URLs to the list.

<figure><img src="/files/c5pTaNchPtbsfTLKfZ5e" alt="" width="522"><figcaption></figcaption></figure>

1. Click **View Setting** to open the configuration window.
2. Search for the desired websites and select them to add them to the not monitoring list.
3. If your desired website is not on the list, enter the website URL (e.g., `google.com`) and click **Add Website.**&#x20;
4. Confirm the website appears in the list, and select it to add it to the not monitoring list.

</details>

<details>

<summary><strong>Applications Excluded from Keystroke and Copy/Paste Monitoring</strong></summary>

List of applications where keystrokes and copy/paste activity are not monitored for sensitive data. This is particularly useful for restricting monitoring in sensitive applications such as password managers or tools that handle confidential input.

<figure><img src="/files/NWtw4C8dUPbkeOjg5kzH" alt="" width="522"><figcaption></figcaption></figure>

1. Click **View Setting** to open the configuration window.
2. Select the checkboxes next to the applications to add them to the exclusion list.

</details>

<details>

<summary><strong>Websites Excluded from Keystroke and Copy/Paste Monitoring</strong></summary>

List of websites where keystrokes and copy/paste activity are monitored, or not monitored, for sensitive data. This list is usually used to exclude banking or similar websites where users may type personal passwords.

<figure><img src="/files/aXiPNuU5Cvv4GpNb8mHK" alt="" width="522"><figcaption></figcaption></figure>

1. Click **View Setting** to open the configuration window.
2. Select the websites to exclude from keystroke and copy/paste monitoring.
3. If the website is not on the list, add the website using the full URL and click **Add Website**.

</details>

<details>

<summary><strong>File Extensions Not Monitored at File System Level</strong></summary>

A list of file extensions excluded from file system-level sensitive data upload monitoring. Use this to add extensions to the exclusion list and focus monitoring on high-risk file types only.

<figure><img src="/files/6lt2hTvJkh1MXZ4UMZXk" alt="" width="523"><figcaption></figcaption></figure>

1. Click **View Setting** to open the configuration window.
2. Enter the file extension in the **Add Extension** field (e.g., `pdf`, `xlsx`, `zip`) and click **Add**.
3. Confirm the extension appears in the list.

</details>

<details>

<summary><strong>Applications Monitored at File System Level</strong></summary>

List of applications that are monitored for sensitive data uploads at the file system level.

<figure><img src="/files/IrxvU9Y3wyHhLjdDBTgJ" alt=""><figcaption></figcaption></figure>

1. Click **View Settings** to open the configuration window.
2. A default set of applications is preselected for monitoring. To add more, select the checkbox next to the application in the list.
3. If the application does not appear in the list, enter the executable name (e.g., `chrome.exe`) in the **Add Application** field and click **Add Application**.
4. Once added, select the checkbox next to it to include it in monitoring.

</details>

<details>

<summary><strong>Websites with End-to-End Encryption</strong></summary>

List of websites with end-to-end encryption monitoring. For websites implementing end-to-end encryption, it is not possible to intercept file uploads using network monitoring alone.

Where end-to-end encrypted websites are permitted, and there is a concern that files containing sensitive data may be uploaded, both file system monitoring (file paths and contents) and network monitoring (destinations) are required in order to produce reports containing URL and file path information for the uploaded sensitive data.

<figure><img src="/files/lpgROjeiwo1T0ZDzQJMR" alt=""><figcaption></figcaption></figure>

1. Click **View Settings** to open the configuration window.
2. A default set of websites is preselected. To add more, enter the website in the input field using the format `URL#Title_Substring` (e.g., `whatsapp.com#whatsapp`) and click **Add**.
3. To remove a website, click **X** next to the entry.
4. Close the window.

</details>
{% endstep %}

{% step %}

### Review & Save

1. Scroll to the top of the page and click **Review & Save**. A summary of all configured settings will appear in the side panel.

   <figure><img src="/files/BkJhD41kYfzbto7csAEg" alt="" width="563"><figcaption></figcaption></figure>
2. Review the configurations. To make any changes, close the panel, update the relevant settings, and click **Review & Save** again.

   <figure><img src="/files/O3oqDQH8qVG4DV880rP0" alt="" width="563"><figcaption></figcaption></figure>
3. Once satisfied, click **Save** to apply the configuration.
   {% endstep %}
   {% endstepper %}

## Assign Advanced Settings to Devices

After creating an Advanced Setting, it can be assigned to devices, edited, or deleted from the Advanced Settings list. Devices assigned to a deleted setting automatically revert to the default setting, which cannot itself be deleted. Bulk actions are also available for deleting multiple settings or reassigning devices from one setting to another.

1. Navigate to **INSIGHT** > **Advanced Settings.**
2. Click **Assign Devices** next to the setting you want to assign to a device.

   <figure><img src="/files/hdlwJwfo0n2QgYdNJIlm" alt="" width="563"><figcaption></figcaption></figure>
3. Select devices to assign the setting to, or deselect them to remove the setting.
4. Click **Add** to apply changes.

{% hint style="info" %}

* A device can have only one advanced setting assigned at a time.
* Multiple devices can be assinged to an advanced setting.
* When a new advanced setting is assigned to a device, the existing advanced setting is automatically removed and replaced.
  {% endhint %}

## Edit an Advanced Setting

1. Navigate to **INSIGHT** > **Advanced Settings.**
2. Click **Edit** next to the relevant setting.<br>

   <figure><img src="/files/sXfv2XUFD7zMlEqv6bF0" alt="" width="563"><figcaption></figcaption></figure>
3. Update the required fields and settings. The process follows the same steps as [creating a new Advanced Setting](#create-an-advanced-setting).
4. Click **Review & Save** to review the changes.
5. Click **Update** to confirm changes.

## Delete an Advanced Setting

1. Navigate to **INSIGHT** > **Advanced Settings**.
2. Click **Delete** next to the relevant setting.<br>

   <figure><img src="/files/OsEAGjs7InKcFocTEZfE" alt="" width="563"><figcaption></figcaption></figure>
3. Click **Yes, Delete it!** to confirm.

{% hint style="info" %}
To delete settings in bulk, click the checkboxes next to the settings and select the **Delete** <i class="fa-trash-can">:trash-can:</i> **icon**.
{% endhint %}


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.guardware.com/insight/policies/advanced-settings.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
