Sign In with your
Trend Micro Account
Need Help?
Need More Help?

Create a technical support case if you need further support.

Cloud App Security Data Collection Notice

    • Updated:
    • 22 May 2018
    • Product/Version:
    • Platform:
    • N/A N/A
Summary

The section below outlines the following Cloud App Security features that collect data, the data transmitted, and their location on the product console where you can disable the features:

Details
Public

O365 (Exchange Online, SharePoint Online, OneDrive for Business) Provisioning

Cloud App Security provisions service accounts to integrate with Microsoft Office 365 services, and accesses Office 365 data with the service accounts to protect users’ email messages and files from network threats.

 
Data will be automatically cleaned up one month after the grace period of your license expires. After data is cleared, Cloud App Security does not protect your service any more.
Data collected
  • Domain, user, and group information in Windows Azure Active Directory
  • Exchange Online mailbox information
  • SharePoint Online site collection information
  • OneDrive for Business user and user site information
Console Settings

Provision:

  • Administration > Service Account > Add > Office 365

Service Account

 
When your license for Cloud App Security is valid, contact Trend Micro Technical Support to submit a request for de-provisioning. After de-provisioning is completed, data is cleaned up.

Back to top

Cloud storage service (Box, Dropbox, Google Drive) Provisioning

Cloud App Security provisions service accounts to integrate with cloud storage services and obtains access tokens to protect users’ files from network threats.

 
Data will be automatically cleaned up one month after the grace period of your license expires. After data is cleared, Cloud App Security does not protect your service any more.
Data collected
  • Box user and group information
  • Dropbox user and group information
  • Google Drive user and organization unit information
Console settings

Provision:

  • Administration > Service Account > Add > Box/Dropbox/Google Drive

Service Account

De-provision:

  • Administration > Service Account > Remove

Back to top

Logs

Logs cannot be disabled unless you choose to NOT use Cloud App Security.

 
After data is cleared, administrators cannot retrieve history data of user events and policy violations from Cloud App Security.
Data collected
  • Email senders
  • Email recipients
  • Email locations
  • Email subjects
  • Attachment names
  • File modifiers
  • File locations
  • File names
Console settings

Cloud App Security automatically deletes logs older than 90 days.

Automatically delete logs older than 90 days

Back to top

Quarantine

Quarantine logs cannot be disabled unless you do not set Action to Quarantine in any Advanced Threat Protection or Data Loss Prevention policy or you do not enable Virtual Analyzer in any Advanced Threat Protection policy.

 

Data will be automatically cleaned up one month after the grace period of your license expires.

After data is cleared, administrators cannot retrieve history data of user events and policy violations from Cloud App Security.

Data collected
  • Email senders
  • Email recipients
  • Email locations
  • Email subjects
  • Attachment names
  • File modifiers
  • File locations
  • File names
Console settings

For Quarantine logs, Cloud App Security provides an option for administrators to choose to automatically delete them older than 30, 60, or 90 days.

Quarantined logs

Back to top

Predictive Machine Learning

Trend Micro Predictive Machine Learning uses advanced machine learning technology to correlate threat information and perform in-depth file analysis to detect emerging unknown security risks through digital DNA fingerprinting, API mapping, and other file features.

 
Disabling Predictive Machine Learning prevents the mentioned data from being sent to Trend Micro, but severely affects the ability of Cloud App Security to detect new, previously unidentified, or unknown threats.
Predictive Machine Learning
Data collected
  • Metadata of suspicious executable files and scripts in cloud storage services
  • Metadata of suspicious executable files and scripts in email attachments
Console locationATP policy > Malware Scanning > Rules
Console settings
  • Enable Predictive Machine Learning

    Enable Predictive Machine Learning

Back to top

Predictive Machine Learning Feedback

Predictive Machine Learning feedback enables you to participate, share and leverage Trend Micro’s global database of threat related intelligence to rapidly identify and defend against potential threats within your unique network environment.

 
Disabling Predictive Machine Learning feedback prevents the mentioned data from being sent to Trend Micro, but affects the enhancement of Cloud App Security to rapidly identify and address new threats.
Predictive Machine Learning Feedback
Data collected
  • Suspicious executable files and scripts in cloud storage services
  • Suspicious executable files and scripts in email attachments
Console locationATP policy > Malware Scanning > Rules > Predictive Machine Learning
Console settings
  • Allow Trend Micro to collect suspicious files to improve its detection capabilities

Predictive Machine Learning Feedback

Back to top

Virtual Analyzer for files

Virtual Analyzer is a cloud sandbox designed for analyzing suspicious files. Sandbox images allow observation of file behavior in an environment that simulates endpoints on your network without any risk of compromising the network.

 
Disabling Virtual Analyzer prevents the mentioned data from being sent to Trend Micro, but severely affects the ability of Cloud App Security to detect advanced malware in files.
Data collected
  • Suspicious executable files
  • Suspicious scripts
  • Suspicious documents with macro
  • Other suspicious files from Trend Micro virus scan engine
Console locationATP policy > Virtual Analyzer
Console settings
  • Enable Virtual Analyzer
  • Files

Virtual Analyzer

Back to top

Advanced Spam Protection

Cloud App Security uses Trend Micro Antispam Engine to provide advanced spam protection, as a complement to the email protection service on your email gateway side, to further protect Exchange Online users from BEC, ransomware, advanced phishing, and other high-profile attacks.

 
Disabling Advanced Spam Protection prevents the mentioned data from being sent to Trend Micro, but severely affects the ability of Cloud App Security to detect BEC, phishing, ransomware, and other spam.
Advanced Spam Protection
Data collected
  • IP addresses of upstream MTAs
Console locationATP policy > Advanced Spam Protection
Console settings
  • Enable Advanced Spam Protection

Enable Advanced Spam Protection

Back to top

Advanced Spam Protection Feedback

Advanced Spam Protection feedback enables you to participate, share and leverage Trend Micro’s global database of threat related intelligence to rapidly identify and defend against potential threats within your unique network environment.

 
Disabling Advanced Spam Protection feedback prevents the mentioned data from being sent to Trend Micro, but affects the enhancement of Cloud App Security to rapidly identify and address new spam.
Advanced Spam Protection Feedback
Data collected
  • Email addresses
  • Email subjects
  • URLs in email body
Console locationATP policy > Advanced Spam Protection
Console settings
  • Allow Trend Micro to collect suspicious email information to improve its detection capabilities

Advanced Spam Protection Feedback

Back to top

Web Reputation

Cloud App Security leverages Trend Micro Web Reputation Services to scan URLs contained in files, email bodies and attachments to detect malicious URLs based on their reputation scores.

 
Disabling Web Reputation prevents the mentioned data from being sent to Trend Micro, but severely affects the ability of Cloud App Security to detect malicious URLs.
Data collected
  • URLs in email body
  • URLs in email attachments
  • URLs in files
Console locationATP policy > Web Reputation
Console settings
  • Enable Web Reputation

Enable Web Reputation

Back to top

Premium
Internal
Rating:
Category:
SPEC
Solution Id:
1119582
Feedback
Did this article help you?

Thank you for your feedback!

To help us improve the quality of this article, please leave your email here so we can clarify further your feedback, if neccessary:
We will not send you spam or share your email address.

*This form is automated system. General questions, technical, sales, and product-related issues submitted through this form will not be answered.

If you need additional help, you may try to contact the support team. Contact Support

To help us improve the quality of this article, please leave your email here so we can clarify further your feedback, if neccessary:
We will not send you spam or share your email address.

*This form is automated system. General questions, technical, sales, and product-related issues submitted through this form will not be answered.