I finally found a command to enable the DLP. sudo mdatp config
data-loss-prevention --value enabled Create an extension attribute that
returns the value of dlp status, create a smart group for anything but
active and then scope this command to this g...