Policy Rules Guide
Explore this glossary to discover various rules that may be incorporated into a policy.
Protected folders

Protected folders are fundamental in FenixPyre, defining specific folder locations accessible to designated users and groups. These folders allow users and groups within your organization to access and consume encrypted content using FenixPyre. Notably, encrypted files can only be accessed within these protected folders, whether via FenixPyre's Windows agent or cloud integrations. Examples of protected folder paths include common user directories, on-premises network drives, and cloud-based document sharing services.
Supported Path Types
1. Windows Local Paths
Local paths are used for protecting folders on users' Windows machines.

Syntax
Key Features
Supports
%username%variable for dynamic user pathsCase-insensitive
Backslashes (
\) required as separatorsDrive letter (e.g.,
C:) must be specified
Examples
Best Practices
Use
%username%for paths that should work across different user profilesAvoid spaces in folder names when possible
Use consistent casing for better readability
Verify the path exists before adding
2. Network Paths
Network paths allow protection of shared folders on network drives. Supports UNC, DFS, and mapped drive paths.

UNC Path Syntax
DFS Path Syntax
Key Features
Double backslashes (
\\) required at startServer/domain name must be specified
Supports both IP addresses and hostnames
Examples
Best Practices
Use UNC paths instead of mapped drives for reliability
Verify network connectivity before adding
Ensure proper network share permissions
Consider using DFS for location independence
3. SharePoint/OneDrive Paths
Cloud paths for protecting content in Microsoft 365 environments.

Syntax
Features
Automatic conversion from web URLs
Supports both SharePoint and OneDrive locations
Examples
Automatic URL to Path Conversion
Web URLs are automatically converted to the correct format. You can just paste any sharepoint/onedrive link and it will automatically be converted to the desired format:
4. Egnyte Paths
For organizations using Egnyte cloud storage.

Syntax
Examples
5. Box Paths
For organizations using Box cloud storage.

Syntax
Examples
User Permissions
The following permission decide what type of actions can be performed by the user or group on FenixPyre.
Can Encrypt
This permission determines whether a user can encrypt files
This permission determines whether a user can encrypt files
Can Decrypt
This permission determines whether a user can decrypt files and remove protection.
This permission determines whether a user can decrypt files
Can Share
This permission determines whether you can share a file via outlook or right-click option via FenixShare.
The permission determines whether you can share a file from SharePoint, OneDrive, Egnyte or Box Drive using FenixShare.
Can View Audit Logs
This permission determines whether a user can view audit logs form the right-click option
Thiis permission determines whether a user can view audit logs .
Can Open
Rolling out soon
Rolling out soon
Can Edit
Rolling out soon
Rolling out soon
Can Add Protection
Rolling out soon
Rolling out soon
Can Delete
Rolling out soon
Rolling out soon
User Applications
All admin approved and FenixPyre approved applications are displayed on the policy page. Learn how to add a new application
With FenixPyre installed on Windows Desktops, you can control which applications can access encrypted files and how they do so.

There are a number of configurations that you can manage for an application while adding them to a policy.

Allow opening multiple protected files from different protected folders
This option is crucial for managing access to multiple protected files, offering users the flexibility to work with them concurrently across various protected folders. When enabled, it empowers the application to simultaneously open and save several protected files originating from distinct protected directories.
Enable opening files from non-protected folders
This option determines whether the application can open encrypted files stored outside of protected folders.
Enable compliance mode
Read this article for more details
Endpoint Settings
Automatic Encryption Service
Automatic encryption service is a windows endpoint feature that FenixPyre offers in which it encrypts any file that has been newly added to or created within an a protected folder.
Managing Automatic Encryption Disruptions
The suggested delay is 5,000 ms. We recommend keeping the delay value below 60,000 ms (or 1 minute).
Anchor's automatic encryption service may disrupt workflows by encrypting new files in protected folders immediately. This encryption can cause application conflicts, such as interrupting an SFTP file transfer, depending on how files are created in the folder. To address these issues, we have introduced a delay setting to allow more flexible handling of such cases.
Limitations
Sequential Processing: When adding multiple files to a protected folder, the encryption service processes each file one at a time. Each file is subject to a delay, regardless of any accumulated delay.
Placeholder Files: The service does not encrypt placeholder files.
Active File Usage: Files may not be encrypted if they are in use by another application or process.
Zero-byte Files: Files with zero bytes are not encrypted.
Learn more about Automatic Encryption Service
If you are looking for a solution for encryption files on cloud - SharePoint/OneDrive, Egnyte or Box we suggest you learn about Auto-Encryption on FenixShare
Periodic Encryption Service
FenixPyre offers a Windows feature called the Periodic Encryption Service, which regularly scans protected folders and encrypts any unencrypted files. You can set the scan frequency between 30 minutes (recommended) and 1440 minutes (every 24 hours).
Recommended value: 30 mins
Limitations
Placeholder files in OneDrive or SharePoint folders will remain unencrypted.
Network shared folders are excluded from scans, except for Egnyte Connected Folders.
Learn more about Periodic Encryption Service
Automatic Decryption Service
The Automatic Decryption Service is a Windows endpoint feature that monitors a configured source directory for newly copied encrypted files, decrypts them automatically, and moves the decrypted output to a configured destination directory.
Enable auto-decryption
FALSE
Whether the auto-decryption feature is currently enabled.
Expiration window
8 hours
Hours after activation before the feature is automatically disabled.
Source directory
C:\Users\%username%\OneDrive\Desktop\encrypted
Absolute path to the folder monitored for new encrypted files.
Destination directory
C:\Users\%username%\OneDrive\Desktop\decrypted
Absolute path where decrypted files are moved.
Rescan interval
60 seconds
Periodic rescan of the source directory as a fallback to folder monitoring.
Destination retention
300 seconds
Time-to-live for decrypted files in the destination before they are removed.
Max files per window
5 files
Maximum number of files processed within the rate-limit window.
Rate limit window
5 seconds
Time window over which the rate limit is enforced.
The Automatic Decryption Service must be enabled by an administrator before it becomes active.
Learn more about Automatic Decryption Service
Offline Mode
Offline mode allows offline access to encrypted files, enabling users to work without an internet connection. Administrators can determine which users have offline access and set a time limit of up to 90 days. While an internet connection is typically needed for accessing Anchored files, offline mode balances offline functionality with maintaining control and protection of Fenixpyre encrypted files
Recommended period: 15 days
Learn more about Offline mode
Allowed Extensions
By default, any file whose extension is listed under Allowed Extensions is encrypted automatically by the Automatic Encryption Service and the Periodic Encryption Service on the FenixPyre Windows agent.
If you want to change how applications encrypt files on your system, visit User Applications.
For FenixPyre cloud integrations, encrypting, decrypting, opening, and sharing files on FenixShare is limited to these Allowed Extensions. This serves as a protective measure, ensuring only authorized users can access the encrypted files.
Clipboard Protection
Clipboard Protection monitors clipboard activity and enforces granular control over cut, copy, paste, and Paste Special actions. It distinguishes between copy and paste operations and prevents content originating from a FenixPyre encrypted file from being pasted into an unencrypted destination. When content does not originate from a FenixPyre encrypted file, users can paste it anywhere. A UI indicator is shown in the bottom-right corner of the screen when Clipboard Protection is enabled.
FenixPyre Encrypted File
Same file
Allow
FenixPyre Encrypted File
FenixPyre Encrypted File
Allow
FenixPyre Encrypted File
Unencrypted File
Deny
Unencrypted File
Any File (Encrypted/Unencrypted)
Allow
Enabling the Clipboard Protection Service also activates Screenshot Protection and Print Protection.
Learn more about Clipboard Protection
Print Protection
Print Protection prevents sensitive data from being leaked through physical or digital printing channels. It detects and blocks print, Print to PDF, and virtual printing actions for FenixPyre encrypted files.
Learn more about Print Protection
Screenshot Protection
Screenshot Protection prevents users from capturing sensitive application data through OS-level or third-party screenshot and screen-recording tools. It blacks out the application window in screen captures, detects standard snipping and screen-recording tools, and extends protection across multi-monitor setups.
Learn more about Screenshot Protection
Dynamic Watermark Display
Dynamic Watermark Display overlays traceable user information on the screen to help prevent photo-based data leaks. The watermark is transparent and moves with the application window. Administrators configure the content, style, and opacity from the policy.
Enable Watermark
FALSE
Apply a watermark when documents are encrypted.
Content
%USER_EMAIL% %DEVICE_NAME%
Watermark text to display on the encrypted file window when opened.
Style
Font Style β Normal
Font Style β Bold / Italic / Normal. Font Size β 0 to 100 pt.
Opacity
40%
0 to 100 %.
You can use these values in the watermark text: %USER_EMAIL% for the current user's email, %DEVICE_NAME% for the current device name, and %IP_ADDRESS% for the current device's IP address.
Learn more about Dynamic Watermark Display
File Settings
Preserve File Timestamps
By default, FenixPyre preserves original file timestamps when encrypting or decrypting. This means the "last modified date," "last access date," and "last write date" stay the same even after files are processed. If you want these timestamps to reflect the time of encryption or decryption instead, you can change this default behavior.
Recommended Value: Enabled
Preserve File Security Info
You can keep a fileβs security details, like its Discretionary Access Control List (DACL), even after encrypting or decrypting. A DACL controls who can access files and folders in a computer system.
Recommended Value: Enabled
File Access Rules
Access Rules define the conditions that must be met before encrypted data can be opened. They are automatically applied to new and existing files, which makes managing access controls much easier.

Default Rule (Organization): The device must belong to the data-owning organization. All files are given this global default rule upon encryption.
IP Address: Limit access to selected public IP ranges (supports multiple IPs and CIDR notation).
Geo-Fencing: Currently only supports the US, so files can only be opened if accessed from within the United States. This is verified using geolocation, IP addresses, or both.
Office Add In Settings
The FenixPyre Office Add-In offers various settings that help Data Loss Prevention (DLP) in Office 365. These settings disable any features that could compromise data security, ensuring your sensitive information remains protected.
Can Lock Files
FenixPyre automatically handles file locking for Office files synced from OneDrive or SharePoint. It ensures encrypted files are edited by only one user or device at a time, preventing conflicts and maintaining data security.
enabled
Can Share
Enable or Disable Share Options in Microsoft Office
disabled
Can View Info
Enable or Disable View Info Option in Microsoft Office
disabled
Can Transform
Enable or Disable Transform Option in Microsoft Office
disabled
Can Export
Enable or Disable Export Option in Microsoft Office
disabled
Can Publish
Enable or Disable Publish Option in Microsoft Office
disabled
Can Print
Enable or Disable Print Option in Microsoft Office
disabled
Can Custom Preview
Enable or Disable Custom Preview Option in Microsoft Office
disabled
Can Save to Non-Protected Folders
This setting controls the ability to save files to non-protected folders. It overrides similar setting in User applications, including Microsoft Word, Excel, and PowerPoint.
disabled
Advanced Settings
User Policy Update Interval
The Windows agent updates user policies at regular intervals. By default, these updates occur every 60 seconds.
60 seconds
Access Control Heartbeat Interval
Frequency at which FenixPyre verifies user status and ensures compliance with file access rules.
15 seconds
Last updated
Was this helpful?
