FortiDLP
FortiDLP is a cloud-native endpoint DLP and Insider Risk Solution which is aimed at monitoring and Preventing Data Theft on the endpoint, across Windows, macOS and Linux.
Anthony_E
Community Manager
Community Manager
Article Id 353689
Description This article describes how to suppress the Outlook add-on installer dialog.
Scope FortiDLP.
Solution

Agent v7.0.0 and later includes a mail plugin for Microsoft Outlook. Some users have observed that after an installation or upgrade to v7.0.0 (or later), the first time they open Outlook they are prompted with a dialog to Install the Reveal Agent Outlook plugin.

 

For example:

 

Anthony_E_0-1730197957390.png


To avoid this message on each machine, it is necessary to add the Ava Security Limited code signing certificate as a Trusted Publisher.

 

Method 1: Group Policy Objects (GPO).

  1. Copy the ava-codesign.pem file (below) to a known location on the domain controller.
  2. Open an appropriate Group Policy and navigate to Computer Configuration -> Policies -> Windows Settings -> Security Settings > Public Key Policies -> Trusted Publishers:

    Anthony_E_1-1730197957401.png

  3. Under Trusted Publishers, select Import, using the ava-codesign.pem file from step 1.
  4. The certificate should be pushed to each machine at the next Group Policy update interval (usually a maximum of 90 minutes, or after a restart).

 

Note 

ava-codesign.pem can only be used to verify agent v7.10.1 (or later).  To verify agent versions older than v7.10.1 as well, repeat steps 1-4 with jazz-codesign.pem.

 

Method 2: Microsoft Endpoint Manager.

  1. Sign in to the Microsoft Endpoint Manager admin center.
  2. Select Devices -> Configuration profiles -> Create profile.
  3. Enter the following properties:
    1. PlatformWindows 10 and later.
    2. TemplatesCustom.
  4. Select Create.
  5. Use the following values for the fields in the custom profile:
    1. Name: Ava Code signing (16/11/2021 - 15/11/2024).
    2. Description: (Optional).
    3. OMA-URI: ./Device/Vendor/MSFT/RootCATrustedCertificates/TrustedPublisher/8a54e969b497487ad68ba516e2409223d972d9c3/EncodedCertificate
    4. Data type: String.
    5. Value: Paste the contents of ava-codesign-base64-endcoded.txt (below) into the Value field (the text file represents the certificate in base 64 encoded form).

 

Anthony_E_2-1730197957410.png

 

 

  1. Select Save.
  2. Add scopes and assignments as necessary.

 

Note:

The steps above can only be used to verify agent v7.10.1 (or later). To verify agent versions older than v7.10.1 as well, repeat steps 1-5, but replace:

  • Step 5(a) with Name: Jazz Code signing (26/11/2019 - 20/12/2021).
  • Step 5(c) with OMA-URI: ./Device/Vendor/MSFT/RootCATrustedCertificates/TrustedPublisher/b5948902107bfe8a930df1740e747101da8dab15/EncodedCertificate
  • Step 5(e) with Value: Paste the contents of jazz-codesign-base64-endcoded.txt (below) into the Value field (the text file represents the former certificate in base 64 encoded form).


Anthony_E_3-1730197957418.png

Contributors