---
version: "2.4"
language: "en"
---
# HaloCAD Add-on for Autodesk AutoCAD

## HaloCAD Add-on for Autodesk AutoCAD

This page provides a complete collection of HaloCAD Add-on for Autodesk AutoCAD documentation.

### Documentation

*

  #### [Technical Reference Manual](https://help.secude.com/halocad-add-on-for-autodesk-autocad/2.4/technical-reference-manual.md)

#### [Installation Manual](https://help.secude.com/halocad-add-on-for-autodesk-autocad/2.4/ac-installation-manual.md)

*

  #### [Operations Manual](https://help.secude.com/halocad-add-on-for-autodesk-autocad/2.4/ac-operations-manual.md)

*

  #### [Release Notes](https://help.secude.com/halocad-add-on-for-autodesk-autocad/2.4/ac-release-notes.md)

---
version: "2.4"
language: "en"
---
# Appendix

This section provides supplemental information.  
**Installer Version Requirement**

When uninstalling the HaloCAD add-on, use the installer for the currently installed version, whether you run it by double-clicking the installer or from the command line. Using a different installer version may result in errors.

## Uninstalling the HaloCAD Add-on for AutoCAD

When you no longer use the add-on, you may uninstall the application. Uninstalling removes all files and registry settings that were added to your computer during the initial installation.

**Method #1**

1. Click **Start** menu \> go to **Control Panel** \> **Programs** \>**Programs and Features** \> **Uninstall a Program** \>select**HaloCAD Add-on for AutoCAD** application from the list \> right-click and select **Uninstall** option or double-click on the installer `HaloCAD_AutoCAD_Setup.exe` file.

2. Depending on your Windows security settings, you may get a security warning as "*Do you want to allow the following program to make changes to this computer* ?". If you get this security warning, click the **Yes** button to confirm that you want to uninstall the add-on.

3. The HaloCAD installer checks the current user session for any supported CAD applications running in the background and, if any are detected, displays the following message prompting you to close them before continuing with the uninstallation.

   ![Uninstall message #1.png](https://help.secude.com/__attachments/a_34b65022196f87a72c72aff38b7088d69929f88dc4bbdc9431de9aa6f28c5152/Uninstall%20message%20%231.png?cb=86e626f22e066eb11d7c2ab64cb7609a)

   *Uninstall message #1*
4. Click **OK** and close all HaloCAD-supported CAD applications.

5. Redo [step 1](https://help.secude.com/halocad-add-on-for-autodesk-autocad/2.4/ac-appendix.md#Step1), and the following confirmation message appears.

   ![Uninstall message #2.png](https://help.secude.com/__attachments/a_0aab1edcb250898b9d5fcb7a4dfa70d5ed1eff087fa8708202eb25a59f5d0c64/Uninstall%20message%20%232.png?cb=4e9c13c2f6f790a3676199eb9ac93a07)

   *Uninstall Message #2*
6. Click **Yes** to confirm the uninstallation of HaloCAD from your computer.

7. When prompted with the following message, click **Yes** to delete the identity of the currently logged-in user from the ongoing session(`%AppData%\Roaming\Secude\HaloCAD\acad`), or **No**to proceed with the uninstallation without removing the identity. This prompt does not appear if no HaloCAD session has been initiated.

   ![Uninstall message #3.png](https://help.secude.com/__attachments/a_96130a595619a6e991534b4829d3df1fd33c8a658af31cdf9e4016c122e0e895/Uninstall%20message%20%233.png?cb=f055f4599cb793644bad67d174aeaf48)

   *Uninstall message #3*
8. The HaloCAD add-on has been successfully uninstalled. Click **OK**to close the dialog box.

   ![Uninstall message #4.png](https://help.secude.com/__attachments/a_c61f1f69aa33be7eabc0e91267694d29c93a6890d824d228ad9e278e761a94fe/Uninstall%20message%20%234.png?cb=f4dab7e5df1c1b1009a3e834dfc5adea)

   *Uninstall message #4*

**Method #2**

The add-on can be removed using the command line, as illustrated in the sample below.

1. Open a command prompt.

2. Navigate to the add-on installer's directory.

   1. **Option 1** : uninstall without deleting the identity of the currently logged-in user`HaloCAD_AutoCAD_Setup.exe -uninstall`

   2. **Option 2** : uninstall deleting the identity of the currently logged-in user`HaloCAD_AutoCAD_Setup.exe -uninstall -clearcache <yes>`

3. The uninstalling process is complete.

## Uninstalling the HaloCAD Reader Add-on for AutoCAD

The process of uninstalling the reader add-on is similar to that of the full version.

**Method #1**

1. Click **Start** menu \> go to **Control Panel** \> **Programs** \>**Programs and Features** \> **Uninstall a Program** \>select**HaloCAD Reader Add-on for AutoCAD** application from the list \> right-click and select **Uninstall** optionor double-click on the installer `HaloCAD_Reader_AutoCAD_Setup.exe` file.

2. The uninstallation process for the Reader version is similar to that of the Full version; refer to the above section and follow the on-screen instructions to complete the process.

**Method #2**

The add-on can be removed using the command line, as illustrated in the sample below.

1. Open a command prompt.

2. Navigate to the add-on installer's directory.

   1. **Option 1** : uninstall without deleting the identity of the currently logged-in user `HaloCAD_Reader_AutoCAD_Setup.exe -uninstall`

   2. **Option 2** : uninstall deleting the identity of the currently logged-in user `HaloCAD_Reader_AutoCAD_Setup.exe -uninstall -clearcache <yes>`

3. The uninstalling process is complete.

---
version: "2.4"
language: "en"
---
# Installation Manual

## About this Manual

This manual walks you through the process of installing and configuring the following HaloCAD add-ons:

1. HaloCAD Add-on for AutoCAD

2. HaloCAD Reader Add-on for AutoCAD

**Reference**

All technical manuals are included with the product package you have purchased.

Administrators should first read the Technical Reference Manual to understand the add-on's architecture, learn about the prerequisites, and activate a license key. They should also refer to the Release Notes to learn about the supported CAD applications before following the instructions in this document.

---
version: "2.4"
language: "en"
---
# Installing the HaloCAD Add-on for AutoCAD

This chapter describes how to install and configure the HaloCAD Add-on for AutoCAD. This manual just briefly explains steps 1-3, which cover the prerequisites, obtaining the licensing key, and creating an encrypted JSON file; for more information, please refer to the Technical Reference Manual.

## Step 1: Fulfill the Prerequisites

1. Refer to the Release Notes to learn about supported operating systems, file types, and CAD applications.

2. Before installing the add-on, make sure all prerequisites are fulfilled.

Please refer to the section "[Prerequisites](https://help.secude.com/halocad-add-on-for-autodesk-autocad/2.4/technical-reference-manual.md#pre)".

## Step 2: Obtain the License Key

Obtain the license key and choose whether to activate it automatically or manually.

Please refer to the section "[License Administration](https://help.secude.com/halocad-add-on-for-autodesk-autocad/2.4/technical-reference-manual.md#lic)".

## Step 3: Create an Encrypted JSON File

To ensure a secure installation, create an encrypted JSON file using this admin tool and share it without exposing the original tenant details. When the encrypted JSON file is ready, place it with the HaloCAD installer. By reading data from the `hc.conf.enc` file, the installer activates the license and bypasses the "[Initialization](https://help.secude.com/halocad-add-on-for-autodesk-autocad/2.4/ac-installing-the-halocad-add-on-for-autocad.md#Initialization)" screen, which would otherwise ask for Microsoft Entra ID application details.

Please refer to the section "[Secure Installation (Recommended)](https://help.secude.com/halocad-add-on-for-autodesk-autocad/2.4/technical-reference-manual.md#secure)".

## Step 4: Install the Add-on

You can install the add-on in the following modes:

1. **Graphical Mode**

   Graphical mode installation is an interactive, graphical user interface-based method that is driven by a wizard.

2. **Silent Mode**

   Silent-mode installation is a non-interactive method of installing the add-on using command lines.

3. **Via System Center Configuration Manager**

   With System Center Configuration Manager (SCCM), the add-on is deployed on the targeted computers across your enterprise.

### **Graphical Mode**

**Before you begin**

The following prerequisites must be met:

1. A user who installs the HaloCAD Add-on must have administrator rights.

2. Ensure that all active and open CAD applications are closed. If not, HaloCAD prompts a warning message as "*Please close all the CAD applications to proceed with the installation of HaloCAD Add-on for AutoCAD.*"

3. Ensure that the HaloCAD Reader Add-on for AutoCAD is not installed on the same workstation. If it is already installed, HaloCAD prompts a warning message as "*No supported CAD applications are available in the system. (OR) Remove the Reader version of this product.*"

4. Ensure that your Microsoft Entra tenant details are ready when the installation UI requests them. As an alternative, you can use `hc.conf.enc` for a secure and automated installation.

**Installation Procedure**

Install the add-on using the GUI-based setup program provided in the installation package.

1. Double-click the installer `HaloCAD_AutoCAD_Setup.exe` file.

2. Depending on your Windows security settings, a prompt may appear stating, *"Do you want to allow the following program to make changes to this computer?"* If this warning appears, click **Yes** to continue with the installation.

3. When the installer starts, the **Startup** dialog appears, followed by the **Welcome** dialog.

   ![Startup dialog.png](https://help.secude.com/__attachments/a_391d251445329e9e770d6cd2cc505d3640469590314bf42314a9e58dc29bd95d/Startup%20dialog.png?cb=580c6c61db482e307c918bae08132f9a)

   *Startup dialog*  
   ![1 Welcome Dialog.jpg](https://help.secude.com/__attachments/a_ffb37ac3021d626edd51643980e4d7c321daf072b92159039f5ee32e49d261b8/1%20Welcome%20Dialog.jpg?cb=cd49b6b05a130563e8b8d2f4f756028d)

   *Welcome dialog*
4. Click **Next** to continue the installation. The installer UI includes a link to the product's online documentation. When you click **Online Help**, the installation help page opens in your browser.

5. The **End-User License Agreement (EULA)** dialog appears.

   ![2 End-User License Agreement dialog.jpg](https://help.secude.com/__attachments/a_b0967eecdbb8842666cfc6ffac8d660d8517be04fc7ec795f03665c3d0f2ae7d/2%20End-User%20License%20Agreement%20dialog.jpg?cb=678b77d5fc9d1f60466c85c4a20f9fc4)

   *End-User License Agreement dialog*
6. Read the End-User License Agreement. If you agree to the terms, select **I accept the terms in the License Agreement** and click **Next** to continue.

7. The CAD application version selection dialog appears.

   ![3 CAD Application Selection dialog.png](https://help.secude.com/__attachments/a_25a83874c8d797a94608c28a5ee788af5988475d440f09df90509570d72e40cd/3%20CAD%20Application%20Selection%20dialog.png?cb=b74f5f8671a279a55b18855e4fb019d1)

   *CAD application version selection dialog*
   1. Select the installed **AutoCAD** application version in your system.

   2. Click **Next** . To review or modify installation settings (if needed), click **Back**to return to the previous screens.

8. The installation begins, and the progress is displayed in the dialog.

   ![4 Installing.jpg](https://help.secude.com/__attachments/a_0c854135740dcef17229617452c40ef19837c9579c2592408a541120fddc072c/4%20Installing.jpg?cb=f891817b0019c0d8885da1a3fec05369)

   *Installation progress dialog*
9. When the installation is complete, a message appears confirming that the add-on has been successfully installed.

   ![5 Installation completed.jpg](https://help.secude.com/__attachments/a_f82fd14f6e47d82c9cc4fc88a3170f9c288ab969c2fc9e1e3c947e3039e08830/5%20Installation%20completed.jpg?cb=7b32d5a4aa48b3770dd181a9e1f1df19)

   *Installation completed dialog*
10. Click **Next** to proceed.

11. The initialization dialog appears. To prevent connectivity issues, ensure that the correct Microsoft Entra ID application details are entered on the screen. Note**:** If the `hc.conf.enc` file is included with the installer, this initialization screen is skipped and only the completion dialog is shown. The initialization screen appears only when the `hc.conf.enc` file is not present in the installer folder.

    ![6 APP ID details.jpg](/__attachments/a_cc595c667b6b8edbe2e012227a5d2a0c8e27353b914ced40daf9d010de7c3099/6%20APP%20ID%20details.jpg?cb=514884c5ae0e800454e960676ceea830)

    *Initialization dialog*
    1. **Application ID** : Enter the unique identifier of your registered application. For example, `v6ca776-c74e-437d-98ef-662ecb5751tt`

    2. **Redirect URI** : Enter the URI that was provided when registering the native application in the Azure portal. For example, `https://localhost`.

    3. **Tenant ID:** If the registered application is **Single tenant** , you need to enter the globally unique identifier of your tenant if not, you can leave it empty. For example, `9c1cfc28-1ec6-44ea-bec6-e3492ef0cd16`

    4. **Cloud Type** : **Commercial** is selected by default. Based on your Azure subscription and configuration, select the required cloud type from the list: Commercial, Custom, Germany, US_DoD, US_GCC, US_GCC_High, US_Sec, US_Nat, or China_01. If you select **Custom** , enter the appropriate URLs in the **Protection Cloud URL** (for example, `https://api.aadrm.com`) and **Policy Cloud URL** (for example, `https://dataservice.protection.outlook.com`) fields.

    5. **Enable Federal Information Processing Standards (FIPS):** Enable this option to use encryption algorithms that comply with FIPS standards. When enabled, MPIP uses only FIPS-compliant encryption algorithms, and when disabled, it uses standard encryption algorithms. If this option was not enabled during installation, it can later be enabled through a registry entry. For more details, please refer to the section "[Step 5 Modify Registry Settings](/halocad-add-on-for-autodesk-autocad/2.4/ac-installing-the-halocad-add-on-for-autocad.md#HRS)".

    6. Click **Next**.

12. Once the initialization is complete, a success message appears as shown below.

    ![7 Completing the HaloCAD setup dialog.jpg](/__attachments/a_fc0372f4624a0076ea3a690d3fd770dca8610459349332ad4dc0c5d5ff93206d/7%20Completing%20the%20HaloCAD%20setup%20dialog.jpg?cb=135014fb394feec2908fda346ec887cb)

    *Initialization completed dialog*
13. Click **Close** to close the installation wizard.

**Post-installation checks**:

1. To view the add-on, open the **AutoCAD** Application \> **HaloCAD** tab.

2. **Masking Personally Identifiable Information (PII)** :By default, the HaloCAD Add-on masks Personally Identifiable Information (PII) in logs, such as email names, file paths, and IP addresses in the MIP SDK logs. In HaloCAD logs, information such as the label name, label ID, engine ID, policy ID, and watermark text is masked with asterisks. To view PII in clear text, create the following registry entry in Path: `Computer\HKEY_CURRENT_USER\SOFTWARE\Secude\HaloCAD Add-on for AutoCAD`

   **Name** : `mipallowpii`, **Type** : `REG_SZ`, **Value** : `true`

   The log files are located at the following paths:
   * **MIP SDK log** : `%AppData%\Roaming\Secude\HaloCAD\acad\mip\logs\mip_sdk.miplog`

   * **HaloCAD log** : `%AppData%\Roaming\Secude\HaloCAD\acad\halocad.log`

3. If your network infrastructure includes a proxy server that provides access to external websites. Then, to connect to the Secude License Manager URL, you need to manually add the Proxy settings in the add-on. To do so, create a registry entry in the root directory, `Computer\HKEY_LOCAL_MACHINE\SOFTWARE\Secude\HaloCAD Add-on for AutoCAD`

   **Name** : `proxyuri`, **Type** : `REG_SZ`, **Value** : The format is, `<URL>:<PORT>`. For example, `http://10.41.0.130:808`

### **Silent Mode**

Besides graphical mode, the add-on can be installed in silent mode, which does not require user involvement or display a user interface. It is a convenient way to streamline installation using the command at once.

1. Open the Command Prompt with elevated rights (Run as Administrator).

2. Navigate to the add-on installer directory.

3. To know the list of options available in silent mode, follow the steps given below:

   **Type** `HaloCAD_AutoCAD_Setup.exe -help`

   **Press** `Enter`

   **Output**

   ...

   `HaloCAD_AutoCAD_Setup.exe -install -application <AutoCAD 2026 |AutoCAD 2025 |AutoCAD 2024 > -applicationid <azure_application_id> -redirecturi <azure_redirect_url> -tenantid <azure_tenant_id for Single-tenant app|null for Multi-tenant app> [-cloudtype <Commercial|Custom|Germany|US_DoD|US_GCC|US_GCC_High|US_Sec|US_Nat|China> -protectioncloudurl <protection cloud url> -policycloudurl <policy cloud url>] -enablefipsmode <true|false>`

   `[Default Parameters: cloudtype - Commercial and enablefipsmode - false]`

   `HaloCAD_AutoCAD_Setup.exe -uninstall`

   `To delete HaloCAD cache through Silent Mode Uninstallation`

   `HaloCAD_AutoCAD_Setup.exe -uninstall -clearcache <yes>`

   `For Silent Mode Installation if ENC file already exists in the same location`

   `HaloCAD_AutoCAD_Setup.exe -install -application <AutoCAD 2026 |AutoCAD 2025 |AutoCAD 2024 > -enablefipsmode <true|false>`

4. The following command illustrates how to install the add-on using the Azure application details.

   `HaloCAD_AutoCAD_Setup.exe -install -application "AutoCAD 2025" -applicationid v6ca776-c74e-437d-98ef-662ecb5751tt -redirecturi https://localhost -tenantid 9c1cfc28-1ec6-44ea-bec6-e3492ef0cd16 -cloudtype Custom -protectioncloudurl https://api.aadrm.com -policycloudurl https://dataservice.protection.outlook.com -enablefipsmode true`

5. The example below shows how to install the add-on using the `hc.conf.enc` file located in the same installation location.

   `HaloCAD_AutoCAD_Setup.exe -install -application "AutoCAD 2025" -enablefipsmode true`

6. Press `Enter`.

7. The installation is complete.

### **Via System Center Configuration Manager**

Microsoft System Center Configuration Manager (SCCM) is an administrative tool that allows organizations to deploy operating systems and applications to Windows users efficiently and cost-effectively across their environment.

Using SCCM, the HaloCAD add-on can be deployed silently and automatically to specific target computers throughout the enterprise.

**Before You Begin**

1. Ensure that you have reviewed the prerequisites described in the Graphical Mode section.

2. We recommend adhering to best practices when creating a deployment procedure.

3. For guidance on preparing your environment, refer to the official Microsoft online documentation.

**Deployment Using SCCM**

This guide assumes that an SCCM environment is already configured. After configuration, you can use the silent mode commands described in the Silent Mode section to deploy the add-on.

## Step 5: Modify Registry Settings

Prerequisite: To modify the add-on registry entries, first launch the CAD application and sign in to Microsoft Purview Information Protection to ensure that an active HaloCAD session is established.

Note: Only the registry entries listed in the table below should be modified.

The HaloCAD registry entries are grouped into two sections: **HKEY_CURRENT_USER** and **HKEY_LOCAL_MACHINE**. Depending on your requirements, you can modify the following settings:

1. `HKEY_CURRENT_USER\SOFTWARE\Secude\HaloCAD Add-on for AutoCAD`. Once you have logged into the HaloCAD Session, open Registry Editor, navigate to this path, and modify the desired registry key. For example, to change the log level, double-click **loglevel** , change the "Value data" using the values listed in the table below, and then click **OK**.

   1. loginterval

   2. loglevel

   3. logsize

2. `HKEY_LOCAL_MACHINE\SOFTWARE\Secude\HaloCAD Add-on for AutoCAD`: `enable_fips` (This entry does not require an active HaloCAD session.)

|  **Name**   | **Default Value** | **Type**  |                                                                                                                                                                                                                                                                                          **Description**                                                                                                                                                                                                                                                                                           |
|-------------|-------------------|-----------|----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| loginterval | `30`              | REG_SZ    | It automatically removes log files that are older than the default retention period. By default, log files older than 30 days are deleted.                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| loglevel    | `0X00000003 (3)`  | REG_DWORD | Log level information is logged in the `halocad.log` file. * Error---0. Logs error events that prevent program execution. * Record---1. Records all the details about the behavior of the application. * Warning---2. Logs unexpected exceptions that indicate potential problems. * Information---3. A standard log level that highlights the progress of the application. * Verbose---4. Debug events are logged. * Verbose 1---5. Debug 1 events are logged. * Verbose 2---6. Debug 2 events are logged. * Verbose 3---7. Debug 3 events are value. * Verbose 4---8. Debug 4 events are logged. |
| logsize     | `1024`            | REG_SZ    | The `halocad.log` file is created at the start of a HaloCAD session and is stored in the default parent location directory. To have control over log file size, HaloCAD allows you to configure backup/archive the current log file with a timestamp when it exceeds the default size of `1024 MB,` and creates a new one. Format: `halocad<ddmmyy_hhmmss>.log`                                                                                                                                                                                                                                    |
| enable_fips | `false`           | REG_SZ    | Enable or Disable FIPS Mode 1. true: MPIP uses only FIPS-compliant encryption algorithms. 2. false: MPIP uses standard encryption algorithms.                                                                                                                                                                                                                                                                                                                                                                                                                                                      |

*Configuration in the HaloCAD Registry*

**What to do next**

1. If the encrypted configuration file was placed with the installer:

   1. You can launch the CAD application and start using the HaloCAD features immediately.

   2. The license is activated silently in the background.

   3. For details on protecting CAD files, refer to the Operations Manual.

2. If the encrypted configuration file was not placed with the installer:

   1. You must activate the license manually.

   2. Follow the instructions in the "UI-based Manual License Activation" section of the Technical Reference Manual.

**HaloCAD Add-on with PLM**

1. If you have installed HaloCAD as a standalone add-on in your environment, you can create a file and protect it with a suitable label. For more information, please refer to the Operations Manual.

2. If you have the HaloCAD add-on installed in a suitable PLM environment, it will intercept the file download and automatically protect it with a suitable label. For more information, please refer to the HaloCAD for PLM Operations Manual.

   To integrate with SAP ECTR, you need to install the following components:
   1. HaloENGINE Service

   2. HaloENGINE

   3. HaloCORE Client for NetWeaver

   4. HaloCORE for DMS

   5. HaloCAD KPro

   To integrate with Autodesk Vault, you need to install the following components:
   1. HaloENGINE

   2. HaloCAD for Autodesk Vault

---
version: "2.4"
language: "en"
---
# Installing the HaloCAD Reader Add-on for AutoCAD

This chapter describes how to install and configure the HaloCAD Reader Add-on for AutoCAD.

**Before you begin**

The following prerequisites must be met:

1. A user who installs the HaloCAD Reader Add-on must have administrator rights.

2. Ensure that all active and open CAD applications are closed. If not, HaloCAD prompts a warning message as "*Please close all the CAD applications to proceed with the installation of HaloCAD Reader Add-on for AutoCAD*."

3. Ensure that the HaloCAD Add-on for AutoCAD (full version) is not installed on the same workstation. If it is already installed, HaloCAD prompts a warning message as "*No supported CAD applications are available in the system. (OR) Remove the full version of this product.*"

4. Ensure your Microsoft Entra tenant information is ready to enter when the setup process prompts you to perform a manual installation. Alternatively, for a safe and automatic installation, use `hc.conf.enc`. In both cases, the tenant information must be the same as that used in the full version installation. However, the licensing key is different for each of the add-ons. Refer to the sections "License Activation" and "Secure Installation" in the Technical Reference Manual for further information on the various methods for activating a license key and automatic initialization.

**Installation Procedure**

Install the application by using the GUI-based setup program that is provided in the installation package.

1. To begin the interactive installation, double-click the installer `HaloCAD_Reader_AutoCAD_Setup.exe` file. For the installation procedure, follow the installation wizard or refer to the full version.

2. The reader add-on can be installed and configured in the same manner as the full add-on. The command line to execute the silent installation is `HaloCAD_Reader_AutoCAD_Setup.exe -help`, and follow the commands.

3. **Post-installation checks**:

   1. To view the add-on, open the **AutoCAD Application** \> **HaloCAD** tab.

   2. Similar to the full version, the Reader add-on also masks personally identifiable information (PII) in logs. To view PII in clear text, create the following registry entry in Path: `Computer\HKEY_CURRENT_USER\SOFTWARE\Secude\HaloCAD Reader Add-on for AutoCAD`

      **Name** : `mipallowpii`, **Type** : `REG_SZ`, **Value** : `true`

      The log files are located at the following paths:
      * **MIP SDK log** : `%AppData%\Roaming\Secude\HaloCAD\acad\mip\logs\mip_sdk.miplog`

      * **HaloCAD log** : `%AppData%\Roaming\Secude\HaloCAD\acad\halocad.log`

      * For more details, please refer to the section "[Step 5: Modify Registry Settings](/halocad-add-on-for-autodesk-autocad/2.4/ac-installing-the-halocad-add-on-for-autocad.md#HRS)".

   3. If your network infrastructure includes a proxy server that provides access to external websites. Then, to connect to the Secude License Manager URL, you need to manually add the Proxy settings in the add-on. To do so, create a registry entry in the root directory, `Computer\HKEY_LOCAL_MACHINE\SOFTWARE\Secude\HaloCAD Reader Add-on for AutoCAD`

      **Name** : `proxyuri`, **Type** : `REG_SZ`, **Value** : The format is, `<URL>:<PORT>`. For example, `http://10.41.0.130:808`

**What to do next**

1. If the encrypted configuration file was placed with the installer:

   1. You can launch the CAD application and begin using the reader add-on right away to view the protected file.

   2. The license is activated silently in the background.

   3. For details, refer to the Operations Manual.

2. If the encrypted configuration file was not placed with the installer:

   1. You must activate the license manually.

   2. Follow the instructions in the "UI-based Manual License Activation" section of the Technical Reference Manual.

---
version: "2.4"
language: "en"
---
# Operations Manual

## About this Manual

This manual provides comprehensive guidelines and step-by-step instructions for working with **HaloCAD solutions (Label** and **Protect)** . For information on deployment and configuration, refer to the **Installation Manual** included in the product package.

## General FAQs

This section answers the most frequently asked questions (FAQs). For additional inquiries, please contact your sales representative or the support team.

1. **What does HaloCAD provide for an organization?**

   HaloCAD solution protects engineering CAD files and enforces security across their entire lifecycle.

2. **How many variants does HaloCAD have?**

   HaloCAD is available in three variants:

   1. HaloCAD Add-on for CAD applications -- a standalone add-on

   2. HaloCAD for PLM

   3. HaloCAD Reader Add-on for CAD applications

3. **What is the difference between the HaloCAD Add-on for CAD and the HaloCAD for PLM?**

   HaloCAD Add-on for CAD is a standalone solution for organizations that do not store CAD files in PLM. It enforces protection through user engagement.

   HaloCAD for PLM integrates with the respective PLM application and includes the capabilities of HaloCAD PROTECT and HaloCAD MONITOR. The MPIP label is applied automatically, based on the rules defined in the Classification Engine, without requiring user intervention.
4. **What distinguishes the HaloCAD Reader add-on from the HaloCAD Standalone (full add-on)?**

   HaloCAD Standalone Add-on (Full Version) protects CAD files using Microsoft Purview Information Protection solution. This version is licensed.

   HaloCAD Reader Add-on allows viewing of files protected by the HaloCAD Standalone Add-on. This version is free of charge.
5. **What languages are supported by the HaloCAD add-on?**

   Currently, the HaloCAD add-on only supports English.

6. **Does the HaloCAD Add-on support all native CAD file types?**

   Yes, the HaloCAD Add-on supports all CAD native file types.

7. **What happens if an unauthorized person tries to open a HaloCAD-protected CAD file?**

   The process begins with user authentication, which verifies the user's identity. If authentication fails, an error message is displayed, and access is denied.

8. **Who decides what labels should be used for various CAD drawings and how they are managed in the background?**

   An administrator manages labels (user rights) in the Microsoft Purview portal, while engineers can create profiles, classification schemas, and action rules based on the sensitivity of their data.

9. **What if I don't want a certain file to be protected?**

   If you do not want the file to be protected, you can apply the **"No Protection"** label, which does not include any policy settings.

10. **Can I create my own labels?**

    Yes, HaloCAD allows users to create custom permission labels.

## How does it work?

This chapter provides a high-level explanation of the underlying processes and interactions between the system components to help you understand how HaloCAD protects sensitive data.

### License Enforcement

After installation, HaloCAD programmatically sends a license validation request to Secude's License Manager when a user attempts to start a session for the first time by opening the CAD application. Based on the administrator's installation method, one of the following scenarios applies:

**Case 1:**

If the license is activated automatically during the installation process, the user can continue using all HaloCAD features without interruption.

**Case 2:**

If the license has not been activated, the user will receive an error message and will be unable to access HaloCAD features. For information on license activation, refer to the **License Activation** section of the Technical Reference Manual.

### Applying Protection using HaloCAD Add-on

At a high level, HaloCAD workflow involves the following steps:  
![Common_Full_How does it work.png](https://help.secude.com/__attachments/a_06e38a78e035adf5cbfb5d2da4203f8bd88886dfb503b62de31b7a4991a8c599/Common_Full_How%20does%20it%20work.png?cb=50711313c7ce5ba3f2660fd6bb68bbeb)

*HaloCAD protection*

1. To create new CAD files, the user launches the CAD application and logs into the HaloCAD session for the first time.

2. HaloCAD connects to the Microsoft Entra tenant. In this manual, `halosecude.onmicrosoft.com` is used as an example tenant.

   1. Microsoft Entra ID prompts the user for authentication.

   2. After successful authentication, Microsoft Purview Information Protection (MPIP) labels are downloaded for the logged-in user (`john@halosecude.onmicrosoft.com`).

3. File protection: The user (John) selects and applies two different labels to two separate files.

4. HaloCAD enforces document protection based on the selected label. When a sensitivity label is applied, it is stored in the document metadata, and the corresponding protection settings are enforced to secure the content.

5. **File-Sharing** : Assume that `john@halosecude.onmicrosoft.com` shares the files with multiple users. **Users A** ,**B** ,and **C** receive **File 1** , while **User D** receives **File 2**.

6. Content consumption: Users A, B, C, and D attempt to access the protected files. Microsoft Entra ID authenticates each user, and the file opens upon successful authentication. Access permissions such as **View, Edit, Print, Copy, Export,** and **Change** are granted based on the applied label. Different permission levels may be assigned to individual users or user groups.

   Note: The user who initializes HaloCAD is considered the author and is granted full access rights to the document. For more information on labels, refer to the Microsoft documentation.

   1. File 1 - Full access is granted to `User A@halosecude.onmicrosoft.com`.

   2. File 1 - Read-only (view-only) access is granted to `User B@halosecude.onmicrosoft.com`.

   3. File 1 - `User C@halosecude.onmicrosoft.com` is denied access and cannot open the file.

   4. File 2 - Access was previously granted to `User D@halosecude.onmicrosoft.com` but has been revoked due to risky or suspicious activity.

**Logged-in user (HaloCAD session)**

In this document, the term "logged-in user" refers to the individual or user account that launches the CAD application and signs in to Microsoft Entra ID through the Microsoft Sign-In application. This may differ from the operating system user currently signed in. Collectively, this is referred to as the "HaloCAD session."

### Viewing a Protected File Via the HaloCAD Reader Add-on

At a high level, HaloCAD workflow involves the following steps:  
![Common_Reader How does it work.png](https://help.secude.com/__attachments/a_fbaaa5ba91cc23f7a581d9a7c020154fd4a417396dc6e41761c81524b921cacb/Common_Reader%20How%20does%20it%20work.png?cb=dd0cedef1a51cb05fe460946f52fff25)

*HaloCAD Reader Add-on*

1. The user selects two files that are protected by HaloCAD.

2. When the user logs in to the HaloCAD session for the first time, a connection to Microsoft Purview Information Protection is required. Microsoft Entra ID authenticates the user.

3. HaloCAD indicates that the files can be opened only in read-only mode. In this scenario, the user is authorized to open File 1.

4. File 2 does not open because the user does not have the required permissions.

By design, saving is restricted once a protected file is opened in a session to prevent protected content from being copied to an unprotected file. HaloCAD shows a restriction message. In a fresh session, unprotected files can be created and saved without any restrictions.

## Get Started with HaloCAD

This section describes how to protect a file, open a protected file, and use the HaloCAD Reader add-on.

### Permission Levels and Usage Rights

#### **Basic Permissions**

The following table lists the basic permissions and the usage rights that they contain:  

| **S.No** |    **Permission Level**     |                                                       **Usage Rights (Allowed Recipient Actions)**                                                        |
|----------|-----------------------------|-----------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1        | View                        | Open and read the data (also known as "Read-only"). It includes Zoom and view from different angles (for CAD file types).                                 |
| 2        | Edit                        | Edit the file and save it                                                                                                                                 |
| 3        | Copy                        | Extract data (including screen captures) from the file into the same or another file.                                                                     |
| 4        | Print                       | Print the content                                                                                                                                         |
| 5        | Export                      | Save the content to a different filename (Save As). Also includes "Export to PDF".                                                                        |
| 6        | Change Rights               | Changing the label that is applied to a file includes removing protection and saving it as an unprotected file.                                           |
| 7        | Owner (Full Control rights) | Grants all rights to the file and all available actions can be performed. Also includes the following permissions: 1. Remove protection 2. Relabel a file |

*Basic Permissions*  
**Author (creator) of a file**

The author of a file has all the rights and actions mentioned in the above table. Also includes the following permissions:

1. Open file after the expiry date

2. Revoke access

#### **Custom Permissions**

The following table lists the custom permissions and the usage rights that they contain:  

| **S.No** | **Permission Level** |                                              **Usage Rights (Allowed Recipient Actions)**                                              |
|----------|----------------------|----------------------------------------------------------------------------------------------------------------------------------------|
| 1        | Viewer               | Open and read the data (also known as "Read-only"). It includes Zoom and view from different angles.                                   |
| 2        | Reviewer             | Viewer's allowed permissions plus: 1. Edit 2. Save the file                                                                            |
| 3        | Co-Author            | Reviewer's allowed permissions plus: 1. Print 2. Extract data (including screen captures) from the file into the same or another file. |
| 4        | Co-Owner             | Co-Author's allowed permissions plus: 1. Export 2. Change Rights                                                                       |
| 5        | Only for me          | Grants all rights to the file and all available actions can be performed only by the author of the file.                               |

*Custom Permissions*

### HaloCAD Screen Introduction

After installing the HaloCAD add-on, the HaloCAD tab appears in the CAD application, as shown in the figure below:  
![HALOCAD Start up - AC .png](https://help.secude.com/__attachments/a_cc4c7b9a99f81697c8c0c703bd536e7057c39e085074840c10644936d7e2e6fb/HALOCAD%20Start%20up%20-%20AC%20.png?cb=586ea0acdee91d2775421edebee7f6f6)

*HaloCAD in AutoCAD*

The following table provides a brief description of each HaloCAD menu element.  

| **S.No** |                                                                         **Icon**                                                                          |                                                                                                                                                                                                                                                                                                                                             **Description**                                                                                                                                                                                                                                                                                                                                             |
|----------|-----------------------------------------------------------------------------------------------------------------------------------------------------------|---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1        | ![stauts (1).png](https://help.secude.com/__attachments/a_22cbd92292655f3fefd9f73998d0ba0ab5afba735cd4141c5f6499a871bc5195/stauts%20(1).png?cb=ce9418192203a4b0d6c6149b5cbf59df) | The **Status** icon displays the status of the file. ![Status screen.png](https://help.secude.com/__attachments/a_db94c7580e97e82e27941bc1dea605630d67e72b499bae3acef3df7e5d97ebd4/Status%20screen.png?cb=834fa693870e7f8fbeae1c737a0062b3) 1. **Connected as**: Name of the logged-in user 2. **Owner**: Author of the document 3. **Sensitivity**: Name of the label applied 4. **Permissions**: Rights on the file 5. **Expire access**: Displays the details of how long a user can access the labeled file 6. **Revoke Access** button**:**Revokes access granted for a protected document 7. **Reset**button: Logs off a user from the current active session. The button will be disabled unless the user logs in again |
| 2        | ![About.png](https://help.secude.com/__attachments/a_f55834c85b81e42b397fba4206d1f78f7cb426507889667951261d05cae505f9/About.png?cb=6934a8b3072095a7cee61e8692716638)             | The **About**icon displays the application version and license information. For details on license activation, refer to the "License Activation" section of the Technical Reference Manual. ![About Screen.png](https://help.secude.com/__attachments/a_53c955336293094deebd1a8327793d2d7615b388171bd4e4b9491717300d6d1b/About%20Screen.png?cb=04a969a467462a71a699b9a55119e9ed)                                                                                                                                                                                                                                                                                                                                               |
| 3        | ![Label icon.png](https://help.secude.com/__attachments/a_e2b58f0dfec9d1245f927848e27a70c28c107cc75a8c7b72a3dea4895fa93207/Label%20icon.png?cb=482a28372c1b817ac112503dfbcbac24) | The **Sensitivity** icon enables and disables the **HaloCAD**ribbon. ![HaloCAD Ribbon.png](https://help.secude.com/__attachments/a_b4c8f2f3d0b49d2235f5cc7f09de84db89728cd2ce2e5503d480f2f5931cc757/HaloCAD%20Ribbon.png?cb=a5dd1107c16d4d6bca46b79198b26906) **Pencil icon - Click to change label**: 1. Downloads the available labels. 2. Allows changing an applied label.                                                                                                                                                                                                                                                                                                                                                 |
| 3        | ![Label icon.png](https://help.secude.com/__attachments/a_e2b58f0dfec9d1245f927848e27a70c28c107cc75a8c7b72a3dea4895fa93207/Label%20icon.png?cb=482a28372c1b817ac112503dfbcbac24) | ![Sensitivity bar after connecting - AutoCAD.png](https://help.secude.com/__attachments/a_e5de128843958a190f73fe8a67ecead0063032c2c52e7aa6c9627beef2c15437/Sensitivity%20bar%20after%20connecting%20-%20AutoCAD.png?cb=7508c0aea8960ce13cb6a0d5895207ed) 1. **Green check mark - Click to set label**icon - applies the selected label or removes the existing label. 2. **Red cross mark - Click to cancel**icon - cancels the selected label. 3. **Sensitivity** labellist - displays the labels.                                                                                                                                                                                                                            |

*Overview of screen elements*

### How to Protect a CAD File?

**Prerequisites**

* To protect organizational data by using sensitivity labels, configure protection settings for each label in the **Microsoft Purview portal**.

* To set a default label for documents, configure the following setting in the **Microsoft Purview portal** : Go to **Label policies** \> **Settings** \> **Documents** \> **Default settings for documents** \> **Apply a default label to documents**, and then select a label from the list.

To protect a CAD file, perform the following steps:

1. Open the AutoCAD application, and then open an existing file or create a new file.

2. For new or unprotected files, the **Sensitivity** status displays **Not set** if no default label is configured in the policy. If a default label is configured, the configured default label is displayed. In this example, no default label is set.

3. On first login, HaloCAD prompts for **Microsoft Sign-In Assistant** authentication.

   ![Microsoft Sign-In Assistant invoking message.png](https://help.secude.com/__attachments/a_a457a1c9e4008c060892d9d0f0e7a40c380d4eabe0e884398ebc6b6f05b0e82b/Microsoft%20Sign-In%20Assistant%20invoking%20message.png?cb=1f27eeff142b5b05e48f95f0e760e276)

   *Microsoft Sign-In Assistant invoking message*
4. Click **OK** and enter your credentials.

   ![Microsoft Sign in1.png](https://help.secude.com/__attachments/a_d5392e6f4a889d185a3950e95cd968d75054f4403eb37cfd890b19cd4bcca73f/Microsoft%20Sign%20in1.png?cb=ae1cbf50ff9b1665701f1566c5f6967b)

   *Authentication sign-in prompt*
5. After authentication, HaloCAD connects to Microsoft Entra ID and caches the user credentials.

6. Go to the **HaloCAD** tab and click **Sensitivity**.

7. To apply the label to the active document, click the pencil icon (**Click to change label**).

8. A notification appears indicating that labels are being downloaded from Microsoft Purview Information Protection.

   ![Please wait message.png](https://help.secude.com/__attachments/a_3b88039b89c615ff4524433066b66c536e8c8439c4bdfeb67cc4dcc5a034207c/Please%20wait%20message.png?cb=e2c968e123035a20011519a694195ed0)

   *Fetching labels*
9. From the **Sensitivity** list, select a label, and then click the green check mark (**Click to set label**) to confirm the selection.

   ![Downloaded labels AutoCAD.png](https://help.secude.com/__attachments/a_6adc84e567b471d2ee76616560d6d7347b50ab015c6ffb2ed605de41eab78796/Downloaded%20labels%20AutoCAD.png?cb=e89270b409f72b2c567fa469c8de8042)

   *Downloaded labels for the signed-in user*
10. For a new file, click **Save** and specify a file name.

11. For an existing file, an additional save action is not required. When the label is applied by clicking the **Click to set label** (check mark) icon, the file is saved automatically.

**Result**

* The selected label is applied to the active document.

* The selected label is displayed on the HaloCAD ribbon, along with the color configured in the Microsoft Purview portal.

* To clear the credential cache, click **Reset** in the **Status**UI.

![After label selection_AutoCAD.png](https://help.secude.com/__attachments/a_1c39b1ba43587eba16cabac63b304867a4d3b7d93a7fb4b8a4fee472a87a3316/After%20label%20selection_AutoCAD.png?cb=46d5c034075901f7e6563f5fedbe7786)

*File with applied label*

#### **Cancel, Remove, Relabel, and More**

1. **Canceling Label Selection** : If you have selected an incorrect label, you can cancel it by clicking the red cross icon (**Click to Cancel**). This will remove only the selected label that has not yet been applied to the file.

2. **Removing Protection** : To remove an existing label and keep the file unprotected, select the **No Protection** label from the list. Note: Whenever you change a label, click the green check mark icon (**Click to set label**) to apply the updated label. The file will be saved, and the label will be applied to the active document.

3. **Relabeling** : If you want to apply a different label or modify protection settings (Custom Permissions) after a label has already been applied, first click the pencil icon (**Click to change label** ) and then select a new label from the list. For more details, refer to "[Example 7: Custom Permissions Label](https://help.secude.com/halocad-add-on-for-autodesk-autocad/2.4/ac-operations-manual.md#CPL)".

4. **Revoke Access** - If an author does not want a user to access the shared file for security reasons, you can prohibit it by clicking **Revoke Access** in the **Status** UI. Please refer to the section "[Example 10: Revoke a File](https://help.secude.com/halocad-add-on-for-autodesk-autocad/2.4/ac-operations-manual.md#revoke)".

#### Log out an Active User

This section describes how to log out the currently active user from HaloCAD. Logging out ends the active session and allows another user to log in.

1. Go to the **HaloCAD** tab \> click **Status** \> click **Reset**.

2. When the following message appears, click **Yes**.

   ![Reset Clear cached credentials #1.png](https://help.secude.com/__attachments/a_32c3ece507b43187ccf037704a7afc3d48dc482dab0c4918af8ec388831b1d63/Reset%20Clear%20cached%20credentials%20%231.png?cb=883a859681b430cb98051260ecafa62b)

   *Clear cached credentials #1*
3. When the next message appears, click **OK**.

   ![Reset Clear cached credentials #2.png](https://help.secude.com/__attachments/a_b4d4a08b68d563cc1f9d56e0036f941156ed875c427300dc81a3c6f33b7e84e5/Reset%20Clear%20cached%20credentials%20%232.png?cb=23441a9334f41a354fcf13df9ea57418)

   *Clear cached credentials #2*
4. Restart the application.

**Result**

* After relaunching the application, users can log in to a new HaloCAD session using their credentials.

* If you do not relaunch the CAD application, HaloCAD displays the following message: *"For HaloCAD to work properly you should relaunch the application now".*

* Click **OK**, and then relaunch the application.

**Next step**

1. **Log in after reset:** After restarting the application, when you open a protected file or click the pencil icon (**Click to change label** ), HaloCAD prompts you to use the Microsoft Sign-In Assistant. Click **OK**, and then sign in with your credentials.

   ![Microsoft Sign-In Assistant invoking message.png](https://help.secude.com/__attachments/a_a457a1c9e4008c060892d9d0f0e7a40c380d4eabe0e884398ebc6b6f05b0e82b/Microsoft%20Sign-In%20Assistant%20invoking%20message.png?cb=1f27eeff142b5b05e48f95f0e760e276)

   *Microsoft Sign-In Assistant invoking message*
2. For more information about HaloCAD functionality, see **Common scenarios**.

### How to Export a Protected CAD File to a PDF File?

To convert / export / save a protected file as a PDF:

1. Go to the **Output** tab \> click **Export** \> **PDF** \>click **Save**.

2. Alternatively, click the **AutoCAD** logo button \> click **Export** \> **PDF** \> click **Save**.

3. **Result**: An exported PDF file is saved with protection.

The protected file may need to be viewed after being exported. To open a protected file, follow the instructions below:

**Prerequisite**: Ensure that the latest version of Acrobat Reader DC or Acrobat DC is installed.

1. Double-click the protected file or open the **Adobe** application, go to the **File** menu \> **Open** \> browse, and select the file.

2. Microsoft Sign-in prompts you to provide your credentials.

3. Enter the credentials and click **Sign in**.

   ![Opening a PDF file using MIP plug-in.png](https://help.secude.com/__attachments/a_0bed84d0cb5a1c3d8b3c1de3f989ebbf35b891d2caaab656030a9a39f195739a/Opening%20a%20PDF%20file%20using%20MIP%20plug-in.png?cb=a809931c9881a9792aed85dec12846e7)

   *Protected PDF File*
4. To the question "*Do you want to stay signed in?* ", answer **Yes**.

**Result**:

* Upon successful authentication, the protected file is opened.

* If authentication fails, access to the file is blocked.

**Next step**

To see the actual permissions that are applied to the file, do one of the following:

* Click on the lock icon \> **Permission Details** \> **Document Properties** screen \> click **Show Details**.

* Click **File** \> **Properties** \> click **Security** tab \> **Document Properties** screen \> click **Show Details**.

### How to View a Protected File in HaloCAD Reader?

The reader add-on is intended for customers who do not have the full HaloCAD solution installed. Secude provides this viewer program to enable end users to view HaloCAD-protected files without having to install the standard (full) version of the HaloCAD solution on their desktops.  
**Reader add-on vs HaloCAD Standard add-on**

Both add-ons use the Microsoft Purview Information Protection security solution. However, the reader add-on cannot function as a HaloCAD Standard add-on; it is limited to opening and reading CAD files that are protected by the Standard/Full add-on.

Prerequisite: Make sure that the HaloCAD Reader Add-on for AutoCAD is installed.

1. Double-click the protected file.

2. HaloCAD will prompt you about the Microsoft Sign-In Assistant before allowing you to access the file.

3. Click **OK.** Enter the credentials and click **Sign in**. (However, you do not require this validation if your cached account information is available.)

**Result**:

* A read-only version of the file opens with the following message.

  ![Reader add-on message.png](https://help.secude.com/__attachments/a_1f976103bf6e06dc7432f1d7a48ff3499030623e7bc38a1e7b4c7afd67de7730/Reader%20add-on%20message.png?cb=653daf57c73b869cfb40a27ffc833714)

  *HaloCAD reader message*
* Click **OK**on the HaloCAD reader message.

* You can also observe the disabled pencil icon (**Click to change label**) in the Sensitivity ribbon, along with disabled tabs, panels, and buttons in the CAD application, as well as disabled permissions such as edit, copy, print, export, and change rights options.

  ![Disabled Reader pencil.png](https://help.secude.com/__attachments/a_84351d4ec10b64ffe5d4c12923f02bb523dd9433a4df7f4cfd0144fe7471a2c3/Disabled%20Reader%20pencil.png?cb=3fd2fdee6f380ef0f69f1707dae21a25)

  *Disabled Click to change label icon*

**Next step**

The reader add-on gives you the following options, similar to the standard add-on:

1. To view the file's permissions, click the **Status**icon.

2. To log out an active user from a HaloCAD session, click the **Reset**icon.

## Common Scenarios

This section presents common scenarios for illustrative purposes and provides general guidelines.

### Concept: Sensitivity Labels

MPIP labels can be customized to meet the requirements of each organization. These labels are defined and managed directly in the Microsoft Purview portal, and the HaloCAD Add-on retrieves them for user selection. When a sensitivity label is applied, the associated permission levels are automatically enforced on the document; any rights that are not explicitly granted are not assigned to the user. For example, a label applied to a CAD file with view-only permission allows users to view the content without any additional rights.

1. Let's say, for example, that you set up a label with "Viewer" permission. In this case, the user will be able to view MPIP-protected content, but the following actions and menus will be disabled:

   1. Pencil icon - **Click to change label** in the HaloCAD Sensitivity ribbon.

   2. All tabs, panels, and buttons in the CAD application.

   3. Edit, Copy, Print, Export, Change Rights, and Revoke options in the **Status** UI. Refer to [Example 1](https://help.secude.com/halocad-add-on-for-autodesk-autocad/2.4/ac-operations-manual.md#EX1).

2. In contrast to the previous point, if you configure a label with 'Co-Owner' permission, the user will have full access to the file, including the ability to view, edit content, print, copy, and export the file, as well as change rights (labels). Refer to [Example 2](https://help.secude.com/halocad-add-on-for-autodesk-autocad/2.4/ac-operations-manual.md#EX2).

3. For more details on labels, please refer to Microsoft Documentation.

### How to Open a Protected CAD File?

Follow the procedure below to view the protected file:

1. Click the protected file to open it.

2. When a labeled file is opened for the first time, a connection to the Microsoft Entra tenant is requested via the Microsoft Sign-In Assistant.

3. Click **OK**when prompted that the Microsoft Sign-In Assistant will be invoked and user credentials will be cached.

4. Follow the on-screen instructions to complete the authentication process.

5. After successful authentication, the file opens.

6. Access results for the same document may vary based on the applied policy settings. Please refer to the following examples.

#### Example 1: Label with Read-only Access

1. The MPIP label **HCAD Confidential** is applied to the following file. This label allows the logged-in (connected) user to view the file while restricting all other operations. To view the applied label and your file permissions, click the **HaloCAD** tab and then select **Status**.

   ![User with restricted access #1 AutoCAD.png](https://help.secude.com/__attachments/a_3df354cc40e90680f897a23f07b1ebda972bb66906d84dc7df39970343c6afb9/User%20with%20restricted%20access%20%231%20AutoCAD.png?cb=8ff27f010873d71ffd93b4aec9a6d259)

   *User with restricted access #1*
2. In case you edit the drawing by using a command, you will receive the following HaloCAD pop-up.

   ![User with restricted access #2 AutoCAD.jpg](https://help.secude.com/__attachments/a_536b7b9cb0a3e7eeeeffbf950c465e78c91e2d3ab10a1f851e6118af2e5b4226/User%20with%20restricted%20access%20%232%20AutoCAD.jpg?cb=aa437d18a6a2087ae0849d9fa56b0672)

   *User with restricted access #2*
3. Click **OK** .

**Behavior When Attempting to Copy, Save, or Capture Screen Data**

One of the most common ways confidential information is compromised is by copying it (Ctrl + C) or capturing it using tools such as Print Screen or the Snipping Tool and then transmitting it elsewhere. To prevent this, when a label without the **Copy** usage right is applied, the entire content is blanked out during copy or screen-capture attempts. Similarly, when the user clicks the **File** menu, options such as **Save** , **Print**, and other related actions are disabled because the user does not have the required authorization to perform these operations.  
![PrintEX1.png](https://help.secude.com/__attachments/a_ce865664f5534ef65003aa322457e12186a71e13a6eba0094561d0cf0516bcad/PrintEX1.png?cb=e334ed3193ab053894a01e1263777a42)

*HaloCAD prevents copying data*

**Behavior When Attempting to Relabel with Read-Only Permissions**

With "Read-only/View" rights, you are only allowed to view the content; all other options, including the tab, panel, button, and pencil icon - **Click to change label** on the HaloCAD Sensitivity ribbon, are disabled. As a result, the imposed protection cannot be relabeled or removed.  
![Disabled tabs, buttons and icons.jpg](https://help.secude.com/__attachments/a_fb71ea1cee034fe53fefdbca5187e98fb7adbfc2e2b715f533e6cff0b4fd84c7/Disabled%20tabs,%20buttons%20and%20icons.jpg?cb=8d373413e10164980ecabb8e53b35bd1)

*Disabled tab, buttons, and icons*

#### Example 2: Label with Full Control Access

The file shown below is labeled **HCAD Confidential** , which grants the user full access, therefore, all menus are enabled in the file. To view the applied label and your file permissions, click the **HaloCAD** tab and then select **Status**.  
![User with full access #3 AutoCAD.png](https://help.secude.com/__attachments/a_78364c92cfcb476cd80b0f451b1eebc3cd1e572cfec7ed328c657c349674e2b4/User%20with%20full%20access%20%233%20AutoCAD.png?cb=2fc13d5a6cbe8d4956f4ae205278466a)

*User with full access*

**What Happens if You Try to Relabel with Co-Owner Permission?**

With "Co-Owner" rights, you have complete control over the content and can relabel or remove the protection as needed by clicking the pencil icon - **Click to change label**on the HaloCAD Sensitivity ribbon.

#### Example 3: Unauthorized User Access

An unauthorized user who double-clicks on a protected CAD file receives the warning shown below. Note: An unauthorized user is anyone who is not listed in the allowed user list configured within the Microsoft Purview Information Protection sensitivity label.  
![Example 3 read-only Warning.png](https://help.secude.com/__attachments/a_5e13208a1d237cbd3fcb266ec1d1ce9caecdbf300c77bb7985a32899e8b766ca/Example%203%20read-only%20Warning.png?cb=39f1b97d8c661e26564fdcac318fbbfd)

*Unauthorized user opening a protected file #1*

Alternatively, if you use the **File** menu \> **Open**option to open a protected CAD file, you will receive the following message:  
![No permission.png](https://help.secude.com/__attachments/a_d3c12c337de77efdc060ff19f1458f95983d6e2969bbacbf1998ae1eaf52a282/No%20permission.png?cb=b8411283f73c294445ad1404d8de9d0c)

*Unauthorized user opening a protected file #2*

#### Example 4: Label Deleted from Microsoft Purview Portal

For instance, a label is applied to a file and is removed from the Purview portal. Users could no longer open the protected file; however, the underlying protection remains the same. A user who tries to consume this protected file will receive the following message.  
![Deleted Label in Azure Portal.png](https://help.secude.com/__attachments/a_5da96164f9064f0b6187f5700780f2ab0e3fd70625cca1ad22b9c073377babc8/Deleted%20Label%20in%20Azure%20Portal.png?cb=119e44933cb2add6564ce5ef6f8a9dd9)

*Warning message for the unavailability of a label*

#### Example 5: Label with Content Marking

Applying a watermark indicates what type of content it is and how it should be handled, and its presence in a file serves as a constant reminder to the user that the file contains sensitive information. The file below is labeled **HCAD Secret** and bears the watermark **Secret**.  
![Watermark.png](https://help.secude.com/__attachments/a_6b1e7d2f3a493ca3ed965632724d74149048a61dac6a686026a422b28036a6b4/Watermark.png?cb=80f20a1070a1164049de4af73b1c1aca)

*Content with watermark*

#### Example 6: Other Use Case Scenarios

##### **Importing a file with a restricted/least permission label**

A restricted/least permission label refers to a label with the lowest permission, such as view-only access rights. A full permission label has full access rights, such as Edit, Export, Change Rights, and so on.

1. **Case 1** - When you import a source file protected with a "restricted permission" label into the destination file that is protected with a full permission label, the following HaloCAD pop-up message appears as *"Please confirm applying least permission label from import file? Yes - Current file will be updated with import file label "XXXXXXX" No - Import operation will be cancelled."*

   1. If **Yes** ,then the imported file's label will be applied to the destination file. For example, the **HCAD Public** label with view rights will be applied.

   2. If **No** ,then the import will be blocked and the destination file will remain unchanged.

2. **Case 2** - When you import a source file protected with "full permission" or "restricted permission" label into a destination file that is unprotected, the HaloCAD pop-up message appears as described in Case 1 above. The response (Yes or No) process will also follow the same procedure as in Case 1.

3. **Case 3**- When you import a source file protected with "full permission label into a destination file protected with "restricted permission" label, the import is allowed and no label changes occur in the destination file.

In addition, when a protected file with a reference file is opened, all linked files are checked to determine the least restrictive permission among them. If any linked file has the lowest permission level, the destination file adopts that restriction. For example, if a linked source file is set to 'view-only,' the destination file is also enforced to 'view-only' upon opening.

##### **Labeling a File Without Protection**

Compared to a standard MPIP label, a **label-only MPIP label** adds metadata to a file without applying protection. In this context, *label-only* refers solely to metadata classification. The key difference between a standard **MPIP label** and a **label-only MPIP label** is that the standard label includes encryption and protection options, whereas the label-only variant does not. As a result, a **label-only MPIP label** can be applied to files that do not require protection but still need to be labeled for classification purposes.

**Prerequisite** : Make sure the **Control access** check box under **Choose protection settings for the types of items you selected** page is unchecked while defining the label-only in the Microsoft Purview portal.

**Other key points**

1. When a label-only MPIP label is applied to a file, the suffix (**Label Only** ) is appended to the label name. For example, if the label name defined in the portal is **HCAD Metadata** , it appears as **HCAD Metadata (Label Only)** after being applied to the file.

   ![Label only metadata.png](https://help.secude.com/__attachments/a_6fba567b0c9293f51042f1e00887fc0d9d8e59a6a45d94f884fbf1f3c62a531a/Label%20only%20metadata.png?cb=38f1a7489c0b8c97f8452ccd59164267)

   *MPIP label-only*
2. **Full rights**: A file with this label allows a user to have full rights on it.

3. **Notifications**: Similar to a standard MPIP label, the user will receive notifications when label-only is applied to a top-level parent file.

4. **With the HaloCAD Add-on**: The label details will be displayed in the Status UI, just like a standard MPIP label.

5. **Without the HaloCAD Add-on**: A file with a label-only MPIP label will behave like any other unprotected CAD file.

6. **Properties**: To see label details, follow the instructions below:

   1. Click the **AutoCAD** logo button \> **Drawing Utilities** \> **Drawing Properties**.

   2. Click on the **Custom** tab to view the author name, label ID, and label name.

   3. Furthermore, if watermarking is configured in this label, the **Custom** tab displays additional information such as the font color, font name, font size, layout, and text.

#### Example 7: Custom Permissions Label

**Difference Between Sensitivity Labels and Custom Permissions**

**Sensitivity Labels**

Sensitivity Labels are defined and managed by an organization's administrator in the Microsoft Purview portal. Each label includes a predefined set of permissions and is also referred to as administrator-defined permissions.

**Custom Permissions**

Custom Permissions are user-selectable permission sets available in the HaloCAD application UI. These permissions are defined by users and are also referred to as user-defined permissions.

##### **Protection using Custom Permissions from Microsoft Purview Portal**

**Prerequisite** : Make sure the custom permissions label in the portal is set to **Let users assign permissions when they apply the label**.  
![Custom permissions and other labels.png](https://help.secude.com/__attachments/a_eb6dff206b48051d6b194b26b30b0f12922a7513560c726e321b26c66d316cd2/Custom%20permissions%20and%20other%20labels.png?cb=79b3128a59e46f39243148c26ea83813)

*Custom permissions and other labels*

Follow the procedure to apply the custom permissions label:

1. Open the AutoCAD application, select a template, and create the required objects.

2. Click the **Click to change label** icon.

3. When HaloCAD downloads the labels, custom permission labels (from the Microsoft Purview portal and user-defined labels) are listed in the Sensitivity ribbon.

4. For illustration, the custom permission label from Microsoft Purview is named **Custom Permissions (Portal)**.

5. Select the **Custom Permissions (Portal)** label from the list and click the green check mark (**Click to set label icon**).

6. The HaloCAD screen appears, as shown below.

   ![HaloCAD Custom permissions.png](https://help.secude.com/__attachments/a_3a3755f2ace8115a90d69112298cc9a04c0405dee869baf5c0caac694aaa2b63/HaloCAD%20Custom%20permissions.png?cb=a7defa3e0a5bd8bac710fe5e2162e14a)

   *Custom permissions*
7. From the **Select Permission** list, choose the level of access you want users to have when protecting the file: (Viewer - View Only / Reviewer - View, Edit / Co-Author - View, Edit, Copy, Print / Co-Owner - All Permissions / Only for me).

8. In **Enter Users, Groups, or Organizations**, specify who should have access to the file. Enter individual email addresses, group email addresses, or an organization domain, separated by commas, spaces, or semicolons.

9. In the **Expire Access** field, specify how long the labeled file can be accessed. Select **Never**for unlimited access, suitable for less sensitive content. For highly sensitive content, select an expiry date so that recipients (other than the owner) cannot access the file after that date.

10. Click the **Clear date selection** option to clear the previous date selection.

11. Click **Apply** to confirm the protection settings.

    **Result:** The label is applied to the file.

**What happens when a user opens a custom permissions--labeled file?**

Based on the user's permissions, the file can be accessed accordingly. Note: The author of the document always has full rights to the file and can access it at any time, regardless of any custom permissions or expiry date configured in the label. The following example shows a label with custom permissions.  
![User with custom permission.png](https://help.secude.com/__attachments/a_8b2ebdfe4014a00efe5fde331d5bb7362789a153ab75003b347e919aa29590cd/User%20with%20custom%20permission.png?cb=9cda67d2002849a7fcab56e653bdc328)

*User with custom permission*

##### **Protection using Custom Permissions via HaloCAD Add-on**

In comparison to the previous section, the HaloCAD add-on also supports a **Custom Permissions** label. However, this label is defined at the application level within HaloCAD and is not obtained from the Microsoft Purview portal. The process for applying this label is the same as described in the previous section.

#### Example 8: Set an Expiration Date for File Access

**Prerequisites:**

1. Ensure that the expiration date is configured in the Microsoft Purview portal when using a static MPIP label.

2. Ensure that the expiration date is configured in the Custom Permissions label when using it via the Microsoft Purview portal or the HaloCAD add-on.

##### Why is File Expiration Necessary?

When files are shared with external vendors, access may continue even after a contract ends, creating security risks. To prevent this, set an expiration date on the file. This is a recommended practice when working with vendors or contractors. For example, if a file is shared with an expiration date of 31/12/2028, business partners will not be able to open it after that date. Each time the file is opened, HaloCAD displays the file's validity.  
![Validity of the file.png](https://help.secude.com/__attachments/a_5d3abe1ca35576bf810b885f1cb7017090e362e6cfcd04f2efb82cf66eee3cbd/Validity%20of%20the%20file.png?cb=c0490b7d9d9b3be46dad4d4a8162da1f)

*Validity of the file*

##### What Happens When a File Expires?

When a user opens a file that has reached its expiration date in their current time zone, the labeled file cannot be opened. HaloCAD will prompt a message "Y*ou don't have permissions to open some of the selected files* ". This behavior is like unauthorized file access, as described in the section "[Example 3: Unauthorized User Access](https://help.secude.com/halocad-add-on-for-autodesk-autocad/2.4/ac-operations-manual.md#EX3)".

##### How to Open an Expired File

Recipients cannot open an expired file. Only the file author can access it. If a recipient needs continued access, they must contact the author to obtain a new copy of the file with an updated expiration date.

#### Example 9: Remove protection from a file

To remove a label from a protected file, you must either be the file's owner or have full permission to remove protection.

#### Example 10: Revoke a File

Prerequisite: Ensure that the user who wants to revoke a file has the required license, as specified in the Release Notes under the Requirements section.

Revoke Feature: MPIP provides a revoke feature that prevents any new access attempts to a protected file, restricting access to all users except the author. Note that revoking access removes permissions for all users associated with that label.

##### Why Should a User Revoke a File?

A user may revoke access to a sensitive file if it was sent by mistake, accessed from a suspicious location, leaked, or if a recipient no longer requires access. In these scenarios, the author can immediately prevent further access by revoking the file. Note: Revoking does not delete the shared file, but users will no longer be able to open it. The **Revoke Access** button is available on the HaloCAD status screen.

##### How to Revoke a File?

1. To revoke a file, go to the **HaloCAD** tab \> click **Status** \> click the **Revoke Access** button. The following message will appear:

   ![Revoke access message #1.png](https://help.secude.com/__attachments/a_43ba3df0b9319ca68085d73af68d020ec82289c328db127b678c4959867890d0/Revoke%20access%20message%20%231.png?cb=51c8998b67075201935be33ed83b4c2f)

   *Revoke access message #1*
2. Click **Yes** to confirm revoking access and continue with [step 3](https://help.secude.com/halocad-add-on-for-autodesk-autocad/2.4/ac-operations-manual.md#step3). If you do not have the required license, it is not possible to revoke a file. In this instance, HaloCAD will show the alert as follows:

   ![Access denied revoking a file.png](https://help.secude.com/__attachments/a_16ef80c72cb8acb137e6b48d6af089c60b663d32be6b4b91872478392f4544ef/Access%20denied%20revoking%20a%20file.png?cb=e2a9924b8dba65269658ec6783c74c90)

   *Access denied when revoking a file*
3. The following message will appear:

   ![Revoke access message #2.png](https://help.secude.com/__attachments/a_76b2827caada2bc4f982a64a9251aeb6ee2353c460d159e79d7c24a69943f3ac/Revoke%20access%20message%20%232.png?cb=bfac01b6888ee49f02b235b865f633b6)

   *Revoke access message #2*
4. Click **OK** and save the file.

**Result:**

* Access to the file is revoked.

* Users who previously had access to the document can no longer open it.

##### **What Happens if a User Attempts to Open the Revoked File?**

Once the file is revoked, the user cannot open it, although the user has accessed it before. HaloCAD shows a generic message as "*You don't have permissions to open some of selected files."* This behavior is like unauthorized file access, as described in the section "[Example 3: Unauthorized User Access](https://help.secude.com/halocad-add-on-for-autodesk-autocad/2.4/ac-operations-manual.md#EX3)".  
**MIP SDK**

A revoked file can be accessed by the same user if it was previously opened by the same user in the same HaloCAD session. This is due to the actual behavior of the MIP SDK if you have defined the sensitivity label with the two options **Allow offline access** and **Users have offline access to the content for this many days**, the configured offline access allows users to continue to access the revoked file until the offline policy period ends.

##### **What Happens if a User Changes the Label?**

Assume User A shares a sensitive file with User B.

**Case 1:** If User B makes copies of the original document, revoking file access by User A will also revoke all copies, since the label remains unchanged.

**Case 2:** If User A has not revoked access and User B (with full rights) changes the label, revoking file access will not apply to that modified copy. However, the original document will still be revoked.

##### **How to Open the Revoked File?**

A recipient cannot open a revoked file. Only the file author can access it. If a recipient needs access, they must contact the author to obtain a new copy of the file.

### **Export Control Information (ECI) Feature**

The Export Control Information (ECI) feature helps you label files based on their classification.

**Prerequisite**

Ensure that two **MPIP label-only** labels named **Export Controlled Information** and **Not Export Controlled Information** are available in the Microsoft Purview portal.

**When is this feature available?**

The feature works only if the following labels are available in your HaloCAD session:

1. Export Controlled Information

2. Not Export Controlled Information

After fetching the labels, the add-on verifies their presence. If they exist, the ECI feature is enabled.

**What happens when you apply these labels?**

1. If you apply **Export Controlled Information**

   1. The title bar displays a red shield icon.

   2. The title bar shows the text "Export Controlled Information".

      ![ECI -1.png](/__attachments/a_099071582046dcc5dc4221a1800f606ae85238426432f44c72b4c3a72f23abce/ECI%20-1.png?cb=40c6a049def9ebd7669019ec89dec816)

      *Example -* *Export Controlled Information*
2. If you apply **Not Export Controlled Information**

   1. The title bar displays an empty shield icon.

   2. The title bar also shows the text "Not Export Controlled Information."

      ![ECI - 2.png](/__attachments/a_4d6339f5c0c76d62e702187ae1bb966da4549df39f5e7cb7bedd313ff1e9da48/ECI%20-%202.png?cb=a37f66dd0b3022ceda9f2c1ab1f4b9c2)

      *Example - Not Export Controlled Information*
3. If no label is applied (Not Set)

   1. The title bar displays an empty shield icon.

   2. The title bar shows the message: **Please Apply a Label**.

      ![ECI 3.png](/__attachments/a_6a814fafea65c0760f1262dcccfe8de6b73cf0e0121873fbcc7f45ca45ef85a4/ECI%203.png?cb=cfb60d141be77fa23549325ef3a309e5)

      *Example -* *Not Set*

## **Troubleshooting**

This chapter will help you overcome the most common problems with the HaloCAD solution.

### **Cannot Sign in to Microsoft Sign-In Assistant**

**Symptoms**

The user login fails with the following error message.  
![Error Message.png](https://help.secude.com/__attachments/a_3f8cd8e9ac2aac477481bd48bf548ea05fa27fc29376f818aeb8c5b8cab24e67/Error%20Message.png?cb=6d9b3e79084c244dd66b83c93336a910)

*Microsoft Sign-in error message*

**Background**

The above error occurs when a user logs in to a HaloCAD session using Microsoft Sign-In Assistant.

**Probable Cause**

As the Redirect URL specified in the request does not match the URL configured for the registered application, Microsoft Sign-in fails.

**Corrective Action**

1. **Case 1:** An incorrect Redirect URI was entered during the HaloCAD installation.

   1. Reinstall the HaloCAD Add-on using the correct **Redirect URI**.

   2. Launch the CAD application, click the pencil icon (**Click to change label**), and sign in using the Microsoft Sign-In Assistant.

2. **Case 2** : Redirect URIs use an improper scheme (such as `http://contoso.com`)

   1. Log in to the Microsoft Azure portal.

   2. On the home page, click the **Show Portal Menu** icon, then select **Microsoft Entra ID**.

   3. Under the **Manage** section on your tenant's **Overview** page, choose **App registrations**.

   4. Click **All Applications**, and enter your application name in the search bar.

   5. From the list, select your application.

   6. Click the **Redirect URIs** link or select **Authentication** from the **Manage**section on the application overview page.

   7. Verify that the reply URL begins with https://. If it does not, update it to https and save the changes.

      ![Incorrect Redirect URIs.png](/__attachments/a_3db53eaa9d2d1249fc1409ff8ce5bce5c2b0efd1a7e3f013b76f8f2e4d28992a/Incorrect%20Redirect%20URIs.png?cb=e53194da9917a03c5e13fc8432d01cf9)

      *Incorrect Redirect URIs*
   8. Now, sign in using the Microsoft Sign-In Assistant.

3. **Case 3**: Tenant ID provided for multi-tenant application

   1. Reinstall the HaloCAD Add-on without entering the **Tenant ID**.

   2. Open the CAD application, click the pencil icon (**Click to change label**), and sign in using the Microsoft Sign-In Assistant.

### **Labels are not Getting Downloaded in the HaloCAD Session**

**Symptoms**

The user could not download labels.

**Background**

The user logs in successfully in the HaloCAD session, but cannot download labels.

**Probable Cause**

Improper label configuration in the Microsoft Purview portal.

**Corrective Action**

1. Log in to the Microsoft Purview portal as a global administrator.

2. Ensure that the labels are configured to apply protection.

3. Verify that the user has the required policy to use the label.

4. For more details, refer to the Microsoft documentation.

### **Label not Found in the Policy**

**Symptoms**

HaloCAD prompts the following message:  
![Label not found.png](https://help.secude.com/__attachments/a_5948558703a849cd6d305e22a8828bdd7a0ca5e6c3443906f33ecd056102b113/Label%20not%20found.png?cb=42657b787053faa9668d2f34dee1ac87)

*Label not found error message*

**Background**

The above message is shown when you apply a label to a file and save it.

**Probable Cause**

Improper label configuration.

**Corrective Action**

Request your Microsoft Purview portal administrator to review the label and publish label policies.

### **Double Key Encryption Label could not be Applied**

**Symptoms**

HaloCAD prompts the following message:  
![Label could not be applied.png](https://help.secude.com/__attachments/a_b62f5ff7f5a64b9b5fcf67d89c38924c84be37fa9d48af904df400f9b2f7a15a/Label%20could%20not%20be%20applied.png?cb=a4d057352d6127ca811d925833449e95)

*DKE label error message*

**Background**

The above message is shown when you apply a Double Key Encryption (DKE) label to a file and save it.

**Probable Cause**

This issue occurs if the DKE service is stopped or unavailable.

**Corrective Action**

Make sure that the DKE service on the client's computer is active and accessible online.

### **Could not Connect to MPIP -- Case 1**

**Symptoms**

HaloCAD prompts the following message:  
![1_Azure RMS connection fails - wrong values.png](https://help.secude.com/__attachments/a_df9f4cfa6241b52f967706ef21199b90aa036231264a0f7162a4a1fd2b544fb8/1_Azure%20RMS%20connection%20fails%20-%20wrong%20values.png?cb=082ddb7cd5d607e89817b925614b8284)

*MPIP connection warning message #1*

**Background**

The above error occurs when a user logs in to the HaloCAD session via Microsoft Sign-In Assistant.

**Probable Cause**

This issue occurs if one or more of the following conditions are true:

1. **Case 1** : You have entered the incorrect **Application (client) ID** , **Directory (tenant) ID** , and **Redirect URI**.

2. **Case 2**: You have closed the Microsoft Sign-In Assistant dialog unknowingly.

**Corrective Action**

1. **Case 1** : Make sure the correct values of **Application (client) ID** , **Directory (tenant) ID** , and **Redirect URI** are entered during the initialization.

2. **Case 2**: Relaunch the application and enter user credentials in the Microsoft Sign-In Assistant dialog.

### **Could not Connect to MPIP -- Case 2**

**Symptoms**

HaloCAD prompts the following message:  
![2_Azure RMS connection fails- Network issue.png](https://help.secude.com/__attachments/a_1382ae7b8c6de54036d26285ab0cb2b43d055915ddbfcc03b9e019d083208490/2_Azure%20RMS%20connection%20fails-%20Network%20issue.png?cb=55d7256dc1db86eb2959362ef8f9b728)

*MPIP connection warning message #2*

**Background**

The above error occurs when a user logs in to the HaloCAD session via Microsoft Sign-In Assistant.

**Probable Cause**

The most likely cause of this issue is that your network is preventing you from connecting to Microsoft Purview Information Protection.

**Corrective Action**

1. Review yourfirewalls or network infrastructure to establish a connection with Azure.

2. Check if your proxy limits the URL.

### **HaloCAD Activation Fails**

**Symptoms**

HaloCAD prompts the following message:  
![Exceeded maximum activation.png](https://help.secude.com/__attachments/a_513ac43e917519b40615c4a2006d935566b96af9859d54b6bf19147ef68078fb/Exceeded%20maximum%20activation.png?cb=df5eb60ae6e98694e03d722487b3100f)

*HaloCAD Activation warning message*

**Background**

The above message is shown when you try to activate HaloCAD on a system.

**Probable Cause**

After a successful license activation, the license status changes to **Active** , and the **Total activations** count in Secude's License Server Manager increases by one. The total activation count increments with each activation.

For example, if you purchased ten HaloCAD licenses, you can activate HaloCAD up to ten systems. After the tenth activation, attempting to activate HaloCAD on another system will fail, and the License Server Manager will display an error indicating that the maximum number of activations has been reached.

**Corrective Action**

1. **Action 1:** Uninstall one or more HaloCAD add-ons that were previously activated on a CAD system, and then activate the license on the required CAD system.

2. **(Or) Action 2:** Purchase an additional HaloCAD license.

3. After completing the action, activate the license.

### **Incorrect License Key Error Message**

**Symptoms**

HaloCAD prompts the following message:  
![Incorrect license activation message.png](https://help.secude.com/__attachments/a_1cee58684f80868f8a2c2eb558aa6428f4382b299d51ab2d191306aed7e019aa/Incorrect%20license%20activation%20message.png?cb=cb267dc0092fe4945e1fb661682fcde4)

*Incorrect license activation message*

**Background**

The above message is shown when you try to activate HaloCAD on a system.

**Probable Cause**

There are various possible reasons, including a license key associated with another HaloCAD, an incorrect key, or an invalid key.

**Corrective Action**

Make sure to enter the correct licensing key, unique to this add-on, before activating it.

### **Why Am I Getting License Expiration Notifications?**

**Symptoms**

HaloCAD prompts the following message:  
![Prior message for expiration..png](https://help.secude.com/__attachments/a_f756971a7ca05baf8f7b229273091968a41686798c0b3667556bfd4761d73c5c/Prior%20message%20for%20expiration..png?cb=c97540b1f90a870ddaebd37429107c0b)

*HaloCAD notification*

**Background**

The above notification occurs once a day when a user logs into the HaloCAD session.

**Probable Cause**

When you run the CAD application and see a HaloCAD expiration alert, it means action is required to continue using the add-on.

Each license has an end date defined at the time of issue. When the license is within 30 days of expiry, the License Manager triggers daily notifications in HaloCAD. For example, if the license expires on September 30, 2028, notifications will begin appearing once per day starting September 1, 2028.

**Corrective Action**

1. Purchase a new HaloCAD license or renew the existing license.

2. Activate the license.

### **Other License-Related Error Messages**

|                 **HaloCAD License Error Messages**                  |                                     **Root Cause**                                     |                                                **Correction Action**                                                |
|---------------------------------------------------------------------|----------------------------------------------------------------------------------------|---------------------------------------------------------------------------------------------------------------------|
| The license validity period has expired                             | When your license had just expired.                                                    | Please contact Secude's representative to receive a new license.                                                    |
| The license is not enabled.                                         | When you try to activate a license key that is already disabled on the License portal. | Please contact Secude's representative to enable the license.                                                       |
| This device is blacklisted.                                         | When your device is blocked in the license portal for a specific reason.               | Please contact Secude's representative to enable the device.                                                        |
| This license cannot be activated before the start date: yyyy-mm-dd. | When attempting to activate a license before its start date.                           | Please make sure the license is activated on the start date.                                                        |
| Date header is not valid or set in past.                            | When the date or time on the machine is incorrect.                                     | Please make sure that the machine installed with the HaloCAD add-on is synchronized with the current date and time. |

*License-related error messages*

## Technical Support

Before contacting Technical Support, ensure that you have the following information available. Providing this information helps the support team investigate and resolve your issue more efficiently.

* Full contact details

* Product build version

* Date, time, and description of the error (include screenshots, if possible)

* Details of any third-party software used with the product

* Any additional information required to reproduce the issue

**Contact Technical Support**

Secude provides technical support through email [++support@secude.com++](mailto:support@secude.com). When contacting Technical Support by email, include your company details, a detailed description of the issue, and the relevant log files (if available). A support representative will respond to your inquiry.

**Additional Resources**

Visit the Secude website [++https://secude.com++](https://secude.com/) to learn about upcoming events, press releases, and to download white papers.

**Documentation Feedback**

Secude values your feedback and continuously strives to improve product documentation. To provide feedback, send an email to: [++documentation@secude.com++](mailto:documentation@secude.com)

Include the following details in your feedback:

* Product name and version

* Documentation topic

* Description of the suggestion or error

The technical documentation team reviews all feedback and incorporates relevant updates in future documentation releases.

---
version: "2.4"
language: "en"
---
# Release Notes

## Introduction

The release notes provide brief and high-level descriptions of the new features of HaloCAD. Before installing HaloCAD, it is recommended to read the release notes to understand any current limitations or bugs that may apply to this version of the software.

## Product Description

HaloCAD acts as the guardian of your CAD files by automatically protecting them with Microsoft Purview Information Protection (MPIP) labels whenever they leave your secure IT perimeter. As a plug-in for CAD applications, HaloCAD offers access to MPIP-protected files, including label handling and privilege enforcement. CAD users will not notice any differences in the handling of CAD files because protection takes place in the background. By seamlessly attaching MPIP labels to the CAD files while they are being created, it provides end-to-end security for those files.

## System Requirements

The following system requirements table specifies the minimum and recommended technical specifications, such as software and network resources, necessary to run the product.  

|       **Components**        |                                                                                                                                                               **Details**                                                                                                                                                                |
|-----------------------------|------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| Supported Operating Systems | Windows 11 or above with updates installed.                                                                                                                                                                                                                                                                                              |
| Supported file types        | 1. File types supported for Save and Open: `.dwg`, `.dxf`, `.dws`, `.dwt`, `.iges`, `.igs`, `.wmf`, `.sat`, and `.dgn(v7)` 2. File types supported for Export: `.dwf`, `.dwfx`, `.dwfx` (other format), `.stl`, `.dgn(v8)`, `.eps`, `.dxx`, `.pdf`, `.bmp`, `.png`, `.jpg`, and `.tif` 3. Import file types: `.step`, `.stp`, and `.ste` |
| Supporting application      | To view the encrypted PDF files, install the latest version of Acrobat Reader DC / Acrobat DC.                                                                                                                                                                                                                                           |

*Requirements*

**Supported Autodesk applications for HaloCAD Add-ons**

You are currently viewing the release notes for the current build. For previous versions, please refer to their respective release notes.  

|                                               **CAD applications**                                               | **HaloCAD Add-on version** |
|------------------------------------------------------------------------------------------------------------------|----------------------------|
| 1. AutoCAD 2024, 2025, 2026 2. AutoCAD Electrical/Mechanical/MEP/Civil 3D/Plant 3D: 2024, 2025, 2026             | 2.4                        |
| 1. AutoCAD 2023, 2024, 2025, 2026 2. AutoCAD Electrical/Mechanical/MEP/Civil 3D/Plant 3D: 2023, 2024, 2025, 2026 | 2.3                        |
| 1. AutoCAD 2023, 2024, 2025 2. AutoCAD Electrical/Mechanical/MEP/Civil 3D/Plant 3D: 2023, 2024, 2025             | 2.1, 2.2                   |

*Autodesk applications and HaloCAD Add-on*

## Prerequisites

Before installing the add-on, ensure that the following prerequisites are met:

1. An application is registered with Microsoft Entra ID.

2. An active Office 365 subscription is available.

3. Access to the recommended URLs is enabled.

4. TLS 1.2 or later is enabled on all client workstations to ensure secure communication.

For more information, refer to the **Technical Reference Manual**.

## Code Quality and Security

Secude focuses on software quality and security. This is accomplished by adhering to and exceeding best practices in development, testing, and quality control. Secude has chosen SonarQube as the first building block for building and implementing a robust continuous code quality assurance (QA). SonarQube is a platform for static code analysis for continuous inspection of code quality. It performs automatic reviews of code to detect bugs, code smells, unit test coverage, and security issues in 29 programming languages.

SonarQube is utilized throughout the development process at Secude, and only the highest marks are accepted for a product to be released. It helps to regulate code quality from the beginning of development, find and repair issues promptly, and improve overall software stability.

Each build report can be found under its relevant version heading in this release notes.

**Reliability Rating**

1. A = 0 Bugs

2. B = at least 1 Minor Bug

3. C = at least 1 Major Bug

4. D = at least 1 Critical Bug

5. E = at least 1 Blocker Bug

**Security Rating**

1. A = 0 Vulnerabilities

2. B = at least 1 Minor Vulnerability

3. C = at least 1 Major Vulnerability

4. D = at least 1 Critical Vulnerability

5. E = at least 1 Blocker Vulnerability

**Security Review Rating**

The Security Review Rating is a letter grade based on the percentage of Reviewed (Fixed or Safe) Security Hotspots.

1. A = \>= 80%

2. B = \>= 70% and \<80%

3. C = \>= 50% and \<70%

4. D = \>= 30% and \<50%

5. E = \< 30%

**Maintainability Rating**

A=0-0.05, B=0.06-0.1, C=0.11-0.20, D=0.21-0.5, E=0.51-1

The Maintainability Rating scale can be alternatively stated by saying that if the outstanding remediation cost is:

1. \<=5% of the time that has already gone into the application, the rating is A

2. Between 6 to 10%, the rating is a B

3. Between 11 to 20%, the rating is a C

4. Between 21 to 50%, the rating is a D

5. Anything over 50% is an E

## Build 2.4

### New Features

This section lists the new features in the current release.

Added support for AutoCAD integration with Teamcenter. HCADACD-746

### Improvements

This section lists the improvements in the current release.

1. In previous releases, asterisks were used in MIP SDK logs to mask Personally Identifiable Information (PII), such as email names and IP addresses. This feature is now extended to HaloCAD logs to also mask information such as label name, label ID, engine ID, policy ID, and watermark text. HCADACD-686

2. Added default values for silent command-line parameters. HCADACD-729

3. Added support to display online documentation directly from the installer UI for both the standard and Reader add-on installers. When the **Online Help** button is clicked, the online documentation now opens in the user's default browser. HCADINV-730

4. Improved token-sharing encryption and FIPS compatibility by ensuring proper OpenSSL FIPS context initialization and preventing failures in child processes during configuration decryption. HCADACD-738

### Fixed Issues

This section lists the fixed issues in the current release.

1. Fixed an issue where the `enable_fips` registry flag remained set to true even after the **Enable FIPS Mode** option was unchecked in the installer and did not revert to false. HCADACD-731

2. Fixed an issue where STL and PDF files were exported as protected files despite restricted permissions, and files were created on disk even after a warning message was displayed. HCADACD-770

### Known Issues

This section lists the known issues in the current release.

1. Reader: Intermittently, the AutoCAD application will crash when you open a protected file with an unauthorized user account via a recent document list. HCADACD-333

2. Even if the user cache already exists after installation, the Microsoft sign-in dialog will still appear when you close and restart the AutoCAD application. HCADACD-473

3. When attempting to import the protected DGN file into the drawing file, the error message "*You have selected an unsupported DGN file*." will appear. HCADACD-486

4. If a protected file is opened from Recent documents or using the **Open** option in the start window, a pop-up message from AutoCAD will be displayed as "*Drawing file is not valid*" and the file will not open when Startup is set as 2 and Startmode is set as 0 or 1. HCADACD-534

### Unsupported Versions

Support for AutoCAD 2023 has been removed in this release.

## Quality Gate Report

Please see the table below for a list of SonarQube's key parameters for this version. Refer to the "[Code Quality and Security](https://help.secude.com/halocad-add-on-for-autodesk-autocad/2.4/ac-release-notes.md#code)" section for more information on rating definitions.  

|         **Metric**         | **Value** |
|----------------------------|-----------|
| Coverage                   | 85.5%     |
| Maintainability Rating     | A         |
| Reliability Rating         | A         |
| Security Hotspots Reviewed | A         |
| Security Rating            | A         |

*Quality Gate report*

---
version: "2.4"
language: "en"
---
# Technical Reference Manual

## Introduction

Companies across industries, such as automotive, aviation, and high tech, create and manage their intellectual property (IP) based on drawings. These drawings are created digitally using computer-aided design (CAD) applications and are shared with users outside the organization owing to business considerations. It's essential to understand the potential risks associated with sharing business information. Comprehensive security measures are essential to reducing risks and safeguarding sensitive data. HaloCAD, a purpose-built data protection solution, is designed to help organizations achieve this objective effectively.

### How does HaloCAD protect your Data?

HaloCAD effortlessly integrates Microsoft Purview Information Protection (MPIP), formerly known as Microsoft Information Protection (MIP), the leading technology for Enterprise Digital Rights Management (EDRM). It acts as a shield for your CAD files by automatically labeling them with MPIP and manages data assets across your environment. HaloCAD modules can be used either in standalone mode or in combination with HaloCAD for PLM, which automatically protects file downloads, decrypts files during upload, and returns them to the PLM vault.  
![HaloCAD's high-level architecture.png](https://help.secude.com/__attachments/a_e0c6dc85975a3eebe4fb58e1dfc45e6e6f3242ea3932100dfed527f586b3b764/HaloCAD's%20high-level%20architecture.png?cb=9a10e8622ee0fddb28499b27d61f4613)

*HaloCAD Add-on for CAD applications*

### About this Manual

This manual provides administrators with the information required to successfully deploy HaloCAD components. It explains how to set up the HaloCAD environment, describes the overall architecture, lists the prerequisites and system requirements for each component, and offers step-by-step guidance for installation and configuration. The manual covers the HaloCAD Add-on for CAD, the HaloCAD Reader Add-on for CAD, HaloCAD for Viewers, HaloCAD for TCAI, and HaloCAD for PLM and PDM, along with detailed explanations to ensure smooth implementation and usage.

The term **HaloCAD Add-on for CAD** is a generic reference to the supported CAD applications, namely AutoCAD, Inventor, Revit, Creo, Solid Edge, NX, SOLIDWORKS, and DraftSight. Throughout this manual, any reference to this term denotes these supported CAD applications. Additionally, the HaloCAD Add-on for CAD includes a corresponding reader add-on for each of the above-listed applications, which is collectively referred to by the generic term **HaloCAD Reader Add-on for CAD**.

The term **HaloCAD for PLM** is a general reference to the supported PLM applications, namely Teamcenter, Windchill, and Autodesk Vault. Wherever this term appears in the manual, it denotes these supported PLM systems. Similarly, references to **HaloCAD for PDM** correspond to SOLIDWORKS PDM.  
This is the primary document that administrators should read before installing the HaloCAD components. After completing this, proceed with the installation and operations manuals.

### Features

1. **Business infrastructure**: HaloCAD connects effortlessly with existing infrastructure, making it simple to use and manage.

2. **CAD:**HaloCAD add-on seamlessly extends MPIP security to CAD files.

3. **Usage rights**: Applies label-based protection using Microsoft Purview Information Protection (MPIP) and user-defined custom permissions.

4. **Data security**: Sensitive information is protected persistently regardless of where it is moved, including mobile and cloud platforms.

5. **Data Access and Usage**: Policy enforcement for managing sensitive file access and usage.

   1. Policies specify who has access to sensitive files and what actions they can do with them.

   2. Furthermore, it specifies how data may be used, such as restrictions on viewing, editing, copying, printing, exporting, relabeling, or modifying the rights. Watermarks can be applied to documents that contain sensitive information.

6. **Seamless integration with PLM**: Automatically protects file downloads, decrypts files during upload, and returns them to the PLM vault.

## Quick Start Installation Summary - Standalone HaloCAD Add-on

The image below illustrates the high-level process of setting up the HaloCAD Add-on for CAD.  
![TechReference_Quick start - standalone .png](https://help.secude.com/__attachments/a_1a214678ab8e105455c40d87716c83e0f1b869fbb5408df14e4caa7d7cd302f7/TechReference_Quick%20start%20-%20standalone%20.png?cb=f5ead24b2b28007828631bad33621938)

*Quick start installation steps for HaloCAD Standalone Add-on*  
![TechReference_Quick Start Reader Add-on.png](https://help.secude.com/__attachments/a_708b0b4efc5cb13323dec6fabbaaca5c185f9433c3f0d02743fd8c034b07ffe0/TechReference_Quick%20Start%20Reader%20Add-on.png?cb=e990f5d975398e57f2c86678eac3c685)

*Quick start installation steps for HaloCAD Reader Add-on*

**Reference Manuals**

The table below describes where to obtain information in the HaloCAD documentation set.  

|                                                                                **For information on**                                                                                |                   **Name of the Reference**                    |
|--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|----------------------------------------------------------------|
| 1. Prerequisites, architecture, and supported license activation methods 2. Secure installation using an encrypted JSON configuration file 3. Actions to take when a license expires | Please refer to the current manual.                            |
| HaloCAD Installation Options -- UI, Silent, and SCCM                                                                                                                                 | Refer to the Installation Manual for the add-on you purchased. |
| HaloCAD features, operations, and troubleshooting, if you face any issues                                                                                                            | Refer to the Operations Manual for the add-on you purchased.   |
| Overview of new features, resolved issues, known issues, and supported file types                                                                                                    | Refer to the Release Notes for the add-on you purchased.       |

*HaloCAD standalone add-on reference documentation*

## Quick Start Installation Summary - Integrated with PLM/PDM

The image below illustrates the high-level process of setting up the **HaloCAD Add-on for CAD** with **HaloCAD for PLM/PDM** environment.  
![TechReference_Quick start_PLM-PDM.png](https://help.secude.com/__attachments/a_3d224192dd3b2d81648f6b486dac8eef522b8106d70d0dad38648cb3571ddaac/TechReference_Quick%20start_PLM-PDM.png?cb=f1f21476c16f52782f2d7c44f25661e8)

*Quick start installation steps for HaloCAD for PLM/PDM*

**Reference Manuals**

The table below describes where to obtain information in the HaloCAD documentation set.  

|                        **For information on**                         |                          **Name of the Reference**                          |
|-----------------------------------------------------------------------|-----------------------------------------------------------------------------|
| Step 1 -- Registering an Application in Entra ID.                     | Please refer to the current manual.                                         |
| Step 2 -- How to install HaloCAD Add-on for CAD.                      | Refer to the Installation Manual for the add-on you purchased.              |
| Step 3 -- How to install HaloENGINE.                                  | `HaloENGINE_Manual_Installation_EN_Online.pdf`                              |
| Step 4 -- How to install HaloCAD for PLM/PDM.                         | Refer to the Installation Manual for the HaloCAD for PLM/PDM you purchased. |
| Step 5 and Step 6 -- Workflow illustrating protection and decryption. | Refer to the Operations Manual for the HaloCAD for PLM/PDM you purchased.   |

*HaloCAD for PLM/PDM reference documentation*  
**About the Term "HaloENGINE Tomcat Service"**

The HaloENGINE Tomcat Service is a common component used in both the HaloENGINE and HaloCAD products. Since it was initially developed for HaloENGINE and later adopted across HaloCAD, all Tomcat instances in Secude appear under the name "HaloENGINE Tomcat Service."

## Quick Start Installation Summary - HaloCAD for Viewers

The image below illustrates the high-level process of setting up HaloCAD for Viewers.  
![TechReference_Quicl Start - Viewers.png](https://help.secude.com/__attachments/a_e6871fe35ce1526f5652749c8f2468d7f367b491bcd7a485ac9c9316629d25cb/TechReference_Quicl%20Start%20-%20Viewers.png?cb=8eae1af140d7e0e42c619971fa5a0bf6)

*Quick start installation steps for HaloCAD for Viewers*

For HaloCAD for TCAI, follow the same Quick Start installation steps described for HaloCAD for Viewers. Refer to the HaloCAD for TCAI documentation set for additional information.

**Reference Manuals**

The table below describes where to obtain information in the HaloCAD documentation set.  

|                                                                                **For information on**                                                                                |                  **Name of the Reference**                  |
|--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|-------------------------------------------------------------|
| 1. Prerequisites, architecture, and supported license activation methods 2. Secure installation using an encrypted JSON configuration file 3. Actions to take when a license expires | Please refer to the current manual.                         |
| Installation Options -- UI, Silent, and SCCM                                                                                                                                         | `HaloCAD_Viewers_Manual_InstallationAndUsage_EN_Online.pdf` |
| Overview of new features, resolved issues, known issues, and supported file types                                                                                                    | `HaloCAD_Viewers_ReleaseNotes_EN_Online.pdf`                |

*HaloCAD* *for Viewers reference documentation*

## HaloCAD Architecture

The architecture is designed to provide secure and efficient management of CAD and PLM data through three core components: HaloCAD Add-on for CAD, HaloCAD for PLM, and the HaloENGINE.

### HaloCAD Add-on for CAD

A standalone solution that contains the HaloCAD PROTECT feature. It enables access to protected files, enforces associated privileges, and allows controlled modification of MPIP labels via direct interaction with the user.

HaloCAD Add-on for CAD leverages the Microsoft Purview Information Protection solution to provide persistent document security. During the process of creating a new CAD file, the user downloads MPIP labels using valid credentials, selects a suitable label, and applies it to the file. In the standalone add-on, no automation is available, as setting labels is done manually. Protected files can only be opened and modified by authorized users, and thus, protection remains even when multiple users access the file. The user's rights are governed by pre-established policies. The following figure shows the HaloCAD Add-on for CAD as a standalone add-on.  
![TechReference_Fullmode.png](https://help.secude.com/__attachments/a_7b8d0cd6cec298ed606939473c1ad1c344fd25f6d63ae006082f269c0960368e/TechReference_Fullmode.png?cb=5de7b834c5831259fd3ce9a53184fccc)

*HaloCAD as a standalone add-on*

Note: When HaloCAD (standalone add-on) is integrated with HaloCAD for PLM, files are automatically protected based on predefined rules before the end user can access them.

### HaloCAD Reader Add-on for CAD

Secude offers a standalone reader add-on for CAD applications that lets you view MPIP-protected files containing sensitive data. It enforces 'read-only' privileges to all users and thus even authorized users cannot sneak sensitive information out by copying it or taking a screenshot. Additionally, it does not support the setting or modification of labels. Note: When a HaloCAD MPIP-protected file is shared with partners/suppliers, they don't need to install the HaloCAD Add-on for CAD on their machines; instead, just this simple reader add-on is sufficient. The following figure shows the HaloCAD Reader Add-on for CAD.  
![TechReference_Readermode.png](https://help.secude.com/__attachments/a_aacb15604b238a5e36f21acf0c0155e3fe023410959450ce30d8be19b4ad5098/TechReference_Readermode.png?cb=6f97dfb6cc11eb8a240f43c05257c24a)

*HaloCAD Reader Add-on for CAD*

### **HaloCAD for PLM**

**HaloCAD for PLM (HaloCAD for Teamcenter, HaloCAD for Windchill, and HaloCAD for Autodesk Vault)**

This solution integrates seamlessly with the PLM application, including the features of HaloCAD PROTECT and HaloCAD MONITOR, while utilizing Microsoft Purview Information Protection (MPIP), formerly Microsoft Information Protection (MIP), to provide Enterprise Digital Rights Management (EDRM) capabilities.

HaloCAD for PLM operates continuously in the background, monitoring file uploads and downloads. It connects to Microsoft Purview Information Protection to download sensitivity labels and handle file encryption and decryption.

During a file upload, it checks whether the file is already encrypted and, if so, automatically decrypts it before allowing it to be checked into the PLM Vault. Similarly, whenever a file is downloaded, HaloCAD for PLM automatically enforces protection in accordance with defined action rules, ensuring that all file operations adhere to security rules and keep data safe. It operates independently during the file check-in or upload process. However, during file check-out or download, it depends on the rules defined in the Classification Engine (HaloENGINE).  
![TechReference_HaloCAD for PLM.png](https://help.secude.com/__attachments/a_94826edfc0f4adddb125867173a68e96e9827cf93331f2ef224fb92716eb0889/TechReference_HaloCAD%20for%20PLM.png?cb=0d6e3f609ae3d060a06c2d2cb11caf40)

*HaloCAD for PLM*  
**Separate Installation Requirement**

Ensure that HaloENGINE and HaloCAD for PLM are installed and configured separately on Windows servers.

**HaloENGINE**---A Java-based classification engine that implements the business logic of the architecture. It integrates with Microsoft Purview Information Protection to download sensitivity labels and make them available for configuration. HaloENGINE uses metadata to classify and organize data, and it also enforces classification schemas and action rules. All file downloads must comply with the rules defined in this engine, making it the central component of the architecture.

During file download, HaloENGINE receives relevant metadata from HaloCAD for PLM, determines the appropriate action based on the configured rules, and forwards the label and action information to HaloCAD for PLM for file processing (encryption).

**HaloCAD for PDM (HaloCAD for SOLIDWORKS PDM)**

This solution integrates HaloCAD PROTECT and MONITOR capabilities with the respective PDM application. It connects to Microsoft Purview Information Protection to download sensitivity labels and handle file encryption and decryption.

SOLIDWORKS PDM folders are actively monitored to ensure file security and compliance. When files are cut or copied from a SOLIDWORKS PDM folder to a non-SOLIDWORKS PDM folder, they are automatically intercepted and protected before reaching the destination. Conversely, when previously encrypted SOLIDWORKS application files or PDF files are copied or moved into a SOLIDWORKS PDM folder, they are seamlessly decrypted and saved for use within the environment.

**HaloENGINE**---A Java-based classification engine that implements the business logic of the architecture. As described in HaloCAD for PLM, it provides similar functionality when integrated with PDM.

All file copy/move must comply with the rules defined in this engine, making it the central component of the architecture.  
![TechReference_HaloCAD for PDM.png](https://help.secude.com/__attachments/a_5d4897ce4ce2ba6e58bd8bfa8be8f6c50b61b6077957d6fdf63afb5c895e0de8/TechReference_HaloCAD%20for%20PDM.png?cb=18b66a80ae43cda05837e7c3713efbc8)

*HaloCAD for PDM*

For comprehensive details, please refer to the respective manuals as per your PLM environment:

1. If your environment is integrated with Windchill PLM, refer to the HaloCAD for Windchill Installation Manual.

2. If your environment is integrated with Teamcenter PLM, refer to the HaloCAD for Teamcenter Installation Manual.

3. If your environment is integrated with Autodesk Vault PLM, refer to the HaloCAD for Autodesk Vault Installation Manual.

4. If your environment is integrated with SOLIDWORKS PDM, refer to the HaloCAD for SOLIDWORKS PDM Installation Manual.

### HaloCAD for Viewers

HaloCAD for Viewers is a lightweight application designed to view HaloCAD-protected files in other CAD-Viewer applications with "View only" access to all users who have access to it. This application is useful for suppliers or partners who need to access HaloCAD-protected models or drawings in their environment. The high-level architecture of HaloCAD for Viewers is illustrated in the following figure.  
![TechReference_Arch of Viewers.png](https://help.secude.com/__attachments/a_29394aa446339fad82d772cde6bc6a79f146bcb3436797b39c6766444a67434f/TechReference_Arch%20of%20Viewers.png?cb=4adc86590e461620ae6eb174a6cf3542)

*HaloCAD for Viewers*

### HaloCAD for TCAI

HaloCAD for TCAI is a lightweight application that uses Microsoft Purview Information Protection functionality to decrypt HaloCAD-protected CAD files during bulk loading operations in Teamcenter integration with Autodesk Inventor. This enables protected Inventor files to be scanned and processed by the TCAI Bulk Loader.

The Teamcenter Integration for Autodesk Inventor (TCAI) Bulk Loader utility allows administrators to automatically import large numbers of Inventor files into Teamcenter. However, when Inventor files are protected (encrypted), the Bulk Loader cannot recognize or process them directly.

By decrypting protected files during the loading process, HaloCAD for TCAI enables the Bulk Loader to scan and load these files into Teamcenter.

HaloCAD for TCAI uses the same underlying decryption mechanism as HaloCAD for Viewers, but it is specifically designed to support bulk loading operations in the TCAI environment.  
![TechReference_HaloCAD for TCAI.png](https://help.secude.com/__attachments/a_b680f555cea2bd2768e440ba405ee066d90c972feb4b153c256fe84ade9424d0/TechReference_HaloCAD%20for%20TCAI.png?cb=23775ea43d43cd8812d96d5b1490f7bc)

*HaloCAD for TCAI*

**Microsoft Purview Information Protection**

HaloCAD seamlessly integrates with Microsoft Purview Information Protection solution to protect your sensitive documents. Microsoft Purview Information Protection is an industry-standard document security solution that enables businesses to ensure only authorized users can open protected content while also regulating what they can do with it, such as print, edit, or save. Even if sensitive data is leaked accidentally or maliciously, unauthorized parties cannot view it in clear text, thus leaving it useless.  
**Microsoft documentation**

This manual assumes that you already have a complete Microsoft Purview Information Protection setup and are familiar with using the Microsoft Purview portal and related concepts. If you are new, you can refer to Microsoft's online documentation for setup and configuration.

## Prerequisites

The prerequisites and dependencies for installing and configuring the HaloCAD add-ons are summarized in this section.

### Register an Application in Microsoft Entra ID - **Public client/native**

|-------------------|-------------------------------------------------------------------------------------------------------------------------------------|
| **Applicable to** | 1. HaloCAD Add-on for CAD 2. HaloCAD Reader Add-on for CAD 3. HaloCAD for Viewers 4. HaloCAD for TCAI 5. HaloCAD for SOLIDWORKS PDM |

This section will guide you through registering an application, obtaining the Client ID and Directory ID, and assigning permissions to the application.  
**Microsoft documentation**

Registering an application in Microsoft Entra ID establishes a trust connection between your application and the identity provider, the Microsoft identity platform.

The information in the Microsoft documentation overrides any information published in this section. For a comprehensive description, refer to Microsoft documentation.

#### Create an Application

Follow the instructions below to register an application:

1. Log in to the [Microsoft Entra admin center](https://entra.microsoft.com/) using an account that has administrator privileges.

2. If you have access to multiple tenants, click the **Settings** icon in the top menu and select the tenant for which you want to register the application from the **Directories** + **subscriptions**menu.

3. You will be directed to the homepage.

   ![0_Intial Screen.png](https://help.secude.com/__attachments/a_94454acb9918f0d45b61e09b74c25b2b7bc3a16f3f3d3ebd6685fab1d7ee1678/0_Intial%20Screen.png?cb=7474bc6a49931803f8de1518c0a94eca)

   *Selecting Microsoft Entra ID*
4. Click **Identity** \> **Applications** \> **App registrations**on the left of the navigation pane.

5. On the **App registrations** page, click the **New registration** page or **Register an Application** button (this button appears only if no applications have already been created).

   ![1_New application registration.png](https://help.secude.com/__attachments/a_47b060a2c8c354177bf85d08228e3fe83f8cc631db0bb433a0f90838bb669b67/1_New%20application%20registration.png?cb=5ea4d32fc9fa86b48bc627cd26dbcd0e)

   *New application registration*
6. On the**Register an application** page, enter the registration details for your application.

   ![2_Public client application details.png](https://help.secude.com/__attachments/a_fa6c0eec13d1673cff7e2b317bea526531f38ca72f9a79eedc4d3a27904dc9c9/2_Public%20client%20application%20details.png?cb=14ea97df2b8462fe456b3cb6a27dac4f)

   *Application details*
7. In the **Name**field, enter an appropriate application name.

8. Under **Supported account types**, select which account you would like your application to support. For detailed information on these types, please see Microsoft documentation.

   1. To target only accounts that are internal to your organization, select **Accounts in this organizational directory only**.

   2. To target only business or educational customers, select **Accounts in any organizational directory**.

   3. To target the widest set of Microsoft identities and to enable multitenancy, select **Accounts in any organizational directory and personal Microsoft accounts**.

   4. To target the widest set of Microsoft identities, select **Personal Microsoft account only**.

   5. Under **Redirect URI** : Select **Public client/native (mobile \& desktop)** , and then type a valid redirect URI for your application. For example, `https://localhost`.

   6. When finished, click **Register**.

9. The home page of the new application is created and displayed.

   ![3_Application ID and Tenant ID.png](https://help.secude.com/__attachments/a_97facd7d01233b08cc5be672d92bc4e5dd701df8c2fcb08e6efc666beffa86e3/3_Application%20ID%20and%20Tenant%20ID.png?cb=2d09547b6b78d6efbbceb666e67608ee)

   *Application ID and Tenant ID*
10. Once registration is complete, the following values are shown on the portal. To copy and save the ID value in a text editor, hover your cursor over it and click the **Copy to clipboard**icon.

    1. **Application ID** -- also known as **Client ID**.

    2. **Directory ID** -- also known as **Tenant ID**.

**Save the authentication parameters**

Open a text editor (such as Notepad) and copy the values for the Application (client) ID, Directory (tenant) ID, and Redirect URI. Save these details for initializing the HaloCAD Add-on. Note that the Directory (tenant) ID is required only for single-tenant applications.

#### Add Required Permissions

To protect content using the MIP SDK, you need to provide the following API permission(s) for the created application ID.

1. In the sidebar of the new application page, select **API permissions** . The **API permissions** page for the new application registration will appear.

2. Click **Add a permission** button. The **Request API permissions** page will appear.

3. Under the **Select an API**setting, select APIs my organization uses. A list appears, containing the applications in your directory that expose APIs.

4. Type in the search box or scroll to find the required API that is mentioned in the table below, "Required Permissions".

5. For example, type **Microsoft Information Protection Sync Service**. You can see the API listed as shown in the figure below:

   ![4_API selection.png](https://help.secude.com/__attachments/a_cefa5f6883db47c25b1f3718f9547fde52f114d15923a78605ad64fc50e7d1bc/4_API%20selection.png?cb=60328777c1eb9f0880eb1267645ecb5d)

   *Searching for permissions*
6. Now, click on the displayed API. You can see two permissions on the page − **Delegated permissions** and **Application permissions**.

7. Click the **Delegated permissions** button and then, under the **Permission**section, select the check box against "Read all unified policies a user has access to".

   ![5_Adding permission.png](https://help.secude.com/__attachments/a_48faca230da95309883ad545bbb11e4a6110480676dca3cda0682a86f203acd5/5_Adding%20permission.png?cb=dbc6f87482218efd202793dde05cdce6)

   *Adding permission*
8. Click **Add permissions**. Repeat the steps outlined above to add the other required permissions listed in the table below.

9. You will return to the API permissions page, where the permissions have been saved and added to the table. Please note that administrator consent is not necessary for **Delegated permissions**.

   ![6_Required API Permissions.png](https://help.secude.com/__attachments/a_cabae2621e22426db46a0196e86330009116112ab73fe1c6e8859ac1e453b655/6_Required%20API%20Permissions.png?cb=66ea7fcb1dd8aa1087252334a951ab69)

   *API Required permissions*
10. The following table lists the required permissions.

|                        **API / Permission name**                        |     **Display Name**      | **Type**  |                     **Description**                      |
|-------------------------------------------------------------------------|---------------------------|-----------|----------------------------------------------------------|
| Azure Rights Management Services (Microsoft Rights Management Services) | `User_impersonation`      | Delegated | Create and access protected content for users            |
| Microsoft Graph                                                         | `User.Read`               | Delegated | Sign in and read user profile (will be added by default) |
| Microsoft Information Protection Sync Service                           | `UnifiedPolicy.User.Read` | Delegated | Read all unified policies a user has access to.          |

*Required permissions*

### **Register an Application in Microsoft Entra ID - Web**

|-------------------|----------------------------------------------------------------------------------|
| **Applicable to** | 1. HaloCAD for Teamcenter 2. HaloCAD for Windchill 3. HaloCAD for Autodesk Vault |

Creating an application in Microsoft Entra ID is similar to the steps in the previous section. However, for HaloCAD for PLM, some variations apply.

1. Under **Redirect URI** , select **Web**.

2. Add the permissions listed in the following table.

3. Click **Grant admin consent for your** *\<company\>*.

4. When the confirmation dialog appears, select **Yes** to approve.

5. After the consent is granted, the **Status** column changes to **Granted**.

|                        **API / Permission Name**                        |      **Display Name**       |  **Type**   |                                                         **Description**                                                          |
|-------------------------------------------------------------------------|-----------------------------|-------------|----------------------------------------------------------------------------------------------------------------------------------|
| Microsoft Graph                                                         | `User.Read`                 | Delegated   | Sign in and read the user profile. This API permission is added by default, but it is not used by the HaloENGINE Tomcat Service. |
| Azure Rights Management Services (Microsoft Rights Management Services) | `Content.DelegatedWriter`   | Application | Create protected content on behalf of a user                                                                                     |
| Azure Rights Management Services (Microsoft Rights Management Services) | `Content.Writer`            | Application | Create protected content                                                                                                         |
| Microsoft Information Protection Sync Service                           | `UnifiedPolicy.Tenant.Read` | Application | Read all unified policies of the tenant                                                                                          |

*Required permissions #1*

#### **Additional Permission (Only for Decryption)**

The permissions mentioned above are adequate for applying the MPIP label to a file with the owner as SPN (Service Principal Name) ID or any user email ID. Additionally, the HaloENGINE Tomcat Service requires the following superuser privilege for the decryption function when the owner is not as SPN.  

|                        **API / Permission Name**                        |  **Display Name**   |  **Type**   |                        **Description**                         |
|-------------------------------------------------------------------------|---------------------|-------------|----------------------------------------------------------------|
| Azure Rights Management Services (Microsoft Rights Management Services) | `Content.SuperUser` | Application | Read all protected content for this tenant in the Azure portal |

*Required permissions #2*

#### Upload the Certificate in the Azure Portal

The HaloENGINE Tomcat Service relies on certificate-based authentication to access MPIP services. Therefore, you must enter your certificate information in the registered application before proceeding with the configuration.

Prerequisites:

1. **Certificate**:

   1. Ensure that you have a valid certificate containing the following key properties: `-KeyExportPolicy Exportable` and `-KeySpec Signature`.

   2. The certificate can also be self-signed. Note: As a best practice and for security reasons, use a self-signed certificate only in a test environment. It is not recommended for production environments.

2. **Local Computer** certificate store: The certificate required for MPIP authentication must be installed in the Local Computer certificate store, along with the Root CA and Intermediate CA certificates.

   1. If the certificate is CA-signed, install all related certificates in their respective stores (Root, Intermediate, and Personal).

   2. If the certificate is self-signed, install it in both the Trusted Root Certification Authorities and Personal stores of the Local Computer.

To upload the public key of the certificate, follow the steps below:

1. In the sidebar of the new application page, select **Certificate \& secrets**.

2. Under the **Certificate** section, click **Upload certificate** . The **Upload certificate**dialog appears as shown in the figure below:

   ![Upload certificate_1.png](https://help.secude.com/__attachments/a_64ecba39eda96ac5f7698b1e78e3a97a41e278118cdbdad6709c5902f3b604f1/Upload%20certificate_1.png?cb=9b028533c34b642a22254eac5af1b8b2)

   *Upload certificate #1*
3. Click on the folder icon to select the certificate and click **Open** . For illustration purposes, the file `DESKTOP001.cer` is used.

4. Now, click **Add**. The certificate will get uploaded, and its thumbprint will be displayed on the page as shown in the figure below:

   ![Upload certificate_2.png](https://help.secude.com/__attachments/a_6d76fb5f709a4b7459782026860c7247c1650be5b29736b9808fc07e6c0672cc/Upload%20certificate_2.png?cb=0623c0f3126f69195dfa9f8b7d86687e)

   *Upload certificate #2*

The following table lists the Microsoft Entra ID application types that must be registered when using HaloCAD Add-on for CAD, HaloCAD for Viewer, HaloENGINE, or HaloCAD for PLM.  

|              **Component and Combination**               |           **Application Type**           |                                                                                                                 **Configuration Guideline**                                                                                                                  |
|----------------------------------------------------------|------------------------------------------|--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| HaloCAD Add-on for CAD and HaloCAD Reader Add-on for CAD | Public client/native (mobile \& desktop) | Create a new Microsoft Entra ID application in your tenant for the HaloCAD Add-on for CAD installation and use the same application details for the Reader Add-on. The Reader Add-on cannot open protected files if the tenant details do not match.         |
| HaloCAD for Viewer                                       | Public client/native (mobile \& desktop) | Create a new Microsoft Entra ID application in your tenant for HaloCAD for Viewer installation. Alternatively, if you already have an existing HaloCAD application, use the same app details and ensure that the client type is set to Public client/native. |
| HaloCAD for TCAI                                         | Public client/native (mobile \& desktop) | Create a new Microsoft Entra ID application in your tenant for HaloCAD for Viewer installation. Alternatively, if you already have an existing HaloCAD application, use the same app details and ensure that the client type is set to Public client/native. |
| HaloCAD for SOLIDWORKS PDM                               | Public client/native (mobile \& desktop) | Create a new Microsoft Entra ID application in your tenant for the HaloCAD for SOLIDWORKS PDM installation. When used in combination with HaloENGINE, ensure that the same Directory (Tenant) ID is used. Mismatched IDs will cause configuration errors.    |
| HaloENGINE                                               | Web                                      | Create a new Microsoft Entra ID application in your tenant for the HaloENGINE. For more details, please refer to the HaloENGINE Installation Manual.                                                                                                         |
| HaloCAD for PLM and HaloENGINE                           | Web                                      | Both use a Web-type application, so the same application details can be used during installation.                                                                                                                                                            |

*HaloCAD and Application Type*

### Create and Configure the Sensitivity Labels

|-------------------|----------------------------------------------------------------------------------------------------------------------------------|
| **Applicable to** | 1. HaloCAD Add-on for CAD 2. HaloCAD Reader for Add-on 3. HaloCAD for PLM/PDM (Teamcenter, Windchill, Vault, and SOLIDWORKS PDM) |

As an administrator, you can create, configure, and publish sensitivity labels for various levels of content sensitivity based on your organization's classification taxonomy. Use names or terms that are familiar to your users. Consider starting with label names like Personal, Public, General, Confidential, and Highly Confidential if you don't already have a taxonomy in place. For more details, please refer to Microsoft online documentation.

### Office 365 Subscription Details

|-------------------|---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| **Applicable to** | 1. HaloCAD Add-on for CAD 2. HaloCAD Reader Add-on for CAD 3. HaloCAD for Viewers 4. HaloCAD for TCAI 5. HaloCAD for PLM/PDM (Teamcenter, Windchill, Vault, and SOLIDWORKS PDM) |

1. Fully configured Microsoft Purview Information Protection.

2. An Azure subscription is required to use Azure RMS and the MPIP functionality.

3. A working Microsoft Entra ID service must be available.

4. Transport Layer Security (TLS) 1.2 or higher must be enabled to ensure the use of cryptographically secure protocols at all client workstations. Please refer to the section "[Enable Support for TLS 1.2 at the Client Workstation for Microsoft Entra ID](https://help.secude.com/halocad-add-on-for-autodesk-autocad/2.4/technical-reference-manual.md#TLS)".

5. To avail the revoke access feature, the user should be assigned to the Microsoft Purview Information Protection Premium P1/P2 license. (Not required for the reader and viewer add-on)

6. Audit logging: Your Azure subscription must include Log Analytics on the same tenant as Microsoft Entra ID.

### **Recommended URLs, Addresses, and Ports for MPIP**

|-------------------|-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| **Applicable to** | 1. HaloCAD Add-on for CAD 2. HaloCAD Reader for Add-on 3. HaloCAD for Viewers 4. HaloCAD for TCAI 5. HaloCAD for PLM/PDM (Teamcenter, Windchill, Vault, and SOLIDWORKS PDM) |

MIP SDK doesn't support the use of authenticated proxies. So, make sure you set the Microsoft 365 endpoints to bypass the proxy. View a list of endpoints at "[Microsoft Online Documentation](https://docs.microsoft.com/en-us/microsoft-365/enterprise/urls-and-ip-address-ranges?view=o365-worldwide)". However, Microsoft recommends the following:  

|                                                                                                                                    **Addresses**                                                                                                                                     |                   **Ports**                    |
|--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|------------------------------------------------|
| `*.protection.outlook.com` `40.92.0.0/15`, `40.107.0.0/16`, `52.100.0.0/14`, `52.238.78.88/32`, `104.47.0.0/17`, `2a01:111:f403::/48`                                                                                                                                                | TCP 443                                        |
| `*.aadrm.com`, `*.azurerms.com`, `*.informationprotection.azure.com`, `ecn.dev.virtualearth.net`, `informationprotection.hosting.portal.azure.net`, `*.office.com` (add `substrate.office.com` if you don't want to add all sub-domains), `crl3.digicert.com`, `crl4.digicert.com` . | TCP 443, 80                                    |
| **For event logging** `*.events.data.microsoft.com`                                                                                                                                                                                                                                  | TCP 443                                        |
| **National Cloud**                                                                                                                                                                                                                                                                   | **Microsoft Entra ID authentication endpoint** |
| Microsoft Entra ID for the US Government                                                                                                                                                                                                                                             | `https://login.microsoftonline.us`             |
| Microsoft Entra ID (global service) For details on Microsoft Entra ID endpoints, please refer to "[++Microsoft Online Documentation++](https://docs.microsoft.com/en-us/azure/active-directory/develop/authentication-national-cloud#azure-ad-authentication-endpoints)".            | `https://login.microsoftonline.com`            |

*Recommended endpoints*

**Secude License Manager for HaloCAD**  

|-------------------|------------------------------------------------------------|
| **Applicable to** | 1. HaloCAD Add-on for CAD 2. HaloCAD Reader Add-on for CAD |

To communicate with Secude License Manager for HaloCAD, the following URL and port must be whitelisted in the customer's proxy:  

|                              **Address**                              | **Port** |
|-----------------------------------------------------------------------|----------|
| License API - [api.licensespring.com](https://api.licensespring.com/) | TCP 443  |

*Recommended license manager endpoint*

### Enable Support for TLS 1.2 at the Client Workstation for Microsoft Entra ID

|-------------------|---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| **Applicable to** | 1. HaloCAD Add-on for CAD 2. HaloCAD Reader Add-on for CAD 3. HaloCAD for Viewers 4. HaloCAD for TCAI 5. HaloCAD for PLM/PDM (Teamcenter, Windchill, Vault, and SOLIDWORKS PDM) |

To improve the security posture of the tenant and to remain in compliance with industry standards, Microsoft Entra ID stopped supporting the following Transport Layer Security (TLS) protocols and ciphers:

1. TLS 1.1

2. TLS 1.0

3. 3DES cipher suite (TLS_RSA_WITH_3DES_EDE_CBC_SHA)

In order for the HaloCAD for CAD add-on to be able to authenticate to Microsoft Entra ID, TLS 1.2 must be activated on the respective client workstation. Please see this [Microsoft article to enable TLS 1.2](https://learn.microsoft.com/en-us/troubleshoot/azure/active-directory/enable-support-tls-environment?tabs=azure-monitor).  
**Microsoft documentation**

The information in the Microsoft documentation overrides any information published in this section.

Secude is not liable for changes to the content of this section because it was extracted from the Microsoft article at the time when the HaloCAD manual was prepared. Do check the most recent updates in this regard from the Microsoft documentation.

In summary, the following steps must be performed:

1. Update the Windows Operating System

2. Update .NET Framework

3. Set the following registry settings:

| **S.No** |                              **Windows Registry**                              |                                    **Values**                                     |
|----------|--------------------------------------------------------------------------------|-----------------------------------------------------------------------------------|
| 1        | `[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\.NETFramework\v4.0.30319]` | `"SystemDefaultTlsVersions"=dword:00000001` `"SchUseStrongCrypto"=dword:00000001` |
| 2        | `[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\v4.0.30319]`             | `"SystemDefaultTlsVersions"=dword:00000001` `"SchUseStrongCrypto"=dword:00000001` |

*Registry entries*

## License Administration

|-------------------|------------------------------------------------------------|
| **Applicable to** | 1. HaloCAD Add-on for CAD 2. HaloCAD Reader Add-on for CAD |

HaloCAD uses a key-based license to control application features. Obtain the license key from Secude Support before installing HaloCAD.  
This document does not cover all the specifics of purchasing a license. Please contact Secude's representative for additional details.

The following methods are available to activate the license in HaloCAD.

1. **Tool-based automatic initialization and license activation** : This method generates an encrypted configuration file that contains the license key and Microsoft Entra ID application details. Using this file, the installer automatically completes the installation, application initialization, and license activation. For more information, refer to the "[Secure Installation](https://help.secude.com/halocad-add-on-for-autodesk-autocad/2.4/technical-reference-manual.md#secure)" section.

2. **UI-based manual license activation** : This method provides a straightforward installation process without automatic license activation. After launching the CAD application, the administrator must manually activate the license by entering the license key in the HaloCAD license screen. For more information, refer to the "[UI-based Manual License Activation](https://help.secude.com/halocad-add-on-for-autodesk-autocad/2.4/technical-reference-manual.md#ui)" section.

3. **License activation in silent mode:** This method uses an encrypted configuration file to automatically initialize the application and activate the license during installation. For more details, refer to the **Silent Mode** section of the HaloCAD Installation Manual provided with your purchased application.

4. **License activation via System Center Configuration Manager (SCCM)**: For organization-wide deployment and activation of the HaloCAD add-on, an encrypted configuration file containing the license key information and Microsoft Entra ID application details is used together with the installer. For additional information on SCCM, please refer to the HaloCAD Installation Manual.

The following is a high-level diagram that illustrates license activation.  
![TechReference_Activation methods.png](https://help.secude.com/__attachments/a_ce3227f2915957a85bc7c97049a6ebb1ada8b03a0ec221fa9c20c43fc9ffb91f/TechReference_Activation%20methods.png?cb=4db4bb96e8c6129e4c18ec2252367813)

*License activation*

### **Secure Installation (Recommended)**

|-------------------|-------------------------------------------------------------------------------------------------------------------------------------|
| **Applicable to** | 1. HaloCAD Add-on for CAD 2. HaloCAD Reader Add-on for CAD 3. HaloCAD for Viewers 4. HaloCAD for TCAI 5. HaloCAD for SOLIDWORKS PDM |

As a best practice, application secrets should not be shared with end users, third parties, or trusted vendors. However, to avail of HaloCAD features (standard add-on and reader add-on), it is necessary to share such sensitive information for a successful installation.

To overcome this challenge, Secude offers an admin utility tool that can write and encrypt data, including Microsoft Entra ID application details (Application ID, Tenant ID, and Redirect URI), Cloud type details, and a license key in an encrypted configuration file. It uses the RSA algorithm for cryptography, allowing only the HaloCAD installer to access the configuration file with the private key during the initialization process, effectively masking the Initialization screen from the user.

An administrator can create an encrypted JSON file using this admin tool and share it with internal/external parties without disclosing the original tenant details.

**HaloCAD Admin Utility Tool**

The HaloCAD product package comprises an additional component---`hc.admintool.exe`.

**Prerequisites**: Before executing the admin tool, make sure you have the necessary information.

1. Microsoft Entra ID application details for initialization

2. Cloud type details

3. A license key

   Note: A license key is not required for HaloCAD for Viewers and HaloCAD for TCAI.

**How to Encrypt the Configuration File**

1. From the product package, move the **admintool** folder to your preferred location. For example, `C:\Users\superdocs\Desktop\admintool`.

2. Open the Command Prompt with elevated rights (Run as Administrator).

3. Navigate to the directory of the **admintool** folder and type `hc.admintool.exe` and press **Enter**.

   ![Admin tool Commands.png](https://help.secude.com/__attachments/a_4aa2dec15364299c00c08758ab1d13f457e9203e9324ecfd1200fd911c8d4c87/Admin%20tool%20Commands.png?cb=1a46b89cd30b48fb1baa0e771e3e253f)

   *Admin tool with help command*
4. Enter the required details. For example,

   **Cloud type: Commercial** - `hc.admintool.exe v6ca776-c74e-437d-98ef-662ecb5751tt https://localhost 9c1cfc28-1ec6-44ea-bec6-e3492ef0cd16 B27N-CMTO-LWGH-AKEQ Commercial`

   **Cloud type: US_DoD** - `hc.admintool.exe v6ca776-c74e-437d-98ef-662ecb5751tt https://localhost 9c1cfc28-1ec6-44ea-bec6-e3492ef0cd16 B27N-CMTO-LWGH-AKEQ US_DoD`

   **Cloud type: Custom** - `hc.admintool.exe v6ca776-c74e-437d-98ef-662ecb5751tt https://localhost 9c1cfc28-1ec6-44ea-bec6-e3492ef0cd16 B27N-CMTO-LWGH-AKEQ Custom https://api.aadrm.com https://dataservice.protection.outlook.com`

5. The output window will now appear as follows:

   ![Custom_Admin tool output.png](https://help.secude.com/__attachments/a_e4a32aef0e2e4c678ed57d5f1fd58303c9429414d22fa9190299f4b15e7b06f4/Custom_Admin%20tool%20output.png?cb=d0c0fde036cd75475504c21aa54dac5b)

   *Admin tool displaying the output*
6. **HaloCAD add-on for Creo**: The following help commands are specific to the HaloCAD add-on for Creo.

   ![Creo admin tool.jpg](https://help.secude.com/__attachments/a_4f7c89ac10517c16d754ec4ebeb1de2fd936a114ae40bf3ac7f1a6e2ea67dc4f/Creo%20admin%20tool.jpg?cb=0251084f955bb62a73353c12ecc6fa2b)

   *Admin tool with help command* *for Creo add-on*  
   ![Admin tool - output-Creo ECTR.png](https://help.secude.com/__attachments/a_47d0f55aabc048934a9f67bfa29808df44be851272ac8119af3cd698109416b2/Admin%20tool%20-%20output-Creo%20ECTR.png?cb=53dc5c95b7a1f6b9461aaf266f14ce4f)

   *Admin tool displaying the output with ECTR integration (only for Creo add-on)*
7. **HaloCAD for SOLIDWORKS PDM**: The following help commands are specific to HaloCAD for SOLIDWORKS PDM.

   ![Admin tool output (SWPDM).png](https://help.secude.com/__attachments/a_d635e46848736e0a64118877918db84504d0139898da1b4d0352fe03e8a8277c/Admin%20tool%20output%20(SWPDM).png?cb=5e986a9c43bd90f71bd8c85c932bc538)

   *Admin tool displaying the output for SOLIDWORKS PDM*
8. **HaloCAD for Viewers and TCAI**: The following help commands are specific to HaloCAD for Viewers and TCAI.

   ![Admin tool displaying the output for HaloCAD for Viewers and TCAI.png](https://help.secude.com/__attachments/a_27736f3979ccd3b77f23cf22fe85084fadff704f93373f325e514e11f0afffc1/Admin%20tool%20displaying%20the%20output%20for%20HaloCAD%20for%20Viewers%20and%20TCAI.png?cb=7d27e5050516ef77de8ed96dcd909c75)

   *Admin tool displaying the output for Viewers and TCAI*

**Result**:

* The `hc.conf.json` file will be replaced by an encrypted file named `hc.conf.enc`.

* You can now share the configuration file with external users. With this file, users can install the HaloCAD add-on on their workstations seamlessly, without requiring any additional configuration details.

* Configuration files created with earlier releases are not supported. Always use the admin tool included in the installation package to generate a new configuration file.

**Next step**

1. Place the encrypted file `hc.conf.enc` in the same directory as the HaloCAD installer you have purchased.

2. To start the interactive installation, double-click the installer and follow the steps provided in the Installation Manual for your purchased add-on.

### UI-based Manual License Activation

|-------------------|--------------------------------------------------------|
| **Applicable to** | 1. HaloCAD Add-on for CAD 2. HaloCAD Reader for Add-on |

This section describes how to activate a license using the HaloCAD user interface. Note: If you encounter any issues while activating the license, please refer to the "Troubleshooting" chapter in the Operations Manual.

Prerequisite: Ensure that the HaloCAD installation is complete by following the instructions provided in the Installation Manual.

1. Open the CAD application for which the add-on was purchased.

2. HaloCAD programmatically sends a license validation request to Secude's License Manager, and the following warning message appears:

   ![HALOCAD License warning message.png](https://help.secude.com/__attachments/a_22f9a87d6fe9d28e4b0dbfc85dda333a326578fdc583ed903cfbfa861dbf105e/HALOCAD%20License%20warning%20message.png?cb=3bff119b979098a8e9ccd558802b5da8)

   *HaloCAD license warning message*
3. Click **OK**.

4. Go to the **HaloCAD** tab and click **About** to see the status of your license. You will see **None**on the screen, indicating that the license has not yet been enabled.

   ![License status - None -About Screen.png](https://help.secude.com/__attachments/a_1aa25c618e647a6ff27d0b9816957575ef3ef308e6046589baff4bcff6822ef5/License%20status%20-%20None%20-About%20Screen.png?cb=deb860ef70b4b568263d0c199eefdca3)

   *License Status: None*
5. Click **Activate**.

6. The *HaloCAD License Activation* screen will appear.

   ![HALOCAD Activation Screen.png](https://help.secude.com/__attachments/a_043d310d377a53843087dee14e462711d341590866f7fad20ff14b5d8f21d3bc/HALOCAD%20Activation%20Screen.png?cb=acd5c6bf499586a88f83eaa7cfbf6a15)

   *HaloCAD activation screen*
7. Enter the license key for the standard add-on for protection. Note: Ensure you enter the license key provided specifically for the reader add-on when using it. Interchanging license keys results in activation failure.

8. Click **Activate**.

**Result**:

* You will receive the following confirmation message:

  ![Activation success message.png](https://help.secude.com/__attachments/a_f560c41e457bcd5a7f2c1cb439799188aec6ac2b43cdb4bc5cd7e43100cf7f0d/Activation%20success%20message.png?cb=c479100ffb0eb6c50f18afba55116969)

  *Activation success message*
* Click **OK**.

* As a result, you will see **Active** on the screen, indicating that the license has been activated.

  ![License status.png](https://help.secude.com/__attachments/a_238facca914cd1b71ecb41023614469f572c9943ab37430416d32512eb437a8a/License%20status.png?cb=cfa6e519985f240fe1df3f9523829bc0)

  *License Status: Active*

**Related tasks**:

* If you click the pencil icon (**Click to change label** ) to label the file, the Rights Management Service prompts you to sign in. Click **OK**, and then enter your credentials.

* After successful authentication, the labels can be retrieved from Microsoft Purview Information Protection, and the HaloCAD Ribbon is activated. For more details, please refer to the Operations Manual.

### **License Expiration**

|-------------------|------------------------------------------------------------|
| **Applicable to** | 1. HaloCAD Add-on for CAD 2. HaloCAD Reader Add-on for CAD |

HaloCAD licenses are valid only until the specified expiration date. After the license expires, launching the CAD application will display a warning message stating *"The license is invalid."* After clicking **OK** , another message will appear stating *"User has no valid license. Please contact your administrator."* To continue using the application, a new valid license must be obtained and activated.

Prerequisite: Before reactivating it, ensure that you have a new license key from Secude.

**Option 1** **- Using the Admin Tool (Automatic Activation)**

1. Run the admin tool with the new license key, as explained in the section "[How to Encrypt the Configuration File](https://help.secude.com/halocad-add-on-for-autodesk-autocad/2.4/technical-reference-manual.md#admintool)".

2. Navigate to the configuration directory containing the old `hc.conf.enc` file and replace it with the one created in the previous step.

3. Restart the application.

**Result**:

* The HaloCAD license key is now automatically activated.

* You can start protecting CAD files.

**Option 2 - Using the About UI (Manual Activation)**

1. Open the CAD application.

2. Go to the **HaloCAD** tab and click **About**.

3. Click **Activate**.

4. Enter the new key that Secude has provided.

**Result**:

* The HaloCAD license key is now manually activated.

* You can start protecting CAD files.

## Appendix

**Third-Party Libraries**

Third-party software/code is included or bundled with Secude's products according to its appropriate license. Secude conducts testing to ensure that third-party products are compatible with and perform as intended with Secude applications.  

|-------------------|------------------------------------------------------------|
| **Applicable to** | 1. HaloCAD Add-on for CAD 2. HaloCAD Reader Add-on for CAD |

The third-party libraries and dependencies used by the HaloCAD Add-on for CAD are shown in the table below.  

|   **Library**    |          **Version**           |                                                             **Source Code**                                                              |                                       **License Link**                                       |
|------------------|--------------------------------|------------------------------------------------------------------------------------------------------------------------------------------|----------------------------------------------------------------------------------------------|
| Mhook            | 2.5.1                          | <https://github.com/apriorit/mhook>                                                                                                      | <https://github.com/apriorit/mhook#license>                                                  |
| Protobuf Library | 3.15.6                         | <https://github.com/protocolbuffers/protobuf>                                                                                            | <https://github.com/protocolbuffers/protobuf/blob/master/LICENSE>                            |
| OpenSSL          | 3.2                            | <https://github.com/openssl>                                                                                                             | <https://github.com/openssl/openssl/blob/master/LICENSE.txt>                                 |
| Rapidxml         | 1.13                           | [https://sourceforge.net/projects/rapidxml/files/latest/download](https://sourceforge.net/projects/rapidxml/files/latest/download%C2%A0) | <http://rapidxml.sourceforge.net/license.txt>                                                |
| JSON Parser      | 3.11.3                         | <https://github.com/nlohmann/json>                                                                                                       | <https://github.com/nlohmann/json/blob/develop/LICENSE.MIT>                                  |
| MSAL             | 4.72.1.0                       | <https://github.com/AzureAD/microsoft-authentication-library-for-dotnet>                                                                 | <https://github.com/AzureAD/microsoft-authentication-library-for-dotnet/blob/master/LICENSE> |
| ConfuserEx       | 1.0.0.0                        | <https://github.com/yck1509/ConfuserEx>                                                                                                  | <https://github.com/yck1509/ConfuserEx/blob/master/LICENSE>                                  |
| WTL              | 9.0.4140                       | <https://www.nuget.org/packages/wtl/9.0.4140>                                                                                            | <https://opensource.org/licenses/cpl1.0.txt>                                                 |
| MIP SDK          | 1.18.103 Creo and NX: 1.16.126 | <https://learn.microsoft.com/en-us/information-protection/develop/version-release-history>                                               | <https://docs.microsoft.com/en-us/information-protection/develop/>                           |
| Licensespring    | 7.40.0                         | -                                                                                                                                        | -                                                                                            |

*Third-party libraries*

The third-party libraries and dependencies used by HaloCAD for Viewers, HaloCAD for TCAI, HaloENGINE, HaloCAD for Teamcenter PLM, HaloCAD for Windchill PLM, HaloCAD for Autodesk Vault PLM, and HaloCAD for SOLIDWORKS PDM are listed in its Installation Manual.

---
version: "6.10"
language: "en"
---
# HaloENGINE

## HaloENGINE

This page provides a complete collection of HaloENGINE documentation.

### Documentation

#### [Installation and Configuration Manual](https://help.secude.com/haloengine/6.10/installation-manual.md)

*

  #### [Release Notes](https://help.secude.com/haloengine/6.10/release-notes.md)

---
version: "6.10"
language: "en"
---
# Appendix

This section contains supplementary information.

## Uninstalling the HaloENGINE

Before uninstalling, ensure that you export the current configuration. The exported configuration file can be imported during reinstallation to retain existing settings, reduce configuration effort, and minimize the risk of misconfigurations or errors.

**Method #1**

When you no longer use the service, you may uninstall the application. Uninstalling removes all files and registry settings that were added to your computer during the initial installation.

1. Click **Start** menu \> go to **Control Panel** \> **Programs** \>**Programs and Features** \> **Uninstall a Program** \>select**HaloENGINE** application from the list \> right-click and select **Uninstall** option or double-click on the installer `HaloENGINE_Setup.exe`.

2. Depending on your Windows security settings, you may get a security warning as "*Do you want to allow the following program to make changes to this computer* ?". If you get this security warning, click the **Yes** button to confirm that you want to uninstall the application.

3. The following confirmation message appears:

   ![Uninstall message #1.png](https://help.secude.com/__attachments/a_630915ad3497abeb0c84211f2b4f11a58cd61f45636243513bec61419a76d3da/Uninstall%20message%20%231.png?cb=eb354164dbbcee2bc5a138ee32134f1f)

   *Uninstall message #1*
4. Click **Yes** to confirm that you want to remove it from the computer.

5. You will be prompted to save a backup of the configuration files.

   ![Uninstall message #2.png](https://help.secude.com/__attachments/a_c1bef40b84da8c1f52e8873d80035d3a69ee5e14e7a9e412450151d59a36bfc9/Uninstall%20message%20%232.png?cb=d6f04ca2a8e007ac6732e0faf8d8a59d)

   *Uninstall message #2*
6. Click **Yes** to save and continue with the uninstallation (The previous configuration files will be kept in the same location) or choose **No**to proceed with the uninstallation without saving.

   ![Uninstall message #3.png](https://help.secude.com/__attachments/a_1a040614b22e2b616ef0eb98d7c650fb947577bfb1f27a1d24ad4910d649a94b/Uninstall%20message%20%233.png?cb=096f1b2f72ede5e5a05561e8ddb9a74a)

   *Uninstall message #3*
7. Click **OK**to close the message.

**Method #2**

The application can be removed using the command line, as illustrated in the sample below.

1. Open a command prompt.

2. Navigate to the application installer's directory.

3. Use the following commands to uninstall:

   Example #1: uninstall and keep the configuration files

   `HaloENGINE_Setup.exe -uninstall -keepconfig true`

   Example #2: uninstall and delete the configuration files

   `HaloENGINE_Setup.exe -uninstall -keepconfig false`

## Metadata **Definition**

The following section provides a table of built-in metadata for PLM and PDM clients.

### Windchill

The table below lists the Windchill metadata available in the HaloENGINE.  

|       **Windchill metadata**        |                                                                                                                                                                                                           **Use**                                                                                                                                                                                                           |
|-------------------------------------|-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| server_name                         | Derivation from server name (FQDN of the Windchill server). (For example, `svin0007.secude.local`)                                                                                                                                                                                                                                                                                                                          |
| user_name                           | Derivation from Windchill logged-in users. (For example, John and Derek)                                                                                                                                                                                                                                                                                                                                                    |
| file_name                           | Derivation from the file name.                                                                                                                                                                                                                                                                                                                                                                                              |
| project_name                        | Derivation from the project name. (For example, Windchill)                                                                                                                                                                                                                                                                                                                                                                  |
| product_name                        | Derivation from product name (For example, Windchill).                                                                                                                                                                                                                                                                                                                                                                      |
| lifecycle_template                  | Derivation from the lifecycle of a file. Lifecycle provides an overview of how business items develop and serves as a model for the commercialization process. The lifecycle templates may be of the following types: Approval, Basic, Default, and so on. (For example, `Pipeline.prt` - Default)                                                                                                                          |
| user_role                           | Derivation from the user role. (For example, Designer and Engineer)                                                                                                                                                                                                                                                                                                                                                         |
| lifecycle_state                     | Derivation from the lifecycle of a file. Each phase of a lifecycle template is associated with a lifecycle state. There are different kinds of lifecycle states. 1. Approval (template): In work, under review, approved (states) 2. Basic (template): Basic: In work, released, canceled (states) 3. Default (template): Default: In work, under review, released (states) (For example, `Pipeline.prt`- Default-released) |
| security_label                      | Derivation from Windchill access control policy. For more details, please refer to the online [PTC Windchill documentation](https://support.ptc.com/help/wnc/r12.0.0.0/en/index.html#page/Windchill_Help_Center%2Fsublandingpages%2FSublandingPageSecurityLabel.html%23). (For example, Export Control, Corporate Proprietary, and Third Party Proprietary)                                                                 |
| file_type                           | Derivation from file type (Creo file types and MS Office native file types). (For example, sec, prt, asm, xlsx)                                                                                                                                                                                                                                                                                                             |
| library_name                        | Derivation from the library name. (For example, Density, Wheel, and Pipeline)                                                                                                                                                                                                                                                                                                                                               |
| workspace_name                      | Derivation from workspace. (For example, Generic_computer and Drive System)                                                                                                                                                                                                                                                                                                                                                 |
| system_context                      | Derivation from the origin of the data. (For example, Generic_computer, and Drive System)                                                                                                                                                                                                                                                                                                                                   |
| preexpression_custom_pre-expression | Derivation from custom pre-expression. 1. Yes 2. No                                                                                                                                                                                                                                                                                                                                                                         |

*Windchill metadata*

### Teamcenter

The table below lists the Teamcenter metadata available in the HaloENGINE.  

|       **Teamcenter metadata**       |                                                                                               **Use**                                                                                               |
|-------------------------------------|-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| user_role                           | Derivation from the user role. Multiple roles may be assigned to a single user. (For example, Designer and Engineer)                                                                                |
| user_def_group                      | Derivation from a group of users who log in. (For example, a user from the Engineering group)                                                                                                       |
| gov_clearance                       | Derivation from a specific object based on value or licensing value. (For example, secret - single value field)                                                                                     |
| ip_clearance                        | Derivation from intellectual property (IP) classification values and clearance levels assigned to data objects and users for IP access evaluation. (For example, super-secret - single value field) |
| user_name                           | Derivation from Teamcenter logged-in users. (For example, John and Derek)                                                                                                                           |
| file_type                           | Derivation from file type and Teamcenter object data. (NX file types and MS Office native file types) (For example, prt, asm, and XLSX)                                                             |
| gov_classification                  | Derivation from a Teamcenter object based on its value or license value. (For example, secret - single value field)                                                                                 |
| obj_project_names                   | Derivation from Teamcenter object data. The object could be used in several projects. (For example, project1; project2- multi-value- field)                                                         |
| ip_classification                   | Derivation from Teamcenter's intellectual property (IP). (For example, secret, internal, and confidential - single value field)                                                                     |
| preexpression_custom_pre-expression | Derivation from custom pre-expression. 1. Yes 2. No                                                                                                                                                 |

*Teamcenter metadata*

### Autodesk Vault

The table below lists the Autodesk Vault metadata available in the HaloENGINE.  

|     **Autodesk Vault Metadata**     |                                                                        **Use**                                                                        |
|-------------------------------------|-------------------------------------------------------------------------------------------------------------------------------------------------------|
| lifecycle_state                     | Derivation from the lifecycle of Autodesk Vault data. (For example, work-in-progress, review, and released)                                           |
| file_type                           | Derivation from file type. File types of AutoCAD, Inventor, and MS Office native file types. (For example, `dwg`, `ipt`, and `iam`)                   |
| folder_name                         | Derivation from the folder name in the Autodesk Vault server. (For example, `$/DESIGNS/INVENTOR FILES/Jet Engine Model/Workspace/Design Accelerator`) |
| preexpression_custom_pre-expression | Derivation from custom pre-expression. 1. Yes 2. No                                                                                                   |

*Autodesk Vault metadata*

### SOLIDWORKS PDM

The table below lists the SOLIDWORKS PDM metadata available in the HaloENGINE.  

|     **SOLIDWORKS PDM Metadata**     |                                                                                                                                                                   **Use**                                                                                                                                                                   |
|-------------------------------------|---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| author_name                         | Derivation from the Web2 client interface Items author.                                                                                                                                                                                                                                                                                     |
| domain_name                         | Derivation from the network domain name associated with the current user. (For example, `SZVLU100.com`)                                                                                                                                                                                                                                     |
| file_type                           | Derivation from file type. File types of SOLIDWORKS.                                                                                                                                                                                                                                                                                        |
| user_name                           | Derivation from machine logged-on user. (For example, John and Derek)                                                                                                                                                                                                                                                                       |
| client_hostname                     | Derivation from the computer where SOLIDWORKS PDM is installed. (For example, `SZVLU100.com`)                                                                                                                                                                                                                                               |
| current_state                       | Derivation from the file's status as set in SOLIDWORKS PDM. (For example, Approved and Waiting for approval)                                                                                                                                                                                                                                |
| project_name                        | The name of the project from which the saved file is derived. (For example, CMS Turbo Engine)                                                                                                                                                                                                                                               |
| ad_group                            | Derivation from the domain groups. (For example, Domain Users and Superusers)                                                                                                                                                                                                                                                               |
| folder_path                         | Derivation from folder name in SOLIDWORKS PDM server. (For example, `C:/<Folder>`). Please note that files cannot be encrypted if the folder name (`folder_path`) is specified with a backslash "**\\** ", such as `C:\folder1\folder2`. Therefore, it is advised to configure with a forward slash "**/** ", such as `C:/folder1/folder2`. |
| preexpression_custom_pre-expression | Derivation from custom pre-expression 1. Yes 2. No                                                                                                                                                                                                                                                                                          |

*SOLIDWORKS PDM metadata*

## Third-Party Libraries

Third-party software/code is included or bundled with Secude's products according to its appropriate license. Secude conducts testing to make sure the third-party products are compatible with and perform as intended with Secude applications.

The third-party libraries and dependencies used by HaloENGINE are shown in the table below.  

|                                 **Library**                                  |  **Version**   |                                                                                                           **Source Code**                                                                                                            |                                       **License Name**                                       |                                                         **License Link**                                                         |
|------------------------------------------------------------------------------|----------------|--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|----------------------------------------------------------------------------------------------|----------------------------------------------------------------------------------------------------------------------------------|
| jakarta.xml.bind:jakarta.xml.bind-api                                        | 3.0.1          | <https://mvnrepository.com/artifact/jakarta.xml.bind/jakarta.xml.bind-api/3.0.1>                                                                                                                                                     | CDDL-1.0                                                                                     | <https://javaee.github.io/glassfish/LICENSE>                                                                                     |
| jakarta.xml.ws:jakarta.xml.ws-api                                            | 3.0.1          | <https://mvnrepository.com/artifact/jakarta.xml.ws/jakarta.xml.ws-api/3.0.1>                                                                                                                                                         | CDDL-1.0                                                                                     | <https://javaee.github.io/glassfish/LICENSE>                                                                                     |
| javax.annotation:javax.annotation-api                                        | 1.3.2          | <https://github.com/javaee/javax.annotation>                                                                                                                                                                                         | CDDL-1.0                                                                                     | <https://github.com/javaee/javax.xml.soap/blob/master/LICENSE>                                                                   |
| com.sun.activation:javax.activation-api                                      | 1.2.0          | <https://repo1.maven.org/maven2/javax/activation/javax.activation-api/1.2.0/>                                                                                                                                                        | CDDL-1.0                                                                                     | <https://github.com/javaee/activation/blob/master/LICENSE.txt>                                                                   |
| com.sun.activation: jakarta.activation                                       | 1.2.2          | <https://github.com/javaee/activation>                                                                                                                                                                                               | CDDL-1.0                                                                                     | <https://javaee.github.io/glassfish/LICENSE>                                                                                     |
| org.slf4j:slf4j-api                                                          | 2.0.+          | <http://www.slf4j.org/download.html>                                                                                                                                                                                                 | MIT                                                                                          | <http://www.slf4j.org/license.html>                                                                                              |
| com.sun.xml.bind:jaxb-impl                                                   | 2.3.5          | <https://github.com/javaee/jaxb-v2>                                                                                                                                                                                                  | CDDL-1.1                                                                                     | <https://github.com/javaee/jaxb-v2/blob/master/LICENSE>                                                                          |
| jakarta.xml.bind:jakarta.xml.bind-api                                        | 2.3.3          | <https://github.com/eclipse-ee4j/jaxb-api>                                                                                                                                                                                           | BSD 3                                                                                        | <https://github.com/eclipse-ee4j/jaxb-api/blob/master/LICENSE.md>                                                                |
| joda-time:joda-time                                                          | 2.12.7         | <https://github.com/JodaOrg/joda-time>                                                                                                                                                                                               | Apache 2.0                                                                                   | <https://github.com/JodaOrg/joda-time/blob/master/LICENSE.txt>                                                                   |
| net.iharder:base64                                                           | 2.3.9          | <http://iharder.sourceforge.net/current/java/base64/>                                                                                                                                                                                | Public Domain                                                                                | <http://iharder.sourceforge.net/current/java/base64/>                                                                            |
| org.graylog2:syslog4j                                                        | 0.9.61         | <https://github.com/graylog-labs/syslog4j-graylog2>                                                                                                                                                                                  | LGPL 2.1                                                                                     | <https://github.com/graylog-labs/syslog4j-graylog2/blob/master/LICENSE>                                                          |
| ch.qos.logback:logback-classic                                               | 1.5.18         | <https://github.com/qos-ch/logback>                                                                                                                                                                                                  | LGPL 2.1                                                                                     | <https://github.com/qos-ch/logback/blob/master/LICENSE.txt>                                                                      |
| ch.qos.logback:logback-core                                                  | 1.5.18         | <https://github.com/qos-ch/logback>                                                                                                                                                                                                  | LGPL 2.1                                                                                     | <https://github.com/qos-ch/logback/blob/master/LICENSE.txt>                                                                      |
| com.googlecode.json-simple:json-simple                                       | 1.1.1          | <https://github.com/fangyidong/json-simple>                                                                                                                                                                                          | Apache 2.0                                                                                   | <https://github.com/fangyidong/json-simple/blob/master/LICENSE.txt>                                                              |
| org.apache.commons:commons-lang3                                             | 3.13           | <https://github.com/apache/commons-lang>                                                                                                                                                                                             | Apache 2.0                                                                                   | <https://github.com/apache/commons-lang/blob/master/LICENSE.txt>                                                                 |
| nl.basjes.parse.useragent:yauaa                                              | 5.23           | <https://github.com/nielsbasjes/yauaa>                                                                                                                                                                                               | Apache 2.0                                                                                   | <https://github.com/nielsbasjes/yauaa/blob/master/LICENSE>                                                                       |
| org.eclipse.persistence:org.eclipse.persistence.moxy                         | 2.7.9          | <https://github.com/eclipse-ee4j/eclipselink/tree/master/moxy>                                                                                                                                                                       | EPL 2.0                                                                                      | <https://github.com/eclipse-ee4j/eclipselink/blob/master/LICENSE.md>                                                             |
| com.google.guava:guava                                                       | 33.0.0-jre.jar | <https://github.com/google/guava>                                                                                                                                                                                                    | Apache 2.0                                                                                   | <https://github.com/google/guava/blob/master/COPYING>                                                                            |
| org.apache.logging.log4j:log4j-api                                           | 2.20.0         | <https://github.com/apache/logging-log4j2>                                                                                                                                                                                           | Apache 2.0                                                                                   | <https://github.com/apache/logging-log4j2/blob/release-2.x/LICENSE.txt>                                                          |
| com.javax0.license3j:license3j                                               | 3.2.0          | <https://github.com/verhas/License3j>                                                                                                                                                                                                | Apache 2.0                                                                                   | <https://github.com/verhas/License3j/blob/master/LICENSE.txt>                                                                    |
| javax.servlet:javax.servlet-api                                              | 4.0.1          | <https://github.com/javaee/servlet-spec>                                                                                                                                                                                             | CDDL-1.0                                                                                     | <https://github.com/javaee/servlet-spec/blob/master/LICENSE>                                                                     |
| org.apache.poi:poi-ooxml                                                     | 5.2.3          | <https://github.com/apache/poi>                                                                                                                                                                                                      | Apache 2.0                                                                                   | <https://www.apache.org/licenses/LICENSE-2.0>                                                                                    |
| com.univocity:univocity-parsers                                              | 2.9.1          | <https://github.com/uniVocity/univocity-parsers>                                                                                                                                                                                     | Apache 2.0                                                                                   | <https://www.apache.org/licenses/LICENSE-2.0>                                                                                    |
| com.opencsv:opencsv                                                          | 5.9            | <https://github.com/cygri/opencsv>                                                                                                                                                                                                   | Apache 2.0                                                                                   | <https://github.com/cygri/opencsv/blob/master/LICENSE>                                                                           |
| com.ibm.icu:icu4j                                                            | 70.1           | <https://github.com/unicode-org/icu>                                                                                                                                                                                                 | ICU license                                                                                  | <https://github.com/unicode-org/icu/blob/main/icu4c/LICENSE>                                                                     |
| com.fasterxml.jackson.core:jackson-databind                                  | 2.18.1         | <https://github.com/FasterXML/Jackson-databind>                                                                                                                                                                                      | Apache 2.0                                                                                   | <https://github.com/FasterXML/jackson-databind/blob/2.13/LICENSE>                                                                |
| com.datastax.oss:java-driver-core                                            | 4.17.0         | <https://github.com/datastax/java-driver>                                                                                                                                                                                            | Apache 2.0                                                                                   | <https://github.com/datastax/java-driver/blob/4.x/LICENSE>                                                                       |
| com.datastax.oss:java-driver-query-builder                                   | 4.17.0         | <https://github.com/datastax/java-driver>                                                                                                                                                                                            | Apache 2.0                                                                                   | <https://github.com/datastax/java-driver/blob/4.x/LICENSE>                                                                       |
| com.datastax.oss:java-driver-mapper-runtime                                  | 4.17.0         | <https://github.com/datastax/java-driver>                                                                                                                                                                                            | Apache 2.0                                                                                   | <https://github.com/datastax/java-driver/blob/4.x/LICENSE>                                                                       |
| org.json:json                                                                | 20211205       | <https://github.com/vogella/org.json/tree/master/src>                                                                                                                                                                                | org.JSON                                                                                     | <https://github.com/vogella/org.json/tree/master/src>                                                                            |
| org.apache.httpcomponents:httpclient                                         | 4.5.14         | <https://github.com/apache/httpcomponents-client>                                                                                                                                                                                    | Apache 2.0                                                                                   | <https://github.com/apache/httpcomponents-client/blob/master/LICENSE.txt>                                                        |
| org.apache.cxf:cxf-rt-frontend-jaxws                                         | 4.0.8          | <https://github.com/apache/cxf>                                                                                                                                                                                                      | Apache 2.0                                                                                   | <https://github.com/apache/cxf/blob/master/LICENSE>                                                                              |
| org.apache.cxf:cxf-rt-rs-security-cors                                       | 4.0.8          | <https://github.com/apache/cxf>                                                                                                                                                                                                      | Apache 2.0                                                                                   | <https://github.com/apache/cxf/blob/master/LICENSE>                                                                              |
| org.apache.cxf:cxf-rt-ws-rm                                                  | 4.0.8          | <https://github.com/apache/cxf>                                                                                                                                                                                                      | Apache 2.0                                                                                   | <https://github.com/apache/cxf/blob/master/LICENSE>                                                                              |
| org.springframework: spring-context                                          | 6.2.7          | <https://github.com/spring-projects/spring-framework/tree/main/spring-context>                                                                                                                                                       | Apache 2.0                                                                                   | <https://github.com/spring-projects/spring-framework/blob/main/src/docs/dist/license.txt>                                        |
| org.springframework:spring-web                                               | 6.2.7          | <https://github.com/spring-projects/spring-framework/tree/main/spring-web>                                                                                                                                                           | Apache 2.0                                                                                   | <https://github.com/spring-projects/spring-framework/blob/main/src/docs/dist/license.txt>                                        |
| org.codehaus.woodstox:stax2-api                                              | 3.1.4          | <https://github.com/FasterXML/woodstox>                                                                                                                                                                                              | Apache 2.0                                                                                   | <https://github.com/FasterXML/woodstox/blob/master/LICENSE>                                                                      |
| org.springframework.boot:spring-boot-starter-web                             | 3.3.12         | <https://github.com/spring-projects/spring-boot>                                                                                                                                                                                     | Apache 2.0                                                                                   | <https://github.com/spring-projects/spring-boot/blob/main/LICENSE.txt>                                                           |
| org.springframework.boot:spring-boot-starter-security                        | 3.3.12         | <https://github.com/spring-projects/spring-boot>                                                                                                                                                                                     | Apache 2.0                                                                                   | <https://github.com/spring-projects/spring-boot/blob/main/LICENSE.txt>                                                           |
| org.springframework.security:spring-security-jwt                             | 1.0.10 RELEASE | <https://github.com/spring-projects/spring-security-oauth>                                                                                                                                                                           | Apache 2.0                                                                                   | <https://github.com/spring-projects/spring-security-oauth/blob/main/license.txt>                                                 |
| o.jsonwebtoken:jjwt                                                          | 0.9.1          | <https://github.com/jwtk/jjwt>                                                                                                                                                                                                       | Apache 2.0                                                                                   | <https://github.com/jwtk/jjwt/blob/master/LICENSE>                                                                               |
| javax.resource:javax.resource-api                                            | 1.7.1          | <https://github.com/javaee/javax.resource>                                                                                                                                                                                           | CDDL-1.0                                                                                     | <https://github.com/javaee/javax.resource/blob/master/LICENSE>                                                                   |
| commons-io:commons-io                                                        | 2.5            | <https://github.com/apache/commons-io>                                                                                                                                                                                               | Apache 2.0                                                                                   | <https://github.com/apache/commons-io/blob/master/LICENSE.txt>                                                                   |
| commons-fileupload:commons-fileupload                                        | 1.2.1          | <https://github.com/apache/commons-fileupload>                                                                                                                                                                                       | Apache 2.0                                                                                   | <https://github.com/apache/commons-fileupload/blob/master/LICENSE.txt>                                                           |
| commons-beanutils:commons-beanutils                                          | 1.9.4          | <https://github.com/apache/commons-beanutils>                                                                                                                                                                                        | Apache 2.0                                                                                   | <https://github.com/apache/commons-beanutils/blob/master/LICENSE.txt>                                                            |
| org.springframework.boot:spring-boot-gradle-plugin                           | 3.3.12         | <https://github.com/spring-projects/spring-boot/tree/main/spring-boot-project>                                                                                                                                                       | Apache 2.0                                                                                   | <https://github.com/spring-projects/spring-boot/blob/main/LICENSE.txt>                                                           |
| org.springframework.batch:spring-batch-core                                  | 4.3.10         | <https://github.com/spring-projects/spring-batch>                                                                                                                                                                                    | Apache 2.0                                                                                   | <https://github.com/spring-projects/spring-batch/blob/main/LICENSE.txt>                                                          |
| org.springframework.batch:spring-batch-infrastructure                        | 4.3.7          | <https://github.com/spring-projects/spring-batch>                                                                                                                                                                                    | Apache 2.0                                                                                   | <https://github.com/spring-projects/spring-batch/blob/main/LICENSE.txt>                                                          |
| org.springframework.boot:spring-boot-starter-actuator                        | 3.3.12         | <https://github.com/spring-projects/spring-boot/tree/main/spring-boot-project>                                                                                                                                                       | Apache 2.0                                                                                   | <https://github.com/spring-projects/spring-boot/blob/main/LICENSE.txt>                                                           |
| org.springframework.hateoas:spring-hateoas                                   | 2.5.0          | <https://github.com/spring-projects/spring-hateoas>                                                                                                                                                                                  | Apache 2.0                                                                                   | <https://github.com/spring-projects/spring-hateoas/blob/main/LICENSE>                                                            |
| org.jolokia:jolokia-core                                                     | 1.7.2          | <https://github.com/rhuss/jolokia>                                                                                                                                                                                                   | Apache 2.0                                                                                   | <https://github.com/rhuss/jolokia/blob/master/LICENSE>                                                                           |
| org.dizitart:nitrite                                                         | 3.2.0          | <https://github.com/nitrite/nitrite-java>                                                                                                                                                                                            | Apache 2.0                                                                                   | <https://github.com/nitrite/nitrite-java/blob/develop/LICENSE.md>                                                                |
| org.springframework.boot:spring-boot-starter-oauth2-resource-server          | 6.2.7          | <https://github.com/spring-projects/spring-boot/tree/main/spring-boot-project>                                                                                                                                                       | Apache 2.0                                                                                   | <https://github.com/spring-projects/spring-boot/blob/main/LICENSE.txt>                                                           |
| org.springframework.security:spring-security-oauth2-jose                     | 5.8.2          | <https://github.com/spring-projects/spring-security>                                                                                                                                                                                 | Apache 2.0                                                                                   | <https://github.com/spring-projects/spring-security> <https://github.com/spring-projects/spring-security/blob/main/LICENSE.txt>  |
| org.springframework.security.oauth:spring-security-oauth2                    | 2.5.2.RELEASE  | <https://github.com/spring-projects/spring-security>                                                                                                                                                                                 | Apache 2.0                                                                                   | <https://github.com/spring-projects/spring-security> -<https://github.com/spring-projects/spring-security/blob/main/LICENSE.txt> |
| org.springframework.security:spring-security-oauth2-client                   | 6.4.6          | <https://github.com/spring-projects/spring-security>                                                                                                                                                                                 | Apache 2.0                                                                                   | <https://github.com/spring-projects/spring-security> -<https://github.com/spring-projects/spring-security/blob/main/LICENSE.txt> |
| org.springframework.security.oauth.boot:spring-security-oauth2-autoconfigure | 2.6.8          | <https://github.com/spring-projects/spring-security>                                                                                                                                                                                 | Apache 2.0                                                                                   | <https://github.com/spring-projects/spring-security> -<https://github.com/spring-projects/spring-security/blob/main/LICENSE.txt> |
| Tomcat                                                                       | 10.1.52        | <https://github.com/apache/tomcat>                                                                                                                                                                                                   | Apache 2.0                                                                                   | <https://github.com/apache/tomcat/blob/main/LICENSE>                                                                             |
| Java                                                                         | 21             | <https://github.com/adoptium/jdk>                                                                                                                                                                                                    | -                                                                                            | <https://www.eclipse.org/legal/epl-2.0/>                                                                                         |
| MongoDB                                                                      | 7.0.7          | [https://fastdl.mongodb.org/windows/mongodb-windows-x86_64](https://fastdl.mongodb.org/windows/mongodb-windows-x86_64-7.0.7-signed.msi)                                                                                              |                                                                                              |                                                                                                                                  |
| MIP SDK                                                                      | 1.18.103       | <https://learn.microsoft.com/en-us/information-protection/develop/version-release-history> The MIP SDK is publicly available for integration, but is not open source. It is provided by Microsoft under proprietary licensing terms. | <https://docs.microsoft.com/en-us/information-protection/develop/>                           | MIP SDK                                                                                                                          |
| MSAL                                                                         | 4.73.1         | <https://github.com/AzureAD/microsoft-authentication-library-for-dotnet>                                                                                                                                                             | <https://github.com/AzureAD/microsoft-authentication-library-for-dotnet/blob/master/LICENSE> | MSAL                                                                                                                             |
| Spdlog                                                                       | 1.17.0         |                                                                                                                                                                                                                                      | <https://github.com/gabime/spdlog>                                                           | Spdlog                                                                                                                           |

*Third-party libraries*

---
version: "6.10"
language: "en"
---
# Configuring the Tomcat Service

The HaloENGINE Tomcat Service communicates directly with the **Microsoft Purview Information Protection** service to fetch the MPIP labels. These labels are then available under the **Protect** option on the **Action Rule** page.  
**Any changes to labels in the Microsoft Purview portal require restarting the HaloENGINE Tomcat service.**

If a MPIP label is added, removed, or modified in the Microsoft Purview portal, or if you change the service registry settings, the administrator must restart the HaloENGINE Tomcat service to ensure that the changes take effect. By doing this, labels are updated in and synchronized with the Microsoft Purview portal.

## Configuration Tool

During installation, Azure details are provided to initialize the HaloENGINE Tomcat Service. After successful authentication, the labels are fetched automatically. To update MPIP-related details (such as the Application ID), use`heslibconfig.exe`.

**Default locations of log files**  

|      **Name**      |                                        **Default Path**                                         |
|--------------------|-------------------------------------------------------------------------------------------------|
| HaloENGINE log     | `C:\Program Files\Secude\HaloENGINE\logs\customer_tenants\halo_customer\HaloENGINE_Monitor.log` |
| Configuration tool | `C:\Program Files\Secude\HaloENGINE\HaloENGINEService\lib\heslibconfig.exe`                     |
| MIP logs           | `C:\Program Files\Secude\HaloENGINE\HaloENGINEService\logs\mip_cache_storage\mip\logs`          |

*Default locations*

To update your Azure details, follow the procedure below.

1. Open the Command Prompt with elevated rights (Run as Administrator).

2. Navigate to the directory where `heslibconfig.exe` is located.

3. To view the list of available options in silent mode, enter the following command:

   **Type** `heslibconfig.exe -help`

   **Press** `Enter`

   **Output**

   `Usage:`

   `heslibconfig.exe -testmip`

   `heslibconfig.exe -update -applicationid <application_id> -tenantid <tenant_id> -thumbprint <thumb_print> -cloudtype <(Commercial|Custom|Germany|US_DoD|US_GCC|US_GCC_HIGH|US_Sec|US_Nat|China_01) (if cloudtype is Custom) <protectioncloudurl> <policycloudurl>`

4. The following command illustrates how to update json file.

   `heslibconfig.exe -update -applicationid 9f0de2dd-8d49-4a3f-9676-bf4b6ff17d44 -tenantid 8c425ee7-352a-4657-ac77-7dc198712cb3 -thumbprint 961602617275c2ab538cf28bb3648c0c6d97edab -cloudtype Custom https://api.aadrm.com https://dataservice.protection.outlook.com`

5. A confirmation message appears stating that the configuration JSON file location has been successfully updated, `...\config\HaloENGINESVC.json`

**Configuration change in JSON File**

After installation, navigate to the configuration folder`...\HaloENGINEService\config`, and you will find a JSON file that contains the HaloENGINE Tomcat Service configuration properties. Note: From the list of default parameters, only the parameters listed below should be modified, and only when necessary. All other parameters must remain at their default values to ensure proper system functionality and stability.  

|        **Name**        |                                                                                                                                                                                                                                                                           **Description**                                                                                                                                                                                                                                                                           |
|------------------------|---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| block_pii              | Enable or disable the visibility of Personally Identifiable Information (PII) in the MIP SDK logs. * false---PII will be visible in clear text in the MIP SDK logs. * true---PII will be masked with asterisks in the MIP SDK logs. This helps to protect the PII's confidentiality.                                                                                                                                                                                                                                                                                |
| cachetype              | MPIP cache storage type used by the service. * In Memory---0, maintains the storage cache in memory in the application. * On Disk---1 (default storage type), stores the database (SQLite3) on disk in the directory provided in the settings object. The database is stored in plaintext. * On Disk Encrypted---2, stores the database (SQLite3) on disk in the directory provided in the settings object. The database is encrypted using OS-specific APIs.                                                                                                       |
| cacheuserlicense       | * 0---false, End User License (EUL) will NOT be stored in the MPIP cache storage. * 1---true (default value), End User License (EUL) will be stored in the MPIP cache storage                                                                                                                                                                                                                                                                                                                                                                                       |
| databoundary           | Audit and telemetry events are sent to the nearest collector, where these events are stored and processed. Other options: 1. Asia 2. Europe_MiddleEast_Africa 3. European_Union 4. North_America For example, if your AIP administrator sets North_America, the HaloENGINE Tomcat Service forces all telemetry and audit data to go directly to North America.                                                                                                                                                                                                      |
| enabledke              | Double Key Encryption * 0 (default value)---Disables the DKE functionality in the HaloENGINE Tomcat Service. * 1 (On)---Enables the DKE functionality in the HaloENGINE Tomcat Service. Please be aware that DKE labels are only visible when DKE functionality is enabled.                                                                                                                                                                                                                                                                                         |
| enablefiletracking     | To register a protected file to track and revoke. * 0 (default value)---the protected file will not be registered for file tracking and access revocation. * 1---The protected file will be registered for file tracking and access revocation                                                                                                                                                                                                                                                                                                                      |
| enableminimaltelemetry | To transmit diagnostic information to Microsoft. * 0 (default value)---all diagnostic events are transmitted. * 1---Minimum diagnostic events are transmitted.                                                                                                                                                                                                                                                                                                                                                                                                      |
| log_level              | The available log levels are ERROR, WARNING, INFO, and DEBUG.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| log_purge              | It indicates removing files older than a defined time frame. By default, the log files older than 7 days will be deleted.                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| streambuffersize       | It is a buffer size used for memory-based encryption with the MIP SDK. When the allotted buffer size is exceeded, an additional memory of stream buffer size is allocated, and this process is repeated until the encryption/decryption operation is completed. The default setting is 10MB.                                                                                                                                                                                                                                                                        |
| templatefile_purge     | Defines the purge time of template files that are generated for every CAD assembly file (compound file) download. The default value set is one hour. For example, when a file is downloaded at 15:25 hours, the HaloENGINE Tomcat Service creates a template file in the tmp\\GUID folder (which can be located in the HaloENGINE Tomcat Service user's profile folder). In the background, it examines and deletes files that have reached the configured time, i.e., after 16:25 hours. Note: This is only applicable in the event of CAD assembly file labeling. |

*HaloENGINE Tomcat service configuration*

## **WinHTTP Proxy Settings**

To allow MIP SDK to use the proxy settings set up in your environment, follow the steps below:

**Determine whether the proxy server has been properly set up by running the following command.**

    C:\Windows\system32>netsh winhttp show proxy

    Current WinHTTP proxy settings:

    Direct access (no proxy server).

If the response to the command is as shown above, it indicates that the proxy server has not been configured in the registry for WinHTTP.

**To configure the proxy server for WinHTTP, use the following command:**

**Syntax** : `C:\Windows\system32>netsh winhttp set proxy <proxyservername>:<portnumber>`

**Example** : `C:\Windows\system32>netsh winhttp set proxy 190.160.166.191:8080`

In this case, the proxy server has been set up with `190.160.166.191:8080`. Once this command is executed successfully, the registry is updated with the proxy server URL, and the HaloENGINE Tomcat Service ensures that the configured proxy settings are applied.

---
version: "6.10"
language: "en"
---
# Technical Support

Before contacting Technical Support, ensure that you have the following information available. Providing this information helps the support team investigate and resolve your issue more efficiently.

* Full contact details

* Product build version

* Date, time, and description of the error (include screenshots, if possible)

* Details of any third-party software used with the product

* Any additional information required to reproduce the issue

**Contact Technical Support**

Secude provides technical support through email [++support@secude.com++](mailto:support@secude.com). When contacting Technical Support by email, include your company details, a detailed description of the issue, and the relevant log files (if available). A support representative will respond to your inquiry.

**Additional Resources**

Visit the Secude website [++https://secude.com++](https://secude.com/) to learn about upcoming events, press releases, and to download white papers.

**Documentation Feedback**

Secude values your feedback and continuously strives to improve product documentation. To provide feedback, send an email to: [++documentation@secude.com++](mailto:documentation@secude.com)

Include the following details in your feedback:

* Product name and version

* Documentation topic

* Description of the suggestion or error

The technical documentation team reviews all feedback and incorporates relevant updates in future documentation releases.

---
version: "6.10"
language: "en"
---
# HaloENGINE API

Secude's HaloENGINE API architecture aims to streamline underlying MPIP functionalities such as file protection and audit log export. The HaloENGINE API enables MPIP capabilities by seamlessly integrating with existing business applications.  
![HaloENGINE REST SDK-01.png](https://help.secude.com/__attachments/a_12af2e378983a676dc4c052fff4842ed4368f5cbb35142bea56aee5b61a5f371/HaloENGINE%20REST%20SDK-01.png?cb=9ddd428940e1dc69d6a146f405ef7d8d)

*HaloENGINE API*

**What can be expected when using the API?**

1. It streamlines web-based application interaction via HTTP methods.

2. The end consumer can protect files with their own rule engine or business logic.

3. This will extend to any existing or customized data portal within the organization that must be scrutinized and protected against data leaks.

The use of this information and the implementation of any APIs described herein are the sole responsibility of the customer. Successful integration depends on the customer's ability to evaluate, configure, and incorporate the APIs within their business environment.

## About this Chapter

This document demonstrates how to successfully call the HaloENGINE API from your application and use it for your business needs. It assumes you are familiar with REST API calls. It provides a clear and comprehensive background to the REST SDK, including endpoints, parameters, response types, and any other information that developers should be aware of. It also explains how the resources work and provides examples that should help you get started.  
Please note that the examples in this document are intended solely as guidance and should not be applied in a production environment.

### Quick Start

The following high-level steps describe how to get started with HaloENGINE and expose the APIs.

1. **Step 1** : Install and configure the HaloENGINE as described in the following chapter, "[Installing the HaloENGINE](https://help.secude.com/haloengine/6.10/installing-the-haloengine.md)".

2. **Step 2**: Import the license in the admin portal with the HaloENGINE API enabled.

3. **Step 3:** Server Certificate Authentication. Select one of the following authentication approaches.

   **Self-signed Certificate:** A minor configuration change is necessary on the client side. Download the server certificate (`HaloENGINEServer.cer`) from the HaloENGINE Admin portal and manually install it on the client machine in the Trusted Root Certification Authorities.

   **Company-Owned Signed Certificate:** If you already have a certificate, you can import it into the admin portal. Make sure your company's Root CA is installed in Trusted Root Certification Authorities. In this case, there is no need to install the server certificate (`HaloENGINEServer.cer`) on your client machine.  For more details, please refer to the section "[Phase 1. Certificate Configuration](https://help.secude.com/haloengine/6.10/phase-1-certificate-configuration.md#phase1)".
4. **Step 4:** Set the classification engine. This step comprises creating profiles, schema, and action rules based on the needs of your business. Please refer to the chapter "[Setting Up Classification Engine](https://help.secude.com/haloengine/6.10/setting-up-classification-engine.md)".

5. Postman or another REST client.

## API Reference

This section provides API examples that can be executed using **Postman**.

### Host/Base URL

|--------------------------|---------------------------------------------------------|
| **Base URL**             | `https://{servername}:{port}/haloengine-server`         |
| **Endpoint description** | `https://{servername}:{port}/haloengine-server/halosdk` |

*Base URL*

Using the above URL, the "halosdk" API is accessible.

The following variables should be replaced with values for your system.

1. {`server`} corresponds to the server's name or IP address.

2. {`port`} is the port number on which the server runs.

**Resource Methods Description**

Typically, an API will have multiple endpoints associated with the same resource. Every resource is exposed via a URL. You can obtain the URL of every resource by obtaining access to the API Root Endpoint.  

| **Method** |         **URL**          |
|------------|--------------------------|
| GET        | `/Version`               |
| POST       | `/GetMetaDataTypes`      |
| POST       | `/GetActionFormRest`     |
| POST       | `/EncryptFile`           |
| POST       | `/DecryptFile`           |
| POST       | `/SendPLMMonitorLogData` |

*Endpoints*

### Version

**Description:**Returns the HaloENGINE server version.

**Request method:**GET

#### Request Example

The following example shows a request sent using Postman.

##### Request URL

    GET https://10.41.14.69:8746/haloengine-server/halosdk/Version

##### Response

A successful request returns the following information:

* **Status Code:** 200

* **Response Body:** Plain text containing the HaloENGINE version number.

    6.10.1.0

This response confirms that the HaloENGINE service is running and returns the current version.

### Get Required Metadata Types

**Description:**Returns supported metadata types used by the HaloENGINE server.

**Request method:**POST

#### Request Example

The following example shows a request sent using Postman.

##### Request URL

    POST https://10.41.14.69:8746/haloengine-server/halosdk/GetMetaDataTypes

Prerequisite: The HaloENGINE API system type does not currently have any built-in metadata; hence, new metadata can be created using Custom metadata. Please refer to the "[Custom metadata](https://help.secude.com/haloengine/6.10/phase-5-configure-profiles-and-classification.md#CM)" section.

##### Request

The request is sent in the Body-JSON format with the following parameters.

1. **customerId** -- Customer ID used by HaloENGINE. Note: `halo_customer` is the default Customer ID in the HaloENGINE Admin Portal and must be used as a mandatory parameter in API requests without modification. Any mismatch in the Customer ID results in an error.

2. **systemId** -- Unique system ID of the client system.

3. **systemType** -- Type of the client system.

**Example**

    {
        "customerId": "halo_customer",
        "systemId": "API_customer",
        "systemType": "HaloENGINE_API"
    }

##### Response

A successful request returns the following information:

* **Status Code:** 200

* **Response Body:** Plain text containing the configured metadata \[`user_group, work_in_progress, folder, review, release, file_name, user_name, file_type, project`\].

### Get Action

**Description:**Determines the action (monitor, encrypt, or decrypt) based on the provided inputs.

**Request method:**POST

There are three options in "Owner Configuration": Service (default), Static email, and User. You can set it up on the HaloENGINE admin portal. Note: For static email, enter the user's email address in the admin portal. To learn how to configure **Owner Configuration** , refer to the section "[Owner Configuration](https://help.secude.com/haloengine/6.10/phase-5-configure-profiles-and-classification.md#owner)".

#### Request Example

The following example shows a request sent using Postman.

##### Request URL

    POST https://10.41.14.69:8746/haloengine-server/halosdk/GetActionFormRest

##### Request

The request is sent in the Body-JSON format with the following parameters.

1. **customerId** -- Customer ID used by HaloENGINE.

2. **systemId** -- Unique ID of the client system.

3. **systemType** -- Type of the client system.

4. Example values `user_name`,` file_type`, and `file_name`.

**Example**

    {
      "customerIdentification": {
        "customerId": "halo_customer",
        "systemId": "API_customer",
        "systemType": "HaloENGINE_API"
      },
      "metadata": {
      "simpleValue": {
        "user_name": ["john"],
        "file_type": ["docx"],
        "file_name": ["BOM.docx"]
      }
    }
    }

##### Response

A successful request returns the following information:

* **Status Code:** 200

* **Response Body:** A successful request returns a JSON response with the following structure:

    {
        "simMode": false,
        "labelVendor": "NONE",
        "action": {
            "value": [
                "LABEL",
                "AUDIT"
            ]
        },
        "authorMode": {
            "userEmailNeeded": false,
            "staticEmail": ""
        },
        "classification": "
    <?xml version=\"1.0\" encoding=\"UTF-8\" standalone=\"yes\"?>\n
    <classification version=\"1.0\">\n    
    	<class name=\"Default\">\n        
    		<displayNames>\n            
    			<displayName locale=\"en_US\" name=\"Default\"/>\n        
    		</displayNames>\n        
    		<properties>\n            
    			<property name=\"Sensitivity\" dataType=\"listValue\">\n                
    				<displayNames>\n                    
    					<displayName locale=\"en_US\" name=\"Sensitivity\"/>\n                
    				</displayNames>\n                
    				<values>\n                    
    					<listValue name=\"Secret\">\n                        
    						<displayNames>\n                            
    							<displayName locale=\"en_US\" name=\"Secret\"/>\n                        
    						</displayNames>\n                    
    					</listValue>\n                
    				</values>\n            
    			</property>\n        
    		</properties>\n    
    	</class>\n
    </classification>\n",
        "template": {
            "guid": "99f1473d-74f4-47ca-9843-e735f94fa797",
            "templateName": "HCAD Secret"
        }
    }

The response varies based on the **Owner Configuration** setting:

* **Service** → `"userEmailNeeded": false`, `"staticEmail": ""`

* **Static email** → `"userEmailNeeded": false`, `"staticEmail": "john@halosecude.onmicrosoft.com"`

* **User** → `"userEmailNeeded": true`, `"staticEmail": ""`

### Encrypt File

**Description:**Executes the encrypt action.

**Request method:**POST

#### Request Example

The following example shows a request sent using Postman.

##### Request URL

    POST https://10.41.14.69:8746/haloengine-server/halosdk/encryptFile

##### Request

The request is sent in the Body-JSON format with the following parameters.

**Key:** `file` (File as Type). Browse and select the required file.

**Description**: File to be encrypted.

**Example**

    BOM.txt

**Key (Optional):** `authorEmailId` (Text as Type)

**Description**: Email address of the document owner. Note: When an email address is provided, the user is assigned owner permissions. If no email address is provided, the service principal ID is assigned as the owner.

**Example**

    john@halosecude.onmicrosoft.com

**Key:** `labelId` (Text as Type)

**Description**: GUID of the template.

**Example**

    99f1473d-74f4-47ca-9843-e735f94fa797

**Key:** `type` (Text as Type).

**Description**: Labeling type. Supported values:

* LABELING

* COMPOUNDFILELABELING

**Example**

    LABELING 

**Key:** `additionalParam` (Text as Type).

**Description** : Required when the **COMPOUNDFILELABELING** type is used. Provide the compound file details in JSON format.

**Example**

    {"compoundid":"compound123"}

##### Response

A successful request returns the following information:

* **Status Code:** 200

* **Response Body:** A successful request returns a JSON response with the following structure:

    {
        "success": true,
        "message": "File encrypted successfully",
        "fileName": "BOM.ptxt",
        "fileType": "ptxt",
        "content": "The encrypted content is displayed."
    }

### Decrypt File

**Description:**Decrypts an encrypted file.

**Request method:**POST

#### Request Example

The following example shows a request sent using Postman.

##### Request URL

    POST https://10.41.14.69:8746/haloengine-server/halosdk/decryptFile

##### Request

The request is sent in the Body-JSON format with the following parameters.

**Key:** `file` (File as Type). Browse and select the required file.

**Description**: Encrypted file to be decrypted.

**Example**

    BOM.rtf.pfile

##### Response

A successful request returns the following information:

* **Status Code:** 200

* **Response Body:** A successful request returns a JSON response with the following structure:

    {
        "success": true,
        "message": "File decrypted successfully",
        "fileName": "BOM.rtf",
        "fileType": "rtf",
        "content": "The decrypted content is displayed."
        "templateID": "99f1473d-74f4-47ca-9843-e735f94fa797"
        
    }

### Send PLM Monitor Log Data

**Description:**Accepts monitoring logs for auditing.

**Request method:**POST

#### Request Example

The following example shows a request sent using Postman.

##### Request URL

    POST https://10.41.14.69:8746/haloengine-server/halosdk/SendPLMMonitorLogData

##### Request

The request is sent in the Body-JSON format with the following parameters.

* **customerId** -- Customer ID used by HaloENGINE.

* **systemId** -- Unique ID of the client system.

* **systemType** -- Type of the client system.

The request body may also include additional fields, such as:

* **logInfo** -- Details about the log event.

* **userInfo** -- Information about the user who triggered the event.

* **fileInfo** -- Metadata about the file involved in the action.

* **resultedDecision** -- Final decision returned by HaloENGINE.

**Example**

    {
      "customerIdentification": {
        "customerId": "halo_customer",
        "systemId": "API_customer",
        "systemType": "HaloENGINE_API"
      },
      "logInfo": {
        "utcTimeStamp": "2021-02-23T23:01:00+05:00",
        "timeZone": "+5",
        "logID": "sjkfsdfsd"
      },
      "userInfo": {
        "userName": "john",
        "userType": "DEV",
        "userEmail": "john@techuyt.com"
      },
      "fileInfo": {
        "fileName": "partrocket.asm",
        "filePath": "C:\\",
        "fileType": "asm",
        "fileProtectedBefore": false,
        "sizeOriginal": 4355675,
        "sizeDownload": 67848
      },
      "resultedDecision": {
        "fileBlocked": false,
        "fileLabeled": false,
        "fileProtected": false,
        "unprotected": true,
        "unlabeled": true,
        "fileBlockedByRule": false,
        "policyName": "HCAD Secret",
        "policyId": "1234",
        "classification": { 
          "byUser": "<?xml version=\"1.0\" encoding=\"UTF-8\"?><classification version=\"1.0\">...</classification>",
          "bySystem": "<?xml version=\"1.0\" encoding=\"UTF-8\"?><classification version=\"1.0\">...</classification>"
        },
        "abortedBySystem": false,
        "abortedByUser": false,
        "error": false,
        "simMode": false,
        "extendedTags": [
          {
            "key": "Key1",
            "value": "Value1"
          }
        ]
      },
      "plmContextInfo": {
        "eventType": "user download",
        "browserClient": "true",
        "preProcessInfo": [
          {
            "type": "Testing",
            "key": "ABC",
            "value": "12345"
          }
        ],
        "attributes": [
          {
            "type": "Attr1",
            "key": "user_name",
            "value": "sjohn"
          }
        ],
        "documentId": "1222",
        "documentNumber": "222",
        "documentType": "1",
        "documentPart": "j",
        "documentVersion": "00",
        "viewOnly": false,
        "dmsProcess": false
      },
      "plmDestInfo": {
        "destinationAttributes": [
          {
            "type": "Dest",
            "key": "XYZ",
            "value": "123"
          }
        ],
        "browser": "IE",
        "hostname": "ABC",
        "ipaddress": "10.91.0.1",
        "operatingSystem": "WIN10"
      }
    }

##### Response

A successful request returns the following information:

* **Status Code:** 200

* **Response Body:** The response body returns the boolean value **true**, represented as plain text.

## Error Handling

An unsuccessful request returns a response code other than 200. If you receive a null response, you may need to review the input.  

|    **Status Code**     |                                                                                                  **Sample Message**                                                                                                   |                                                                                      **Description**                                                                                       |
|------------------------|-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 400 `BAD_REQUEST`      | Sample error messages: 1. The monitor feature is not enabled. 2. Action rules were not initialized correctly. Check configurations. 3. Invalid or Inactive profile or invalid system ID. 4. System ID does not exist. | 1. The Monitor feature is not enabled in the portal. 2. Action rules are not initialized correctly. 3. Invalid or inactive profile, or invalid system ID entered. 4. System ID is invalid. |
| 401 `UNAUTHORIZED`     | Unauthorized client attempting to access the endpoint. The page cannot be viewed because the client type is not licensed for it. Please contact the administrator.                                                    | Attempted to connect to an unlicensed endpoint.                                                                                                                                            |
| `406` `NOT_ACCEPTABLE` | The System type is wrong. Please contact the administrator.                                                                                                                                                           | When any of the values, such as customer ID, system ID, or system type, are incorrect, it will be stated in the error message.                                                             |

*Error Codes*

---
version: "6.10"
language: "en"
---
# Initial Configuration of HaloENGINE Admin Portal

This section describes the portal features and how to get started with the HaloENGINE Admin Portal.

## Features

1. **Single Point Management**: You may manage all of your systems from the HaloENGINE Admin portal.

2. **Role-based access controls and security features**: The HaloENGINE Admin portal supports role-based authentication and authorization.

3. **User-Friendly UI**: The HaloENGINE Admin portal offers a user-friendly user interface that is simple to understand with minimal knowledge of the platform.

4. **Business logic**: The classification engine makes all decisions in terms of business logic.

5. **Dashboard**: A business-friendly dashboard that displays high-level information in a single view, including live and historical log data from HaloENGINE monitor logs.

## Reload and Restart

There will be references to both "reload" and "restart" throughout this manual. To avoid confusion, it's important to be familiar with these two terminologies.

**What is meant by reload?**

Reloading will instruct the service to reload its configuration files while leaving the current process running. It is considerably faster. When you make changes such as creating or updating any settings in HaloENGINE features, service configuration, profile configuration, basic system configuration, or CAD file types, you must click the Reload Configuration button for the changes to take effect.

**What is meant by restart?**

A restart will instruct the service to stop operating completely and then resume. Restarting the HaloENGINE Tomcat service takes some time. The HaloENGINE Tomcat service must be restarted after any modification to the license activation, certificate, tenant configuration, import configuration, or Remote Settings.

**How to Restart the HaloENGINE Tomcat Service**

1. Open the **Start** screen, type `services.msc`, and press **Enter** or **Press** the `Windows Key+R`, type in `services.msc`, and press **Enter**.

2. Locate the **Display Name** - **Tomcat 10.0 for HaloENGINE**.

   ![Restarting Tomcat Service.png](https://help.secude.com/__attachments/a_8e58020bc80488ad325c7e44fda0883a6d24e2c46aca172de666cd7ee95bdd22/Restarting%20Tomcat%20Service.png?cb=4707a62aa53e1a99fa2b039f46da2d70)

   *Restarting Tomcat Service*
3. Click **Restart**and wait for a few minutes.

## Welcome Page

A welcome page is displayed after clicking the installer link. It appears just the first time you configure the portal.  
![Welcome page.png](https://help.secude.com/__attachments/a_3fa7823fb0ff56dfb91d164788dc9b00c4173e5bc1afab45dc2e49b07a79adb0/Welcome%20page.png?cb=7dec67ef84ccc238d5056556c6a852ed)

*Welcome page*

HaloENGINE provides the following options:

1. **Starting new** : Creating a new configuration file to set up HaloENGINE. Please refer to the section "[Starting a New HaloENGINE](https://help.secude.com/haloengine/6.10/initial-configuration-of-haloengine-admin-portal.md#new)".

2. **Upgrade** : Moving to a newer version while keeping the existing configuration file. Please refer to the section "[Upgrading (Uploading Existing Configuration File)](https://help.secude.com/haloengine/6.10/initial-configuration-of-haloengine-admin-portal.md#up)".

## Upgrade HaloENGINE (Uploading Existing Configuration File)

Use this page to upgrade the HaloENGINE from the current version to the latest version. Note: Upgrading via the HaloENGINE installer is not supported.

Prerequisites

1. **For versions earlier than 6.9 (for example, 6.8)**

   1. Back up all certificates.

   2. Export `HaloENGINE-admin-config.zip` from the Admin Portal.

   3. Uninstall any existing versions of HaloENGINE and HaloENGINE Service.

2. **From version 6.9 and later**

   1. Export `HaloENGINE-admin-config.zip` from the Admin Portal.

   2. Uninstall any existing version of HaloENGINE.

   3. Ensure HaloENGINE version 6.10.x.x is installed on the system.

Follow the instructions below to upgrade:

1. Click **Upload Configuration** and then click**Existing Config Zip File**.

2. **Upgrading from version 6.8 to 6.10:** Select **Without Certificate** , click the attach button to select `HaloENGINE-admin-config.zip`, restart the HaloENGINE Tomcat Service, and import the certificates into the HaloENGINE Admin Portal.

3. **Upgrading from version 6.9 to 6.10:** Select **With Certificate** , click the attach button to select `HaloENGINE-admin-config.zip`, and restart the HaloENGINE Tomcat Service.

   ![Uploading existing configuration file.png](https://help.secude.com/__attachments/a_c5edef412b86a5058e646588f75cc36f81946e37e2576710b36fd76328a36c72/Uploading%20existing%20configuration%20file.png?cb=7d8977862faa07017da108cb6032713e)

   *Uploading the existing configuration file*

**What to do next** : Set up the Classification Engine. Please refer to the section "[Setting Up Classification Engine](https://help.secude.com/haloengine/6.10/setting-up-classification-engine.md#engine)".  
**Reset Password**

If your administrator password in the previous version is less than 12 characters, you must reset it according to the current password policy. To know how to reset the password, refer to the section "[Reset Administrator Password](https://help.secude.com/haloengine/6.10/system-configuration.md#reset)".

## Starting a New HaloENGINE

If this is your first time installing HaloENGINE, click **Configure** and proceed as instructed below:

### Step 1. Logging into Portal for the First Time

1. On the*Initial Setup* page, you must create administrator credentials to access the HaloENGINE Admin Portal.

   ![1 First time logging page.png](https://help.secude.com/__attachments/a_695f71b230b6346b9480509b59dab05a21c2bcdcc928257d18ae1267235a62e9/1%20First%20time%20logging%20page.png?cb=544e890a4437d41f84725f8bfbc107ec)

   *First time logging the page*
2. As per policy, enter a strong password, then reenter it. The password-eye icon allows you to reveal or conceal your password.

3. Click **Next**.

**Password Policy**

Be sure to use a strong yet memorable password. If you forget it, HaloENGINE provides an option to reset your password. To know how to reset the password, refer to the section "[Reset Administrator Password](https://help.secude.com/haloengine/6.10/system-configuration.md#reset)". Password must be 12--30 characters and include:

1. At least one uppercase letter \[A-Z\]

2. At least one lowercase letter \[a-z\]

3. At least one number \[0-9\]

4. At least one symbol (@$!%\*?\&-)

   For example, `HaloENg!nE@-`

### Step 2. HaloENGINE Basic Configuration

1. The following page is used to configure the basic settings.

   ![2 Basic Configuration Page.png](https://help.secude.com/__attachments/a_b6bdbf87be574406e86b22861814e10b72b84b02a566ca4e305ab454f8f1c600/2%20Basic%20Configuration%20Page.png?cb=011a381cb40f7eb2b1028d607e9c37ec)

   *Basic Configuration Page*
2. **Default Customer Name** ---The initial default customer name is **halo_customer**. You can modify this name after the portal initialization is complete.

3. **Select Log level**---Choose a type of error log level (INFO/DEBUG/ERROR/WARN/ALL).

4. **Location of HaloENGINE Configuration Files** ---Enter the configuration file's path. The default path is `C:\Program Files\Secude\HaloENGINE\config`.

5. **HaloENGINE System Log** **Location** ---Enter the file path for the HaloENGINE system log. The default path is `C:\Program Files\Secude\HaloENGINE\log`.

6. **HaloENGINE Log Retention Period** **in day(s)**---Set the duration for which the HaloENGINE logs should be available. The log retention period is determined by the days you specify here. Log files older than the retention period will be deleted. For example, if you specify it as 10, log files older than 10 days are deleted. Range: 0 to 90 days.

7. **Tomcat Log Retention Period** **in day(s)**---Specify how long the Tomcat logs should be available. Range: 0 to 90 days.

8. **Enable Remote Access** ---To enable access to configure the HaloENGINE Admin portal remotely (via IP), click on the slider button. Note: Please restart the HaloENGINE Tomcat service if you have made changes in the **Configure Remote Access** property.

9. Click **Next**.

### Step 3. HaloENGINE Configuration

1. Your server's details, such as the fully qualified domain name, IP address, and default port number, will be filled in automatically on this page. If needed, you can modify the port number. Note: Once the port has been configured, it cannot be changed. Therefore, kindly make the necessary modifications. If you still want to modify the port, back up the configuration and then remove the HaloENGINE. Reinstall the HaloENGINE, then modify the port.

   ![3 HaloENGINE configuration page.png](https://help.secude.com/__attachments/a_0d85464347a9c4eebe0fe977aec2384bcf0e6c9cf290d34087a77de49abb277c/3%20HaloENGINE%20configuration%20page.png?cb=356b08e8a04ca64fe8bed9234ccb9da5)

   *Configuration page*
2. Click **Next**.

### Step 4. Completion Page

1. This is the final page of the configuration.

   ![4 Complete HaloENGINE configuration page.png](https://help.secude.com/__attachments/a_e91cbe1c8dcf239c4e95f04da41653837fe46bfbe2b2f38a377fabc465528c3d/4%20Complete%20HaloENGINE%20configuration%20page.png?cb=128c00a46630a899acc91d85e8150ef2)

   *Final configuration page*
2. Click **Create and Apply** to create `config.properties` file and update the `hc-servlet.xml` file.

3. Click **Reload Application** to apply the changes. After reloading, the page will redirect to the login page.

4. These settings can always be changed through the portal as detailed in the section "[System Configuration](https://help.secude.com/haloengine/6.10/system-configuration.md#system)".

---
version: "6.10"
language: "en"
---
# Installation and Configuration Manual

## Introduction

HaloENGINE is a Java-based classification engine that applies business logic and integrates with the Microsoft Purview Information Protection service to fetch the sensitivity labels for configuration in the admin portal. Using metadata, it classifies and organizes data while enforcing schemas and action rules, serving as the core component that works with the HaloCAD for PLM/PDM solution to protect data.

The HaloCAD for PLM solution integrates with the PLM application, includes HaloCAD PROTECT and HaloCAD MONITOR features, and leverages Microsoft Purview Information Protection (MPIP), formerly Microsoft Information Protection (MIP), to provide Enterprise Digital Rights Management (EDRM). During file download, HaloENGINE receives relevant metadata from HaloCAD for PLM/PDM, determines the appropriate action based on the configured rules, and forwards the label and action information to HaloCAD for PLM/PDM for file processing (encryption).  
![HaloENGINE_Introduction.png](https://help.secude.com/__attachments/a_0544d1b5f193eb4d7c1fbf87a45c98552ae9bbb9e946128ed050a04e44683b2f/HaloENGINE_Introduction.png?cb=cc14e23f2429eed842742254c09f95b9)

*HaloENGINE integrated with HaloCAD for PLM/PDM solution*

**HaloENGINE Features**

1. Business logic: All business logic decisions are handled by this classification engine.

2. Logging the audit logs: Captures any file uploaded or downloaded, regardless of file protection.

3. Supports SIEM solutions, including Microsoft Azure Sentinel, Splunk, RSA, and others.

4. Halochain: Verifies whether the log file has been tampered with or not.

5. Dashboard: Displays important performance indicators and metrics, providing an overview of the company's data upload and download events.

### **About this Manual**

This manual will guide you through the installation and configuration of the following components:

1. HaloENGINE

2. HaloENGINE API

**About the Term "HaloENGINE Tomcat Service"**

The HaloENGINE Tomcat Service is a common component used in both the HaloENGINE and HaloCAD products. Since it was initially developed for HaloENGINE and later adopted across HaloCAD, all Tomcat instances in Secude appear under the name "HaloENGINE Tomcat Service."

### **General Concepts of Classification**

**Sensitive Data Classification:**This is the process of identifying and categorizing all the data in an organization depending on its sensitivity. When a systematic method of data classification is used, sensitive information is adequately protected and made accessible to those who need it. For example, more sensitive data, such as financial information, might be categorized in such a way that disclosure carries a higher risk. General information, such as that utilized for marketing, would be categorized as a lower risk. A higher level of protection is necessary for data identified as having a higher risk, whereas lower-risk data may need proportionately less protection. A data classification schema describes a specific approach to determining data classification levels.

**Levels of Sensitive Data**

Depending on sensitivity, data is typically categorized into several kinds.

1. **Public**: low data sensitivity

2. **Internal**: moderate data sensitivity

3. **Confidential**: high data sensitivity

You can take appropriate action on the relevant content in this situation using Microsoft Purview's sensitivity labels. Sensitivity labels allow you to identify the level of sensitivity of data across your organization and impose protective settings that are appropriate for the sensitivity of that data.  
**How are labels created?**

Through the Microsoft Purview portal, you can administer how labels are published to your users. For more details, please refer to Microsoft's online documentation.

**Classification Scheme**

It takes meticulous planning and preparation to define a classification scheme for an organization and set information types and labels. Each organization is unique, and there are no one-size-fits-all data protection rules. You could design your classification scheme based on the business context. Throughout this chapter, a basic-level scenario is used to demonstrate the configuration classification engine. Classifying data can be done in various ways, but most businesses prefer to use a three-level classification schema: Public, Internal, and Confidential.

**Best Practices**

When creating classification labels, consider the following recommendations:

1. **Leverage existing classification schemas (if available):**

   Reuse established frameworks within your organization to maintain consistency and reduce redundancy.

2. **Use sub-labels for key departments:**

   Certain departments may have unique classification requirements. Create sub-labels to address these specific needs. For example, Finance-Confidential, HR-Confidential.

3. **Choose meaningful label names:**

   Avoid using acronyms or ambiguous terms. Ensure label names clearly reflect their purpose and meaning.

**Classification Rule**

Rules are defined based on metadata and action rules to determine whether to block, label, protect, or decrypt a file.

Use the table below to decide how you want to deploy the features.  

|  **Actions**  |                                                          **Description**                                                           |
|---------------|------------------------------------------------------------------------------------------------------------------------------------|
| Monitor       | File uploads and downloads are audited.                                                                                            |
| Block         | File uploads and downloads are blocked.                                                                                            |
| Label/Protect | File uploads and downloads are classified. Using appropriate MPIP labels, classification labels are embedded in the file metadata. |

*Action description*

## Quick Start Installation Summary

The following visual illustrates the high-level concept of configuring HaloENGINE with HaloCAD.  
![HaloENGINE_Quick Start summary.png](https://help.secude.com/__attachments/a_d73083264d651782cf213af086053c5ba6018df358a582577c139555ddac243c/HaloENGINE_Quick%20Start%20summary.png?cb=c54412d558e62c201dd87287a3049c96)

*Quick start installation steps*

**Reference Manuals**

The table below describes where to obtain information.  

|                          **Component**                           |                                         **Refer to**                                          |
|------------------------------------------------------------------|-----------------------------------------------------------------------------------------------|
| Step 1 -- How to install and configure HaloENGINE.               | Refer to the current manual.                                                                  |
| Step 2 -- How to install HaloCAD for PLM/PDM.                    | Please refer to the respective HaloCAD for the PLM/PDM Installation Manual you have purchased |
| Steps 3 and 4 -- Workflow illustrating protection and decryption | Please refer to the respective HaloCAD for the PLM/PDM Operations Manual you have purchased   |

*Reference Manuals*

## How does it work?

At a high level, the workflow between HaloCAD for PLM and HaloENGINE is illustrated in the following steps:  
![HaloENGINE_How does it work.png](https://help.secude.com/__attachments/a_b65facb28c6333d287dc1ad5c07b2330242ecb34349d185cf1b5d2d9cb7024ba/HaloENGINE_How%20does%20it%20work.png?cb=6dbfddc4525627123ae9772c92f97542)

*Integration Workflow: HaloCAD for PLM and HaloENGINE*

1. The user performs a check-out (download) or check-in (upload) action.

2. HaloCAD for PLM fetches the user-selected file and collects its metadata. The metadata is sent to the HaloENGINE, where the appropriate action and label information are derived and provided back to HaloCAD for PLM.

3. HaloCAD for PLM executes actions based on the derived action and label information:

   1. If no valid action is available, the file is downloaded without modification.

   2. During check-in, if a valid action with a label is found, HaloCAD for PLM removes the label and stores the decrypted file in PLM.

   3. During check-out, if a valid action with a label is found, HaloCAD for PLM applies the label.

   4. If a block action rule is configured in HaloENGINE, HaloCAD for PLM prevents file downloads.

4. The protected file is returned to the user.

5. HaloCAD for PLM captures the event details and forwards them to the HaloENGINE monitor log for auditing.

---
version: "6.10"
language: "en"
---
# Installing the HaloENGINE

This chapter walks you through the steps of installing HaloENGINE using graphical and silent methods. By default, HaloENGINE is installed in Microsoft Purview Information Protection (MPIP) mode, which provides label-based protection. Note: Microsoft Purview Information Protection (formerly known as Microsoft Information Protection, MIP). Please note that the term "MIP" is still used in various places all across the manual. Both terminologies, MIP and MPIP, are used interchangeably throughout this document.

## HaloENGINE With or Without Monitor Log Dashboard Integration

It is necessary to know how you would like to install the HaloENGINE with the following options. HaloENGINE can be used with or without the Monitor Log Dashboard Integration.

**Option 1: HaloENGINE with Monitor Log Dashboard**

The Monitor Log Dashboard is connected to HaloENGINE through the MongoDB database. During the installation process, you have the option to choose from the following two, depending on your database setup:

1. First-time installation of the MongoDB database.

   This applies to an environment without a MongoDB database. While installing HaloENGINE, select **Install MongoDB** in the UI. The dashboard can only be successfully started over this connection.
2. Use the existing MongoDB database.

   This applies to an environment where a MongoDB database has already been installed. To connect, all you need to do is use the current MongoDB connection string.

**Option 2: HaloENGINE without Monitor Log Dashboard**

If you do not want to integrate the dashboard, installing the MongoDB database is not necessary. At a later time, if you wish to integrate with the dashboard, you will need to uninstall and reinstall HaloENGINE using Option 1.

## Interactive Installation

Use the GUI-based setup application included in the installation package to install HaloENGINE. If you want to run without a GUI, refer to the section "[++Silent Installation++](https://help.secude.com/haloengine/6.10/installing-the-haloengine.md#silent)". Note: This version does not support silent installation for integrating HaloENGINE with the dashboard. If you want to combine, use the GUI installer.

**Prerequisites**

Before installing HaloENGINE, ensure that the following requirements are met:

1. Ensure that the previously installed HaloENGINE Service is completely uninstalled.

2. Azure application registration details: Refer to the section "[Registering an Application in Microsoft Entra ID](https://help.secude.com/haloengine/6.10/prerequisites.md#Register)".

3. The certificate required for MPIP authentication must be installed in the Local Computer certificate store, along with the Root CA and Intermediate CA certificates.

   * If the certificate is CA-signed, install all related certificates in their respective stores (Root, Intermediate, and Personal).

   * If the certificate is self-signed, install it in both the Trusted Root Certification Authorities and Personal stores of the Local Computer.

4. Administrator rights: The user performing the HaloENGINE installation must have administrator privileges.

**Installation Procedure**

1. To begin the interactive installation, double-click the installer `HaloENGINE_Setup.exe` file. Depending on your Windows security settings, you may get a warning such as "*Do you want to allow the following program to make changes to this computer?"* . If you get this security warning, click the **Yes** button to continue the installation.

2. When the installer starts, the **Startup** dialog appears, followed by the **Welcome** dialog.

   ![Startup Dialog.png](https://help.secude.com/__attachments/a_29eeb8c1ee43d453d0d041381be278e97c719596c54d9e6881201e4e4f375889/Startup%20Dialog.png?cb=8b8736eea34e3cb89a9fdd3e83e62bf6)

   *Startup Dialog*  
   ![1_Welcome dialog.png](https://help.secude.com/__attachments/a_12130efa6c7049ee91756922d977c6f1d44b1726e58ad68fca35c0544709b4d6/1_Welcome%20dialog.png?cb=4d4085cf10090b80b84c8352c63459a6)

   *Welcome dialog*
3. Click **Next** to continue the installation. The **End-User License Agreement (EULA)** dialog appears.

   ![2_End-User License Agreement dialog.png](https://help.secude.com/__attachments/a_88df24c78802215b787ceb946c7f27c5ccb2f0e6b27c4ec8b69fd3f94382eb68/2_End-User%20License%20Agreement%20dialog.png?cb=7b871dd0d5dbe241abc0a14d857011a2)

   *End-User License Agreement dialog*
4. Read the **End-User License Agreement** . If you agree, select **I accept the terms in the License Agreement** , and click **Next** to continue.The Tomcat memory pool size configuration dialog appears.

   ![3_Tomcat pool size configuration dialog.png](https://help.secude.com/__attachments/a_9ba45da63c60b3791c31fd1a0d5218a33e95209bbe8b1b23b27e2144de696d95/3_Tomcat%20pool%20size%20configuration%20dialog.png?cb=781f55e44c97a0d03e64a805321ded20)

   *Tomcat pool size configuration dialog*
5. If you want to change the default values of the **Initial Memory Pool** and **Total Memory Pool**, enter the amount of memory you want to allocate. Note: Ensure that the Total Memory Pool does not exceed the System's available 3/4th RAM.

6. Click **Next**. The destination folder selection dialog appears:

   ![4_Destination Folder dialog.png](https://help.secude.com/__attachments/a_f098a765270fa8f9bbb30a3d9092f98e6003ad4d0aa3075bbdd4433b59be19da/4_Destination%20Folder%20dialog.png?cb=01a93127a3595f43365922e2abe61505)

   *Destination folder selection dialog*
7. By default, application files are stored in the program files directory (`C:\Program Files\Secude\`). If you would like to choose an alternate location, click the **Browse** button and select your location preference. When you are finished, click **Next**.

8. The certificate-based authentication dialog appears. To avoid errors, please ensure that you enter the correct Azure application registration details in the installation wizard.

   ![5_Certificate-based authentication dialog.png](https://help.secude.com/__attachments/a_50b4262de7e8f45cac6e6f23800b4055a94ab5ed3d09cd2edd740041b46ad0e6/5_Certificate-based%20authentication%20dialog.png?cb=78363a0a552718c6583e33918767aea3)

   *Certificate-based authentication* *dialog*
   1. **Azure Application ID** : Enter your application ID. For example, `9f0de2dd-8d49-4a3f-9676-bf4b6ff17d44`

   2. **Tenant ID/Tenant Name** :Enter your Microsoft Entra tenant name (for example, `contoso.onmicrosoft.com`) or its tenant ID (for example, `8c425ee7-352a-4657-ac77-7dc198712cb3`)**.**

   3. **Thumbprint** : Enter the thumbprint of the MPIP authentication certificate installed in the **Local Computer** certificate store.

   4. **Cloud Type** : **Commercial** is selected by default. Based on your Azure subscription and configuration, select the required cloud type from the list: Commercial, Custom, Germany, US_DoD, US_GCC, US_GCC_High, US_Sec, US_Nat, or China_01. If you select **Custom** , enter the appropriate URLs in the **Protection Cloud URL** (for example, `https://api.aadrm.com`) and **Policy Cloud URL** (for example, `https://dataservice.protection.outlook.com`) fields.

   5. Click **Next**.

9. The installation begins, and the progress is displayed in the dialog.

   ![6_Installing dialog.png](https://help.secude.com/__attachments/a_dd476abc3165535c2815f2f102b98c5a26b5ade5e07feb1dfaea9fb8d7c16f4a/6_Installing%20dialog.png?cb=4ac328cebfbc419293ccfb9f56d8c8f8)

   *Installation progress dialog*
10. When the installation is complete, a message appears confirming that the HaloENGINE has been successfully installed. Select one of the following options to configure the HaloENGINE.

    ![7_HaloENGINE setup without MongoDB.png](/__attachments/a_72e84c2a75c02654314e751e94b3b86476c89ea0b39cbdbd5539725831b72fe2/7_HaloENGINE%20setup%20without%20MongoDB.png?cb=c625c653730e9e2d90b9305100b6e1cb)

    *HaloENGINE setup without MongoDB*
    1. HaloENGINE without MongoDB: Select the **Configure HaloENGINE** option if you do not want to integrate the dashboard. As shown above, the configuration screen will display a link. Click the link to access the HaloENGINE admin portal, then proceed with [++point 12++](/haloengine/6.10/installing-the-haloengine.md#12).

    2. HaloENGINE withMongoDB: Select the **Install MongoDB** option if MongoDB is not currently installed in your environment. Click **Next** . The installation starts by displaying a progress bar that indicates the progress of the process. Please be patient as this will take some time. After installing MongoDB, the configuration screen will display a link. Click the link to access the HaloENGINE admin portal, then proceed with [++point 12++](/haloengine/6.10/installing-the-haloengine.md#12).

       ![8_HaloENGINE setup completed dialog with MongoDB.png](/__attachments/a_f870de9d8c8d4762f0eeae916238b9f43d1e9b2d573ac365221b57f059120fe9/8_HaloENGINE%20setup%20completed%20dialog%20with%20MongoDB.png?cb=e8935bd6808bca638ab167b33eda1b42)

       *MongoDBHaloENGINE setup with pre-installed*
    3. HaloENGINE using pre-installed MongoDB:Select the **Use Existing Instance of MongoDB** option if the database already exists, and then enter the MongoDB connection string in the **MongoDB Uri** field. The connection string varies depending on your configuration options.

       * With authentication, use the format `<mongodb>://<username>:<password>@<hostname>:<port>/<db_name>?authSource=admin>`. For example: `mongodb://myDatabaseUser:D1fficultP%40ssw0rd@cluster0.example.mongodb.net/?retryWrites=true&w=majority`

       * Without authentication, use the format `<mongodb>://<hostname>:<port>/<dbname>?directConnection=true>`. For example: `mongodb://localhost:27017/secude?directConnection=true`

    4. Click **Next** to proceed.

11. The configuration screen displays a link. Click the link to access the HaloENGINE Admin Portal.

    ![9_HaloENGINE additional setup completed successfully.png](/__attachments/a_b44f1b1ef6d6f8bc80d6fe458b45e38d2c92b076d4821d6e023b0702b463a203/9_HaloENGINE%20additional%20setup%20completed%20successfully.png?cb=6631baf80570116bee51fccb9101e7a5)

    *HaloENGINE with additional setup completed successfully*
12. Once you click the link, the admin portal opens in your default browser, and a shortcut icon ![Desktop.png](https://help.secude.com/__attachments/a_167460eb814c6471d5f5e87a0ee4fbc8c4629ae2936610430c6b63c7b08cbb0a/Desktop.png?cb=b0f1208e8294d188d77cc3f7694ddc56) is created on your desktop.

**HaloENGINE Tomcat service start-up delay after reboot**

Since the HaloENGINE Tomcat service is set to Automatic (Delayed Start), it will start with a delay of approximately three minutes after a reboot or shutdown. The exact delay depends on the machine, as services marked Automatic (Delayed Start) are initiated only after all other Automatic services have started.

**What to do next**

1. Verify that the **Maximum memory pool size** in HaloENGINE Tomcat (`...bin/HaloENGINE_Tomcat10.exe`) does not exceed the system RAM. After setting up the HaloENGINE certificate, verify that the **maxSavePostSize** (bytes) in the Connector (SSLEnabled in `server.xml`) is smaller than the "Maximum memory pool size".

2. If you want to send large files (2GB) forward and backward, ensure that the "Maximum memory pool size" is greater than the maxSavePostSize (2GB, as specified above).

3. Please refer to the section "[++Initial Configuration of HaloENGINE Admin Portal++](https://help.secude.com/haloengine/6.10/initial-configuration-of-haloengine-admin-portal.md#int)++"++ to know more about the initial configuration.

## Silent Installation

Besides graphical mode, the HaloENGINE can be installed in silent mode, which does not require user involvement or display a user interface. It is a convenient way to streamline the installation process using the command at once.

1. Open a command prompt and go to the installer's location.

2. Follow the steps below to see the list of options present in silent mode:

   Type `HaloENGINE_Setup.exe -help`

   Press **Enter**

   Output

   `...`

   `HaloENGINE_Setup.exe -install -initmempool <Initial memory pool size in MB(s). Minimum size is 128 MB> -totalmempool <Total memory pool size in MB(s). Maximum size is 3/4 of total RAM size.> -dir <destination_directory> -applicationid <application_id> -tenantid <tenant_id> -thumbprint <thumb_print> -cloudtype <(Commercial|Custom|Germany|US_DoD|US_GCC|US_GCC_HIGH|US_Sec|US_Nat|China_01) (if cloudtype is Custom) <protectioncloudurl> <policycloudurl>`

   `HaloENGINE_Setup.exe -uninstall -keepconfig <true|false>`

3. The following command shows how to install and initialize HaloENGINE.

   `HaloENGINE_Setup.exe -install -initmempool 1024 -totalmempool 2048 -dir "C:\Program Files\Secude" -applicationid 9f0de2dd-8d49-4a3f-9676-bf4b6ff17d44 -tenantid 8c425ee7-352a-4657-ac77-7dc198712cb3 -thumbprint 961602617275c2ab538cf28bb3648c0c6d97edab -cloudtype Custom https://api.aadrm.com https://dataservice.protection.outlook.com`

4. Press **Enter**.

5. Please wait until the success message appears. When it is displayed, the installation process is complete, and you can proceed to access the HaloENGINE Admin Portal.

---
version: "6.10"
language: "en"
---
# Phase 1. Certificate Configuration

The HaloENGINE Admin portal includes a reliable approach for dealing with certificates. It provides two approaches for dealing with a server certificate:

1. A self-signed server certificate is generated by the server itself.

2. Or using the organization's own certificate.

The figure below depicts the high-level steps involved in administering the server certificate.  
![HaloENGINE_Server Certificate.png](https://help.secude.com/__attachments/a_bb1cce3f4e7b11bf8b48549d42c27cfd039cdc61a18c0ee6ff28baa140509105/HaloENGINE_Server%20Certificate.png?cb=e7a0c13694a0523a292a1be093ca180d)

*HaloENGINE Certificate*

HaloCAD for SOLIDWORKS PDM client relies on server certificate authentication, therefore, you can use either a self-signed certificate (`HaloENGINEServer.cer`) or a company-owned signed certificate for authentication.

The figure below depicts the high-level steps involved in administering the client certificate.  
![HaloENGINE_Client Certificate.png](https://help.secude.com/__attachments/a_7b80f0c391f30cd6b9cde259e19abe00ea3f97412becf4e48a3ca6dd925d2c2d/HaloENGINE_Client%20Certificate.png?cb=aafe9d3b08882514ad7f628da4cb48be)

*HaloENGINE Client Certificate*

## **Step 1. Use Server Certificate Generated by HaloENGINE Admin Portal (Option 1)**

**Step 1a. Create a Self-Signed HaloENGINE (Server) Certificate**

1. On the left navigation bar, click **System Configuration** , go to the **Certificate Configuration** tab, and click **Configure**.

   ![System Configuration.png](https://help.secude.com/__attachments/a_85fcd30850e8c4e0122cebe57fffa0560dd293613ff763b6a7c68b876c3dfd7f/System%20Configuration.png?cb=85f5770c4cb14d9926c332396869022a)

   *System Configuration page*
2. The *Overview*page appears as shown in the figure below:

   ![Default Certificate Page.png](https://help.secude.com/__attachments/a_d293d7c223b6468ea581aa17c9364830fb59c15621dd53a027d808899af52fc4/Default%20Certificate%20Page.png?cb=83efbaa2c9a0d517052c28ce571da160)

   *Overview page*
3. Click **Server Certificate** , and then click the **Create Certificate** button.

4. The *Add Server Certificate* page appears as shown in the figure below:

   ![Creating a server certificate.png](https://help.secude.com/__attachments/a_788ba8e6e4e412b88f0be8249006bd92df693bab67f97b70165ffc84b9d36ee6/Creating%20a%20server%20certificate.png?cb=06ca26653a0ccd3c9723a64e2bf0c109)

   *Creating a server certificate*
5. **Enter certificate subject name** − Enter a subject name. For example: `CN=COMMONENG.LOCAL, OU=SECUDE, L=ENGLAND, ST=LONDON`.

6. **Enter server keystore password** − Enter a server Keystore password. For example, `HaloENGINE_1`. Note: Copy and paste are not allowed in this field. Please refer to the section "[Keystore password policy](https://help.secude.com/haloengine/6.10/phase-1-certificate-configuration.md#kpp)".

7. **Validity (days)** − Enter certificate validity in days (1 to 5475). The default value is 3650.

8. **Enter subject alternative name (IP addresses)** − Enter the server IP address. For example, `10.91.0.171`.

9. **Enter subject alternative name (DNS)** − Enter an alternative subject name (FQDN). For example, `COMMONENG.LOCAL`.

10. Click **Save**.

    **Results**:
    1. A confirmation message appears after the certificate is successfully updated.

    2. A self-signed server certificate (`HaloENGINEServer.cer`) is generated along with two other files (`HaloENGINEServer.csr, serverKeystore.jks`) in `...Tomcat\conf\cert`.

    3. The page displays the server certificate information.

    **What to do next**
    1. For client systems such as Windchill, Teamcenter, Keytech, or Autodesk Vault, proceed to [Step 4](/haloengine/6.10/phase-1-certificate-configuration.md#4) to generate the client keystore.

    2. In case of the SOLIDWORKS PDM client/HaloENGINE_API, download the self-signed certificate (`HaloENGINEServer.cer`) and install it into the Trusted Root Certification Authorities on the client machine.

    3. Click the download icon, and in the **Download Server Certificate** dialog, click **Download CER File** to download a copy of the self-signed server certificate `HaloENGINEServer.cer`.

       ![Download Server Certificate.png](/__attachments/a_229762ae3cb621b878d83530b0a9daf90975eea01fa12a3f38443dc050748eac/Download%20Server%20Certificate.png?cb=46275aa29e6e69ced4937e83f1a9f6ef)

       *Download Server Certificate*
11. Click **Close** to exit the dialog.

**Keystore Password Policy**

Before creating the password, make sure to follow the policies listed below:

* Passwords must be between **6** to **30 characters** long

* The password should not contain a space

* The first letter should be an alphabetic character \[**upper** or **lower** case letter\]

* It must contain at least **1 numerical** character \[0-9\]

* It must contain at least **1 symbol** \[$ _ #\]

  For example: **HaloENGINE_1**

**Step 1b. For a CA-Signed HaloENGINE Certificate**

You can convert the self-signed certificate created in [Step 1a](https://help.secude.com/haloengine/6.10/phase-1-certificate-configuration.md#1a) into a CA-Signed certificate by signing it with your Certificate Authority (CA).

1. Click the download icon, and in the **Download Server Certificate** dialog, click **Download CSR File** to download the Certificate Signing Request (CSR) `HaloENGINEServer.csr`.

2. Submit the `HaloENGINEServer.csr` file to your Certificate Authority to obtain the signed certificate in `HaloENGINEServer.cer` format.

3. Import the CA - refer to [Step 3](https://help.secude.com/haloengine/6.10/phase-1-certificate-configuration.md#3). Note that a signed certificate cannot be imported until its corresponding CA certificate has been uploaded.

4. As the certificate (`HaloENGINEServer.cer`) is signed now, you need to import it into the HaloENGINETomcat Service.

5. **Import Signed Certificate:**

   1. After importing the CA (in Step 3: Import Intermediate CAs), continue to import the signed certificate.

   2. From the list, choose **Import signed certificate**.

   3. Click on the attachment button and select the signed `HaloENGINEServer.cer` certificate from the **Open**dialog box.

      ![Importing Signed HaloENGINEServer.cer certificate.png](/__attachments/a_b4f40237e8f289eaea21026099531a5dad1ac09c5cfa82fa507c63ffcc9ff6bc/Importing%20Signed%20HaloENGINEServer.cer%20certificate.png?cb=5b204c748eebd5ff7ed2d27ec8ee152d)

      *Importing the signed HaloENGINEServer.cer certificate*

      **Results** : The name of the certificate will be displayed on the screen, and you will receive a confirmation message after uploading the certificate. To close the dialog, click **Close** . The *Server Certificate* page appears as shown in the figure below when you upload your certificate:  
      ![Signed Server certificate and Root CA #1.png](/__attachments/a_0e44725f2cb319f7a28014510a1d5d5cb6b11487c5a87d89c6111a53f913661d/Signed%20Server%20certificate%20and%20Root%20CA%20%231.png?cb=e6586a9a0732193b957eb465c7c1da68)

      *Signed Server certificate and Root CA #1*

      Illustration for the self-signed certificate.  
      ![Self-Signed Server certificate #2.png](/__attachments/a_6735d0cd697af7345c9821ba5b3602365a5cb6f6994068090ab0a85c7dcccb53/Self-Signed%20Server%20certificate%20%232.png?cb=8202ab14fb3944aff89feb1b5492844c)

      *Self-Signed Server certificate #2*
6. **What to do next** : Continue from [Step 4](https://help.secude.com/haloengine/6.10/phase-1-certificate-configuration.md#4).

### Step 2. Use Company Own Certificate as the Server Certificate (Option 2)

Alternatively, if you already have a certificate for your company, you can use it with the HaloENGINE Admin Portal. However, the company's own certificate must be converted to work with HaloENGINE. Conversion is as simple as uploading to the admin portal and downloading it as `HaloENGINEServer.cer`.

To convert the company's own certificate, follow the steps below:

1. On the left navigation bar, click **System Configuration** , go to the **Certificate Configuration** tab, and click **Configure**.

2. Click **Server Certificate** , and then click **Convert Certificate**.

3. The **Convert .pfx/.p12 to HaloENGINE Certificate**dialog appears.

4. Enter the source password for the PFX/P12 file you want to convert. Note: Copying and pasting are not allowed in this field.

5. Enter the server keystore password. Please refer to the section "[Keystore password policy](https://help.secude.com/haloengine/6.10/phase-1-certificate-configuration.md#kpp)".

6. Click the **attachment** button and select the PFX/P12 file from the **Open** dialog box.

   ![Convert existing certificate into HaloENGINE certificate.png](https://help.secude.com/__attachments/a_282aa88ba9dd85233f43c5202614de7be2a26f59584ab6daf8f0cad8544df25c/Convert%20existing%20certificate%20into%20HaloENGINE%20certificate.png?cb=fa10c7c3404e1abaaa076e02aa95093d)

   *Convert the existing certificate*
7. The certificate's name is displayed on the page.

   **Results**:
   1. A confirmation message appears once the certificate is uploaded successfully.

   2. Click **Close**to exit the dialog box.

**What to do next**

1. Import the CA - refer to [Step 3](https://help.secude.com/haloengine/6.10/phase-1-certificate-configuration.md#3). Please note that a signed certificate cannot be imported before uploading its corresponding CA.

2. If your certificate is signed, you need to import it into the HaloENGINE Tomcat Service - refer to [Step 1b](https://help.secude.com/haloengine/6.10/phase-1-certificate-configuration.md#1b).

3. After uploading your certificates, the *Server Certificate* page looks as shown in the figure below:

   ![Company own certificate and its Root CA.png](https://help.secude.com/__attachments/a_e1c1fa857bc69430c11777dc1871b005a8a77dbbc643d956d91ed7c61d67a703/Company%20own%20certificate%20and%20its%20Root%20CA.png?cb=8384ccbe7574e736bb903a6fded2f0c9)

   *Company own certificate and its Root CA*
4. Continue from [Step 4](https://help.secude.com/haloengine/6.10/phase-1-certificate-configuration.md#4).

#### **Step 3. Import Intermediate CAs**

To evaluate a system's overall security level, the HaloENGINE needs a root CA or intermediate CA. You must include all intermediate CAs in the following cases:

1. If an intermediate CA has signed `HaloENGINEServer.cer` -[Step 1b](https://help.secude.com/haloengine/6.10/phase-1-certificate-configuration.md#1b).

2. If you use the company's own certificate, which is signed by an intermediate CA - [Step 2](https://help.secude.com/haloengine/6.10/phase-1-certificate-configuration.md#2).

To upload the CA Certificate, follow the steps below:

1. Click the upload icon, and a pop-up window **Upload Signed Server Certificate / CA Certificate**appears.

2. From the list, choose **Import CA certificate** and enter an alias name of your choice for Root CA (e.g., `itadminsca`).

3. Click on the attachment button and select your root CA from the **Open**dialog box.

   ![Importing CA certificate.png](https://help.secude.com/__attachments/a_65e99b81164680eb70c6138599f53dd4e50c6413b6767f13a95bb15686d63b77/Importing%20CA%20certificate.png?cb=7c9eff13301e3cabc58d91e105247fb7)

   *Importing the CA certificate*
4. The certificate name appears on the page.

   **Results**:
   1. A confirmation message appears after uploading the certificate

   2. Repeat the steps above to add all intermediate CAs.

##### **Step 4. Use Client Certificate from Admin Portal (Option 1)**

Similar to how the Server certificate is handled, HaloENGINE provides two ways to handle a client certificate:

1. A self-signed client certificate is generated by the server - refer to the below [Step 4a](https://help.secude.com/haloengine/6.10/phase-1-certificate-configuration.md#4a).

2. Another option is to use the company's own certificate; refer to [Step 5](https://help.secude.com/haloengine/6.10/phase-1-certificate-configuration.md#step5) for SOLIDWORKS PDM and HaloENGINE API clients.

**Step 4a. For a Self-Signed HaloENGINE Client Certificate**

This instruction applies to the clients listed below. Note: Self-signed client certificates can be generated using the HaloENGINE admin portal, and they are added to the client Keystore at the time of creation.  

| **Client systems** | **Required Keystore format** |
|--------------------|------------------------------|
| Windchill          | `.jks`                       |
| Teamcenter         | `.jks`                       |
| Autodesk_Vault     | `.jks`                       |
| Keytech            | `.jks`                       |

*Client Keystore*

Follow the steps below to create a self-signed client certificate:

1. On the left navigation bar, click **System Configuration** , go to the **Certificate Configuration** tab, and click **Configure**.

2. Click **Client Certificate** and then click **Create Certificate**button.

3. The *Add Client Certificate* page appears as shown in the figure below:

   ![Creating a client certificate.png](https://help.secude.com/__attachments/a_6d47272144b3f3793cf743ebf44dbebd7108d05c1b6cad53db4a4ffc0ab7f5bc/Creating%20a%20client%20certificate.png?cb=c23f269b13dc050d1c1e3440f216a189)

   *Creating a client certificate*
4. **Enter keystore name** − Enter a Keystore name for the client. For example: `CLIENTKEY`.

5. **Enter certificate subject name** −Enter a subject name. For example: `CN=DESKTOP0001, O=SECUDE, L=ENGLAND, ST=LONDON`. **Enter client keystore password** −Enter a client Keystore password. For example: `ckpass1#`. Note: Copying and pasting are not allowed in this field. Please refer to the section "[Keystore password policy](https://help.secude.com/haloengine/6.10/phase-1-certificate-configuration.md#kpp)".

6. **Enter a certificate alias** −Enter an alias name. For example: `SLVU148CLIENT`.

7. **Validity (days)** − The default period is 3650 days.

8. Click **Save**.

   **Results**:
   1. A confirmation message appears after the client's certificates are successfully added.

   2. A self-signed (`CLIENTKEY.cer`) certificate is generated along with two other files (`CLIENTKEY.pfx`, `CLIENTKEY.jks`) in `...Tomcat\conf\cert`. The user-specified Keystore name is used as the filename.

   3. Click **Close** to exit the page.

   4. The client certificate is generated and installed into the HaloENGINE Tomcat Service.

**What to do next: Download the HaloENGINE Client Certificate**.

To establish the connection between the client and server, you need to download this certificate/Keystore and add it to the client machine.

1. Click the download icon, and the **Download Client Certificate**dialog appears.

2. Click **Download JKS File** to download a copy of the JKS file. In the example shown above, a file named `CLIENTKEY.jks` is downloaded. Note: HaloENGINE client systems, such as Windchill, Teamcenter, Autodesk_Vault, and Keytech, require a JKS Keystore to operate.

   ![Downloading client certificate.png](https://help.secude.com/__attachments/a_47b34a635f3a28713180a7587466a6ddec8b71457dd31fdd531109f0664831a6/Downloading%20client%20certificate.png?cb=39a58f4c0c1532fbb8875e7003af729d)

   *Downloading the client certificate*
3. Click **Close** to exit the page.

##### **Step 5. Use Company's Own Certificate as the Client Certificate (Option 2)**

If you want to use your company's certificate, you must add it to the HaloENGINE Tomcat Service. This option applies to SOLIDWORKS PDM and HaloENGINE API clients.

Prerequisites:

1. In the case of other clients, have client certificates ready in advance.

2. If your client certificate is signed by an intermediate CA, you must upload it as described in section [Step 3](https://help.secude.com/haloengine/6.10/phase-1-certificate-configuration.md#3).

To upload an existing client certificate, follow the steps below:

1. Click **Import Certificate**.

2. The **Import Client Certificate**dialog appears.

3. Click on the attachment button and select the client certificate from the **Open**dialog box.

4. Perform the same steps to upload other client certificates as well.

   ![Uploading existing client certificates.png](https://help.secude.com/__attachments/a_dde32fd7183a405b24540f79662c8c1ca0b15f97498810e7fad976a468e1decf/Uploading%20existing%20client%20certificates.png?cb=545ce8165c78b178355c1c698ebd49f6)

   *Uploading existing client certificates*
5. Click **Close** to exit the dialog.

   **Results** : After uploading your certificates, the *Client Certificate*page looks as shown in the figure below:  
   ![Uploaded client certificates.png](https://help.secude.com/__attachments/a_0a2180e67fcdf44da53d27f913505e2286f70c9b0bb6d098675e888327ec24dd/Uploaded%20client%20certificates.png?cb=dc3e0ee32ebc3ed0c824a504973d19d8)

   *Uploaded client certificates*

##### How to Delete the HaloENGINE Client Certificate?

To remove the client certificate, perform the following steps:

1. On the left navigation bar, click **System Configuration** , go to the **Certificate Configuration** tab, and click **Configure** . Then, click **Client Certificate** in the top-right corner.

2. Select the client certificate and click the delete icon under the **Actions** column.

3. In the prompt *"Are you sure to delete?"* , click **OK** . By clicking **OK**, you confirm the permanent deletion of the client certificate.

   **Result:** A confirmation message appears after the certificates are successfully deleted.

##### How to Delete the HaloENGINE Certificate?

**Deleting the server certificate removes all certificates.**

Removing the server certificate will permanently delete all other certificates, including client and CA certificates. After deletion, the admin portal will not load. To access the portal again, manually change the protocol to **HTTP** and the port number to **8383**, and clear your browsing data.

**CA Certificate(s)**

To remove the CA certificate(s), perform the following steps:

1. On the left navigation bar, click **System Configuration** , go to the **Certificate Configuration** tab, and click **Configure**.

2. Click **Server Certificate** in the center.

3. Select the CA certificate and click the delete icon under the **Actions** column.

4. In the prompt *"Are you sure to delete server CA certificate?"* , click **Yes** . By clicking **Yes**, you confirm the deletion of the CA certificate from the Keystore.

   **Result:** A confirmation message appears after the certificates are successfully deleted.

**Server** **Certificate**

To remove the server certificate, follow these instructions:

1. On the left navigation bar, click **System Configuration** , go to the **Certificate Configuration** tab, and click **Configure**.

2. Click **Server Certificate** in the center.

3. Select the server certificate and click the delete icon under the **Actions** column.

4. In the prompt *"Are you sure to delete the HaloENGINE Certificate?"* , click **OK** . By clicking **OK**, you confirm permanent deletion of the Server and Client certificates from the Keystore.

   **Result:** A confirmation message appears after the certificates are successfully deleted.

**Restart the HaloENGINE Tomcat service**

Restart the HaloENGINE Tomcat service after completing all necessary certificate-related changes.

---
version: "6.10"
language: "en"
---
# Phase 7. Tenant Configuration

Prerequisite: Make sure that you have configured the required details as described in the section "[Settings in Azure Portal](https://help.secude.com/haloengine/6.10/prerequisites.md#azure)".

For user authentication and validation, you need to register the domain details as instructed below:

1. On the left navigation bar, click **Customer Configuration**, and then select the customer ID (halo_customer) from the list.

2. On the **Tenant Configuration** tab, click **Configure**.

3. Click the plus icon to open the *User Domain-Tenant Configuration* page, as shown below.

   ![Registering a domain.png](https://help.secude.com/__attachments/a_a2474d68bb6afe13ad5454864079ccdb2e4ba820016868be25e42f37bf8029fc/Registering%20a%20domain.png?cb=17b7924a947b74dffe563fbcc711d0d5)

   *Registering a domain page*

   Note: Values shown in the example screen have been modified for security reasons.
4. **Tenant Name** − Enter the name of your Microsoft Entra tenant. Note: Maximum 30 characters, alphanumeric characters, hyphen, and underscore are only allowed. For example, if your tenant domain is "`Contoso.onmicrosoft.com`," enter only "Contoso." Ensure that the name specified in the **Redirect URL** exactly matches the Tenant Name configured in the Admin Portal. This field is case-sensitive.

5. **Tenant ID** − Enter the unique identifier of your Microsoft Entra ID instance. For example, `8c425ee7-352a-4657-ac77-7dc198712cb3`

6. **Client ID** − Enter the identifier that is assigned when registering the application. For example, `c07e4bfa-95a4-4a08-94b0-0eef20d04398`

7. **Azure Cloud Identifier** − Select the identifier from the list. For example: `.com`, `.us`

8. **Client Scope** − Enter the scope assigned to the application. For example, `api://halocoreadmin/Config.ReadWrites`

9. **Client Secret** − Enter the secret assigned to the application. For example, `T928y~4ueJZFNAlf6QcUAspdz0Xub_9.454z3HH1`. Please refer to the section "[Step 3: Certificates \& Secrets](https://help.secude.com/haloengine/6.10/prerequisites.md#secretkey)".

10. **Client Domain Name (Alias Name)** − Enter an alias name for your domain. For example, `halosecude.onmicrosoft.com`.

11. Click **Save**and repeat the above steps to register other tenants.

    **Results**: A confirmation message appears after the user domain is registered.

**Related tasks**:

1. Use the icons to edit or delete a tenant.

2. Click the **Tenant Details**icon to view tenant information.

3. Registered tenants are listed on the *User Domain-Tenant Configuration* page.

**What to do next**:

1. Restart the HaloENGINE Tomcat service for the configuration change to take effect.

2. Log in using the admin account or the user account.

## User Login (Super Admin/Azure Users)

After completing tenant configuration and reloading, you will be redirected to the login page. Choose one of the following options to log in to the portal.

**Option 1** − Default Super Admin Account

**Option 2**− Microsoft account (log in using user account - Customer_Admin or Customer_User)

1. Click on the button **Continue with Microsoft**.

   ![Microsoft Azure Login #1.png](https://help.secude.com/__attachments/a_f2ea6503e02800eb41f0c2e9d73787a00490ab59d3975df5a66ebf15f1b80850/Microsoft%20Azure%20Login%20%231.png?cb=7f3517559b87273bddb1769c39e5d16c)

   *Microsoft Azure Login #1*
2. Enter the alias name that is entered in the HaloENGINE Admin Portal and click **Azure Login**.

3. Microsoft Sign-In Assistant requests to enter your user credentials.

4. Enter your Azure credentials and click **Sign in**.

   ![Microsoft Azure Login #2.png](https://help.secude.com/__attachments/a_ae2a785ae3ce338026c6b9c84bb873dfbbd26e9ef7d5f9a714e1678847233e1c/Microsoft%20Azure%20Login%20%232.png?cb=86d7c5f43fcee9f24df1a6bce3807134)

   *Microsoft Azure Login #2*
5. For the prompt "*Stay signed in?"* , click **No** or **Yes** based on your preference.

6. After the successful authentication, you will be logged into the portal. Please note that if a user logs into the HaloENGINE Admin Portal using the Azure user account, the access token issued remains valid for a period. Therefore, even if you close the browser and re-open it or refresh the page, you do not need to enter the credentials again to sign in. However, to enforce the user login, the user must first sign out of the Azure portal.

7. For illustration purposes, user accounts are shown in the images below:

   ![Admin account.png](https://help.secude.com/__attachments/a_d1ee7b8d4a03a14af2db78465a256659f0efd34e1c8736b2c6e11b8e5ec3a09f/Admin%20account.png?cb=90b75151aaadde9850c1336c2c38dfa2)

   *Admin account*  
   ![User account.png](https://help.secude.com/__attachments/a_5c99629c8100f51a8b626ed6877c97f0d59b20d1084dca898c1eedcc528afe0c/User%20account.png?cb=a23d7c318e50c06bdeb0261ce0979483)

   *User account*

**Methods to log in admin portal**

1. If you are using the Remote Desktop Protocol (RDP) to connect to your HaloENGINE system and log into the Admin Portal, you need to use the default admin account.

2. Alternatively, if you have enabled "Configure Remote Access" you could sign in via the Microsoft Sign-in option and with the default admin account. Use the following URL:

   1. `http://<ip>:<port>/haloengine-admin/ui/app/login`

   2. For example, `https://10.41.14.69:8746/haloengine-admin/ui/app/login`

---
version: "6.10"
language: "en"
---
# Phase 2. Activate License (First time)

Prerequisite: Make sure you have a license file from Secude.

To activate the license, follow the steps outlined below:

1. On the left navigation bar, click **Customer Configuration**, and then select the customer ID from the list. The following page appears, as shown in the figure below:

   ![Customer Configuration.png](https://help.secude.com/__attachments/a_b21f4a3f8dfd9598adf4a76f44e22a792ae7de79a866e31fa092d9616ddcc0c5/Customer%20Configuration.png?cb=987773e9064c23a4140ed9cc72927351)

   *Customer ID page*
2. The default customer name is halo_customer, but you can modify it if required.

   ![Customer-specific configuration.png](https://help.secude.com/__attachments/a_c3bc2a9473428b96dc03f8d319b47d3816a9f029f7c6a4bea65ffc88f2a34ff8/Customer-specific%20configuration.png?cb=af5ced67b616cf190fa0a0f63ae267d4)

   *Customer configuration page*
3. On the **License Configuration** tab, click **Configure**.

4. The *HaloENGINE License Information* page appears as shown in the figure below:

   ![License Activation page #1.png](https://help.secude.com/__attachments/a_ae03d87fe8fa8882c57646b95d5e36912d2c4f6a484b2bd7218ef57e12ffda09/License%20Activation%20page%20%231.png?cb=4e6ed38b6dd6bc19796f7e9cd245cd4e)

   *License activation page #1*
5. Click **Activate License** and then on the*License Details* page, click **Upload License File**.

   ![License Activation page #2.png](https://help.secude.com/__attachments/a_c4d7e900ef434b766ab41f5efbe1032c5908cab6289c5c8d7a7e1185a7d14ec8/License%20Activation%20page%20%232.png?cb=f8a0908edf49315feba5dcc2e4d292f8)

   *License activation page #2*
6. Select the `license.lic` file from the **Open**dialog box.

   **Results**:
   1. A confirmation message appears after the file is uploaded successfully.

   2. Click **Close** to exit the dialog box.

   **What to do next**:
   1. Restart the HaloENGINE Tomcat Service for the license file changes to take effect.

   2. Log in to the Admin Portal and follow the steps below to view or renew the license details.

**Check License Details / Renew License**

This page is also useful for the following purposes:

1. To verify license information, such as validity and activated features.

2. If the current license has expired, renew it through Secude and update it.

**To check the license details:**

1. Click **Show License Details** . Note**:** The **Show License Details** button is enabled only after the first activation.

   ![Renewcheck license dialog.png](https://help.secude.com/__attachments/a_a38495c0482de50d9d8fa2a5549446f174fd3c14dd6fc5298bcd8ea3547ec5db/Renewcheck%20license%20dialog.png?cb=9644c963dc9a0cf701fca128c58a0726)

   *Renew/check license dialog*

   **Results**: The license details will be displayed.
2. Click **Close** to exit the dialog box.

3. Restart the HaloENGINE Tomcat Service for the configuration changes to take effect.

**To renew the license:**

Click **Upload License File** and select the new `license.lic` file from the **Open**dialog box.

**Results**:

1. A confirmation message appears after the file is uploaded successfully.

2. Click **Close** to exit the dialog box.

---
version: "6.10"
language: "en"
---
# Phase 3. Configure Profiles and Classification

A profile is a repository for all details relating to classification settings.

Follow the procedure below to configure the Profile:

1. On the left navigation bar, click **Customer Configuration**, and then select the customer ID (halo_customer) from the list.

2. On the **Profile Configuration** tab, click **Configure**. The following page appears, as shown in the figure below:

   ![Profile Configuration #1.png](https://help.secude.com/__attachments/a_e3f5040a6ac541410c5f23e24da4f5f94c825b09cbf5dbcffe0531982549d0f6/Profile%20Configuration%20%231.png?cb=b2e02560f5accea320023c87cca312e2)

   *Profile Configuration page #1*
3. On the **Profiles and Classification** tab, click **Configure**.

4. Upon opening, the Classification Profiles page appears empty, with no profiles added.

5. Click the plus icon, and then enter the following details:

   ![Profile Configuration #2.png](https://help.secude.com/__attachments/a_ebfaed066e279d3bc3bb1ace99f716c6169f2caf669c4bb160c5041a255b7b72/Profile%20Configuration%20%232.png?cb=8693794b48310ed1655a430e23441603)

   *Profile Configuration page #2*
6. **Profile Name** − Enter a name for the new profile. Note: A profile name cannot contain any of the following characters ``"< >: " / \ |? * ` ~"`` and can contain "`- _`"

7. **Description** − Enter a description for the new profile (optional).

8. **Activate** − The current profile is automatically enabled by default. However, you can deactivate it by clicking the **Activate**slider button.

9. Click **Save**.

10. Repeat the above steps to create multiple profiles.

    **Results**:
    1. A confirmation message appears after the profile is saved successfully.

    2. The new profile is added to the **Classification Profiles** list.

       ![Example of a Multi-Customer ids.png](/__attachments/a_d5189f5eaa10a33ce1d9dce83523dbdee56ae19e6bfb6e6e0cd04e2d6c4331aa/Example%20of%20a%20Multi-Customer%20ids.png?cb=5211c559d7267ef03d9efefadd145ad1)

       *Profile list*

**Related tasks**

1. You can manage Classification Profiles using the Copy, Edit, Delete, Download, and Import [icons](https://help.secude.com/haloengine/6.10/setting-up-classification-engine.md#UI).

2. To view the details of a profile, click the Profile Details icon.

3. To export a profile configuration, click the **Download** icon. A ZIP file named `Profile.zip` is downloaded. This profile can be reused in another HaloENGINE environment. To import the profile, click the **Import Profile** icon in the upper-right corner and attach the downloaded file.

**What to do next**:

1. Click **Reload Configuration** to apply the changes.

2. Select a classification profile from the displayed list. The **Classification Configuration** page appears, as shown in the figure below:

   ![Classification Configuration.png](https://help.secude.com/__attachments/a_9b9901a14f4e7e7f4179dda093106e69095ef2d8498969cfdb2df3937b7d8fa3/Classification%20Configuration.png?cb=09c2e21aa2af8889661b1f3450bfac18)

   *Classification Configuration*
3. Refer to the following sections to create a classification schema, rules (download and upload), configure metadata (only for Teamcenter System type), and assign systems for each profile.

## Create Classification Schema

The classification schema contains properties and their values.

1. On the **Classification Schema** tab, click **Configure** . Upon opening, the **Classification Schema** page appears empty, with no schemas added.

2. Click the plus icon and enter the following details:

   1. **Property Name** − Enter a name for the new property (maximum 20 characters and case sensitive). For example, sensitivity.

   2. **Property Value** − Enter a value for the property (maximum 20 characters and case sensitive) and click the plus icon on the right. The value is added to the list. For example, Secret, Confidential, and Internal.

      ![Classification Schema Configuration.png](/__attachments/a_396dcbbbbecac86caac18d4854229917ab311456c6444f1c10a652f2af34f4c2/Classification%20Schema%20Configuration.png?cb=cfbe6ce189dddd5eea8b66814b544d79)

      *Classification Schema Configuration*
3. The first entry (e.g., Secret) will be taken as the default value, but you can modify it using the **Default** dropdown menu. The words `default`, `group`, `multiple`, `if`, `tree`, `hierarchy`, and `return` are reserved keywords that are used for internal processes. Therefore, it should not be used as a **Property Name** or **Property Value**. Using the keyword will result in a compile-time error.

4. Add as many values as you wish to add.

5. Click **Save**.

   **Results**:
   1. A confirmation message appears after the **Classification Schema** is saved successfully.

   2. The property name and its values are added as a node.

   3. Similarly, you can add schemas by clicking the plus icon.

6. **Enable tree structure** : To have a tree structure view of information, where each item can have multiple children, select the Property Value (e.g., Asia) and enter a value in the property value field (e.g., India), and then select the **Enable tree structure** check box and add the child node using the plus icon. In this illustration, the **Property Value** "Asia" contains three child nodes - India, Saudi Arabia, and Singapore.

7. Click **Close** to exit the page.

   ![Classification Schema list.png](https://help.secude.com/__attachments/a_a1096aa0c4bb63323404022f8a9710690cc657e0eb332778728c1cb9fae544ab/Classification%20Schema%20list.png?cb=34a52924b523ffa3b8280522709734c2)

   *Classification Schema list*
8. Click Reload Configuration to apply the changes.

**Related tasks**

1. By default, the current property is activated. You can deactivate it by selecting the **Deactivate Property** check box.

2. You can manage classification profiles using the Edit and Delete [icons](https://help.secude.com/haloengine/6.10/setting-up-classification-engine.md#UI).

### Create Download Classification Rules

Download rules define classification rules based on metadata types and Pre-Expression, while Action rules determine whether a file is blocked, protected, or excluded during download.

#### Custom Pre-Expression

This page allows you to create custom pre-expressions depending on the system types for which you have been licensed. This is available for all systems such as Windchill, Teamcenter, Keytech, Autodesk_Vault, SOLIDWORKS_PDM, and HaloENGINE_API.

1. Navigate to the **Profile Configuration** tab and click **Configure** \> go to the **Profiles and Classification** tab and click **Configure** \> select a classification profile \> on the **Rules Configuration** tab, click **Configure**. The following page appears, as shown in the figure below:

   ![Rules Configuration.png](https://help.secude.com/__attachments/a_80a0eeafd0dd3bed6a367b2c31518fdbc58733bab8187e4e0a1cf94ae90abf55/Rules%20Configuration.png?cb=e40f86f2788797a45b2d597d1ea6dbe8)

   *Download rules configuration page*
2. On the **Classification Rules** tab, click **Configure**, and the following page appears, as shown in the figure below:

   ![Classification rules.png](https://help.secude.com/__attachments/a_76ba69093454fcf9034c972dfda0b6d7378cade0fa82aca12bceec2655f25e83/Classification%20rules.png?cb=855525c7d3a7bcd58f30959c4c6a997a)

   *Classification rules page*
3. On the **Pre-Expression** tab, click **Configure** , and the **Pre-Expression Configuration** page appears, as shown in the figure below:

   ![Pre-Expression Configuration.png](https://help.secude.com/__attachments/a_0ee54e73ae29cec673e6f37b5b26b17485cd6605984aa13816eabd329e1a4f67/Pre-Expression%20Configuration.png?cb=f7b0ac93bce2e47259ee75108e017c0a)

   *Pre-Expression Configuration*
4. On the **Pre-Expression Configuration** page, click **Custom Pre-Expression**. Upon opening, the Custom Pre-Expression page appears empty, with no pre-expressions added.

5. Click the plus icon and enter the following details:

   ![Custom Pre-Expression #1.png](https://help.secude.com/__attachments/a_03395a3db3aec191f0183f3a4a161bfa519724431b1e14f09af6e47b8afc9258/Custom%20Pre-Expression%20%231.png?cb=1db6dab075928ca4e8222d94b933a16c)

   *Custom Pre-Expression #1*
6. **Custom Pre-Expression Name** − Enter a name for the new custom pre-expression entry. Note: only '**alphabet** ', '**numbers** ', '**_** ', and '**-**' characters are supported.

7. **Description** − Enter a description of the new custom pre-expression (optional).

8. **System Type** − Based on your license, your system type will be displayed by default.

9. **Metadata** − Select a metadata from the list.

10. **Activate** − The current Custom Pre-Expression is automatically enabled by default. However, you can deactivate it by clicking the **Activate**slider button.

11. Click **Save**.

    **Results**:
    1. A confirmation message appears after the **Custom Pre-Expression** is added.

    2. The new custom pre-expression is added to the list.

    3. Click **Reload Configuration** to apply the changes.

**Reference Manuals**: For more information about metadata description, please refer to the relevant HaloCAD PLM/PDM Installation Manual.

1. Autodesk Vault -- HaloCAD for Autodesk Vault Installation Manual

2. Teamcenter -- HaloCAD for Teamcenter Installation Manual

3. Windchill -- HaloCAD for Windchill Installation Manual

4. SOLIDWORKS PDM -- HaloCAD for SOLIDWORKS PDM Installation Manual

5. Keytech -- HaloCAD for Keytech Installation Manual

6. HaloENGINE API -- Since there is no built-in metadata for the REST SDK, custom metadata can be used to generate new metadata for the HaloENGINE API system type. Please refer to the section "[Custom Metadata](https://help.secude.com/haloengine/6.10/phase-5-configure-profiles-and-classification.md#CM)".

**To add custom metadata configuration**

1. Now, select a custom pre-expression from the list, and the **Custom Metadata Configuration** page appears, as shown in the figure below. For illustration, a new custom pre-expression "DOMAIN" is added to the list.

   ![Custom Pre-Expression #2.png](https://help.secude.com/__attachments/a_4817a0990bc81e3f5e4858808c37f85b25a382c893b56e3190c489f49df6b42f/Custom%20Pre-Expression%20%232.png?cb=acafee407f590a3fc557eb449a8e2d80)

   *Custom Pre-Expression #2*
2. Click the plus icon. The **Add Custom Metadata Values** dialog appears.

3. Enter a value and select any one of the following options:

   1. YES = it contains specified metadata information

   2. NO = it does not contain the specified metadata information

   3. Click **Save**.

   **Results**:
   1. A confirmation message appears after the **Custom Metadata** is saved.

   2. The new metadata value is added to the list.

   3. Click Reload Configuration to apply the changes.

**Related tasks**

1. To find a metadata value, enter the name in the **Search Metadata**text box. The search results will be shown.

2. If you want to remove custom metadata from the list, click the **Delete**icon against the metadata.

3. **To Import Custom Metadata:** If you wish to add your own metadata, click **Import Metadata** .The **Import Custom Metadata** dialog will appear. Click on the button and select the metadata file (`.csv`, .`xls`, `.xlsx`) from the **Open**Windows dialog.

4. **To Export Custom Metadata:** If you wish to export the existing metadata, click **Export Metadata** . An Excel file will be downloaded. The new custom pre-expression is displayed and available for user selection in the **Classification Rule UI** as metadata, as shown in the example below:

   ![Example for Custom Pre-Expression #3.png](https://help.secude.com/__attachments/a_47ac326beef1f7e87de935f38790fdfef18731e30bce74a4e39796c01e0a0302/Example%20for%20Custom%20Pre-Expression%20%233.png?cb=335aaddd616aece60e4376af56aae263)

   *Example for Custom Pre-Expression #3*
5. You can manage Custom Pre-Expressions using the Edit or Delete [icons](https://help.secude.com/haloengine/6.10/setting-up-classification-engine.md#UI).

#### Custom Metadata

For data classification and secure file downloads, the HaloENGINE Admin Portal uses the default metadata. However, depending on organizational requirements, the portal allows administrators to add custom metadata.

Note: Metadata can be configured for PLM clients who do not want schema or rule-based decryption. For more information, refer to the section "[Metadata Configuration](https://help.secude.com/haloengine/6.10/phase-5-configure-profiles-and-classification.md#metadata)".

Follow the procedure below to create custom metadata for System types:

1. On the left navigation bar, click **Customer Configuration**, and then select the customer ID (halo_customer) from the list.

2. Navigate to the **Profile Configuration** tab and click **Configure** \> go to the **System Metadata Configuration** tab and click **Configure**.

3. Click the System Type to which you want to add the custom metadata. In this example, the WINDCHILL System Type is selected.

4. Click the plus icon. The **Add Custom Metadata** dialog appears.

5. Enter a name and click **Save**.

   ![Metadata details page.png](https://help.secude.com/__attachments/a_70bd42d1211c2fbd465a21f419a91a8cdb31694334d7bb240d99d0be33af4058/Metadata%20details%20page.png?cb=7d6a007db6a4bac5a572154cbe164b2e)

   *Metadata details page*

   **Results**:
   1. A confirmation message appears after the **Custom Metadata** is saved.

   2. The new metadata name is added to the list.

   3. Click **Reload Configuration** to apply the changes.

**Related tasks**

1. If you want to edit/remove newly added custom metadata from the list, click the **Edit** /**Delete**icon against the metadata.

2. To search metadata by name, use the text box labeled **Search by Metadata**. Your search results will be displayed.

3. The new custom metadata is displayed and available for user selection in the **Classification Rule UI**, as shown in the example below:

   ![Example for Custom Metadata.png](https://help.secude.com/__attachments/a_f087f1481eeca84d8db7596cf3ca80c14b5a9f2f498fa0b098007be489c009e3/Example%20for%20Custom%20Metadata.png?cb=32e69cb273df41eb4e578837ad0286c0)

   *Example for Custom Metadata*

#### Create Download Rules

Prerequisite: Make sure that classification properties and their values are configured.

Classification Rules define one or more classifications based on metadata types and pre-expressions.

1. Navigate to the **Profile Configuration** tab and click **Configure** \> go to the **Profiles and Classification** tab and click **Configure** \> select a classification profile \> on the **Rules Configuration** tab, click **Configure** \> on the **Classification Rules** tab, click **Configure** \> finally, click the **Rules** tab and then **Configure**.

2. Upon opening, the *Download Classification Rules* page appears empty, with no rules added.

   ![Download classification rules page.png](https://help.secude.com/__attachments/a_a65b90f2be4fbd42ef487ad166ef43f627360e3ae12f4286415652db00619d8d/Download%20classification%20rules%20page.png?cb=40259a10edb44d7a20727bb9e3fba1f3)

   *Download classification rules page*
3. Select a property from the **Choose a Property** table and then click the plus icon.

4. The *Classification Rules Configuration* page appears, as shown in the figure below:

   ![Classification rules configuration.png](https://help.secude.com/__attachments/a_26ca89b4047b08c8988ac6d6ce8de13cc3b3997bcdaf20e4d736dfdcb16d9d32/Classification%20rules%20configuration.png?cb=96917b583ab00a09663b325b7bf8ce09)

   *Classification rules configuration*
5. Enter the values for the following:

   1. **Rule Result** − Select a value from the list.

   2. **System Type** − Based on your license, your system type will be displayed by default.

   3. **Metadata** − Select a value from the list.

   4. **Condition** − Select a condition (Equal/Not Equal) from the list.

   5. **Value** − Enter a value for the selected metadata (case-sensitive).

6. Click **Set** to apply the rules.

7. The selected metadata and its condition are added to the list.

8. Click **Save**.

**Results**:

1. A confirmation message appears after adding or updating the rule.

2. The rule is added to the list under the **Overview**table as shown in the figure below:

   ![Classification rules configuration page.png](https://help.secude.com/__attachments/a_79ea0a0438f5e706ae957e1363bfcc22ecbb28fb908ea8724f6b45736825e5e1/Classification%20rules%20configuration%20page.png?cb=bc738c9b54a376e144ae8d63365c92d4)

   *Classification rules page after configuration*
3. Click **Reload Configuration** to apply the changes.

**Related tasks**

1. By default, the current rule is activated. However, you can disable it by selecting the **Deactivate Rule** checkbox.

2. To adjust a rule's priority, select the rule and click the corresponding **Up Arrow** or **Down Arrow** icon.

3. To undo the priority changes, click the **Restore Priority Changes** icon.

4. To save the updated priority order, click the **Save Priority Changes** icon.

**Reference Manuals** :

For more information about metadata description, please refer to the relevant HaloCAD PLM/PDM Installation Manual.

1. Autodesk Vault -- HaloCAD for Autodesk Vault Installation Manual

2. Teamcenter -- HaloCAD for Teamcenter Installation Manual

3. Windchill -- HaloCAD for Windchill Installation Manual

4. SOLIDWORKS PDM -- HaloCAD for SOLIDWORKS PDM Installation Manual

5. Keytech -- HaloCAD for Keytech Installation Manual

6. HaloENGINE API -- Since there is no built-in metadata for the REST SDK, custom metadata can be used to generate new metadata for the HaloENGINE API system type. Please refer to the section "[Custom Metadata](https://help.secude.com/haloengine/6.10/phase-5-configure-profiles-and-classification.md#CM)".

#### Add Action Rules

Action rules define the conditions under which a file download is blocked, protected, or excluded.

Follow the procedure below to add Action Rules:

1. Navigate to the **Profile Configuration** tab and click **Configure** \> go to the **Profiles and Classification** tab and click **Configure** \> select a classification profile \> on the **Rules Configuration** tab, click **Configure** \> under **Action Rules** , click **Configure**. The following page appears as shown below:

   ![Action Rules.png](https://help.secude.com/__attachments/a_8f9e85a1dcdedd13503a220067afd0593a148ac6915cdda21675852f838db73c/Action%20Rules.png?cb=a8f0d8862a860ac728640d4104f71939)

   *Action Rules*
2. On the **Rules** tab, click **Configure** . When opened, the **Action Rules for Download** page appears empty, with no action rules added.

3. Click the plus icon. The *Add Action Rule* page appears.

4. Under **Choose Resulting Actions**, select any one of the actions. Please note that you can select only one action at a time: Block, Label, or Exclude.

   1. To block a file download, select the **Block** check box and proceed to [point 6](https://help.secude.com/haloengine/6.10/phase-5-configure-profiles-and-classification.md#6).

      ![Action Rule - Block.png](/__attachments/a_42a82b6533c41c49d4dadc96ec28e3b49cc6627e89b80222ac8e93877ffbee4f/Action%20Rule%20-%20Block.png?cb=5e3c0bd488f57994c9b00219ae1032cb)

      *Action rule for block*
   2. To protect a file download, select the **Protect/Label** check box. Click **Choose Label** to select a label from the list. Proceed to [point 6](https://help.secude.com/haloengine/6.10/phase-5-configure-profiles-and-classification.md#6).

      ![Action Rule - Protect.png](/__attachments/a_ce7fe2d5fa41db331eb955f334a356249157255fa061ab6f392338ad3092ba9e/Action%20Rule%20-%20Protect.png?cb=a289da43d47bec8fe89993d122f10875)

      *Action rule for protection*
   3. **Exclude** − Allows suppressing actions such as monitor, block, label, or protect during a file download by selecting the **Exclude** action based on the configured metadata or Pre-expression. If selected, other options will be disabled. Proceed to [point 6](https://help.secude.com/haloengine/6.10/phase-5-configure-profiles-and-classification.md#6).

5. **System Type** − Based on your license, your system type will be displayed by default.

6. Enter the values for the following under **Construct Rules**:

   1. **Property** − Select a value from the list.

   2. **Condition** − Select a condition (Equal/Not Equal) from the list.

   3. **Value** − Select a value from the list.

   4. **Deactivate Rule** − If you want to deactivate a rule, select **Deactivate Rule**check box.

7. Click **Set** to configure the rule. The selected property and its condition are added to the list.

8. Click **Save**.

   **Results**:
   1. A confirmation message appears after adding or updating the action rule.

   2. The rule is added to the list.

      ![List of action rules.png](/__attachments/a_2fa630449f5ce3d25b512a4d8c0283a71b22150ff5bc6dcc83b9b16231256f1f/List%20of%20action%20rules.png?cb=4ea364100790afe039a733673f7d750a)

      *List of action rules*
   3. Click **Reload Configuration** to apply the changes.

**Related tasks**

1. You can manage the **Action Rule** using the **Edit** and **Delete** [icons](https://help.secude.com/haloengine/6.10/setting-up-classification-engine.md#UI).

2. To increase or decrease the priority of a rule, select the rule and click the corresponding **Up Arrow** or **Down Arrow** icon.

3. To reverse any priority changes, click the **Restore Priority Changes** icon.

4. To save your priority changes, click the **Save Priority Changes** icon.

**Action Rule priorities**

When multiple classification rules exist, the HaloENGINE prioritizes them from top to bottom. For example, consider **Rule 1** , **Rule 2** , **Rule 3** , and **Rule 4** in the Classification Engine.

1. The Classification Engine evaluates the topmost rule, **Rule 1**, first. If all classification expressions are correct, the first action rule is applied.

2. If not, it moves on to **Rule 2** and performs further verification.

3. This process continues until a correct classification expression is found or no rules apply.

**Owner Configuration (Optional)**

This feature defines how a user can be determined as the owner of exported documents.  
**Supported client systems:**Teamcenter, Windchill, Autodesk_Vault, and Keytech systems.

Owner configuration does not apply to the SOLIDWORKS PDM client, as protection is managed by HaloCAD for SOLIDWORKS PDM.

Follow the steps below to configure owner rights:

1. On the **Owner Configuration** tab, click **Configure**.

2. The *Document Rights Configuration*page appears as shown in the figure below:

   ![Owner rights in Azure RMS.png](https://help.secude.com/__attachments/a_d1a705c075af1de0741cf24252aae1935097e146d9c2f7606c2cb9939eb606b1/Owner%20rights%20in%20Azure%20RMS.png?cb=57ae12d6897f089219f7ffcc0b8dad47)

   *Owner rights*
3. Select one of the following three options:

   1. **Service**(default) − The Application ID used to initialize the HaloENGINE Tomcat Service becomes the owner of the document.

   2. **Static email** − The email address entered in the text box is considered the owner of the document.

   3. **User** − The mail address is derived from the client system, such as Windchill, Teamcenter, Keytech, Autodesk_Vault, or HaloENGINE_API.

4. Click **Save**to save the rule.

   **Results**: A confirmation message appears after updating the assigned rights.

### Metadata Configuration

**SetMetadata/Unprotect Action (only for Teamcenter)** :It allows you to set existing metadata back onto the file while checking-in, based on the MPIP label. This aids in the consistency of file classification. As an example, for Teamcenter **IP_Classification** values can be returned. Note: It is not currently supported by other PLMs.

Prerequisite: Ensure that the Classification Schema is available.

Follow the steps below to configure metadata:

1. Navigate to the **Profile Configuration** tab and click **Configure** \> go to the **Profiles and Classification** tab and click **Configure** \> select a classification profile \> go to the **Metadata Configuration** tab and click **Configure**.

2. Upon opening, the *Add Metadata Rule* page appears empty, with no metadata rules added.

   ![Add metadata rule.png](https://help.secude.com/__attachments/a_3bfcca6647dfac8aa959ff79b1b96a5e69c3b0350d8299dd5aaedfb5225b57a8/Add%20metadata%20rule.png?cb=7af92bcf3f69bd7a5d2076a01056ec40)

   *Add metadata rule*
3. By default, the **SetMetadata/Unprotect** option is selected.

4. Click **ADD METADATA**.

5. The *Add Metadata* page appears, as shown in the figure below:

   ![Add Metadata.png](https://help.secude.com/__attachments/a_c2a6a7e31c99910c3fd57f510b079c12811cc60cfd538073565dc93d4a13bee4/Add%20Metadata.png?cb=c0f52d59e9641a25c713ca2cf5b55103)

   *Add metadata page*
   1. **Metadata** − IP_CLASSIFICATION will be displayed by default. Currently supported only for **ip_classification** metadata.

   2. **Value** − Enter the metadata that is used during encryption (minimum of 3 characters, maximum of 30 characters, and case sensitive).

   3. Clickon the **plus** icon to apply the rules. The selected metadata and its condition will be added to the list.

   4. Click **Save**.

6. **System Type** − Teamcenter will be displayed by default. Currently supported only for the Teamcenter system type.

7. Enter the values for the following under **Construct Rules**:

   1. **Property** − labelID will be displayed by default. Currently supported only for labelID.

   2. **Condition** −Select a condition (Equal/Not Equal) from the list.

   3. **Value** − Select a label from the list.

   4. Click **Set** to set up the rules. The selected property and its condition will be added to the list.

   5. **Deactivate Rule** − By default, the current rule will be activated. However, the admin portal allows you to turn off the Rule by selecting the **Deactivate Rule**check box.

8. Click **Save**.

   **Results**:
   1. A confirmation message appears after adding or updating the rule.

   2. Click **Reload Configuration** to apply the changes.

The table below outlines the key attributes that are allowed on each system type.  

|                                                                                      **Profile Configuration**                                                                                      ||||||||
|------------------|----------------------------------|------------------------|--------------------|-------------------|----------------------|---------------------------|---------------------------------|
| **System Types** | **Download Rules** **(default)** | **PII and Fin. Info.** | **Cust. Pre-Exp.** | **Owner Config.** | **Metadata Config.** | **Sys. Metadata Config.** | **Auth./Comm. Endpoint**        |
| Teamcenter       | Yes                              | N/A                    | Opt.               | Opt.              | Opt.                 | Opt.                      | Mutual                          |
| Autodesk_Vault   | Yes                              | N/A                    | Opt.               | Opt.              | N/A                  | Opt.                      | Mutual                          |
| Windchill        | Yes                              | N/A                    | Opt.               | Opt.              | N/A                  | Opt.                      | Mutual                          |
| Keytech          | Yes                              | N/A                    | Opt.               | Opt.              | N/A                  | Opt.                      | Mutual                          |
| SOLIDWORKS PDM   | Yes                              | N/A                    | Opt.               | N/A               | N/A                  | Opt.                      | Supports mutual and server-side |
| HaloENGINE_API   | Yes                              | N/A                    | Opt.               | Opt.              | N/A                  | Opt.                      | Supports mutual and server-side |

*Key attributes of each system type*

**Abbreviations used in the above table**

1. Yes - applicable by default

2. N/A - Not Applicable

3. Opt. - Optional

4. Fin. Info. - Finance Information

5. Cust. Pre-Exp. - Custom Pre-Expression

6. Owner Config. - Owner Configuration

7. Metadata Config. - Metadata Configuration (Profile Configuration \> Profile Classification \> Classification Configuration \> METADATA CONFIGURATION)

8. Sys. Metadata Config. - System Metadata Configuration (Profile Configuration \> System Metadata Configuration)

9. Auth. - Authentication

10. Comm. - Communication

### Assign User Permission

HaloENGINE uses three roles---**ROLE_SUPER_ADMIN** , **ROLE_CUSTOMER_ADMIN** , and **ROLE_CUSTOMER_USER** ---for authentication and authorization. These roles are set up and managed through the Azure portal. For more details, please refer to the section "[User Management Settings](https://help.secude.com/haloengine/6.10/prerequisites.md#UMS)". The **Assign User Permission** page allows you to add users who have been assigned to the role **ROLE_CUSTOMER_USER**.

The following configurations are possible for the ROLE_CUSTOMER_USER. Using these read-and-write permissions, a user can manage multiple profiles.

For example,

1. User 1 - assigned with full rights as an admin user. So he could access the entire portal without any limitations.

2. User 2 - assigned with read-only access. This user can view the configuration of a particular profile, but is restricted to changing the settings.

3. User 3 - assigned with write access. This user is allowed to change the configuration of a particular profile.

**User accounts**

1. Administrator with Super User role---Granted, the highest level of access to the entire HaloENGINE component.

2. Domain Users with Customer_Admin roles---Have fewer administrative privileges than Super User.

3. Domain Users with Customer_User roles must be configured with access. Access to this user is granted by either Customer_Admin or Super User.

Follow the procedure below to configure user access:

1. Navigate to the **Profile Configuration** tab and click **Configure** \> go to the **Assign User Permission** tab and click **Configure**.

2. Upon opening, the *User-Profile Permission* page appears empty, with no profiles added.

3. Click the plus icon and enter the following details:

   ![Add profile permission.png](https://help.secude.com/__attachments/a_e09f37c038aabb02f7879c74b703465344023fce7dec16a85c2d5c3ebd8254ab/Add%20profile%20permission.png?cb=86301d32d1697ae0520389b271d143e8)

   *Adding a user page*
4. **Email ID** - Enter the email ID, which is mapped to the role ROLE_CUSTOMER_ADMIN/ROLE_CUSTOMER_USER in the Azure portal. For more details, please refer to the section "[User Management Settings](https://help.secude.com/haloengine/6.10/prerequisites.md#UMS)".

5. **Select Profile** - Select a profile from the list.

6. **User Permission** - Select either View Permission or Full Permission for the user.

7. Click **Save**.

   **Results**:
   1. A confirmation message appears after adding the user permission.

   2. The email ID is added to the list, as shown in the figure below:

      ![User profile permission #1.png](/__attachments/a_e22935ad531a0ec970e834fbe04c326b803c4fab4aa5997f0f4035becd8ff229/User%20profile%20permission%20%231.png?cb=e82435a1b1ffd0c6fbd74510b18ba399)

      *User profile permission #1*
   3. Click **Reload Configuration** to apply the changes.

**Related tasks**

To know the details of a user.

1. Click on the user's email ID. The *Profile Permission Details* page appears as shown in the figure below:

   ![User profile permission #2.png](https://help.secude.com/__attachments/a_8dadf3336226b1b47a6ee6c614a6004716c71a1625673224f0caf94a22cebcd8/User%20profile%20permission%20%232.png?cb=08ce5843e4b2ad7e3e872f724a040fe7)

   *User profile permission #2*
2. You can manage the permission using the **Edit** and **Delete** [icons](https://help.secude.com/haloengine/6.10/setting-up-classification-engine.md#UI).

---
version: "6.10"
language: "en"
---
# Phase 4. Assign Systems

The client systems that must communicate with HaloENGINE should be registered in the admin portal using a unique ID. Please note that if you enable the monitor without configuring a System Unique ID in Assign Systems, the Monitor log in HaloENGINE will not be updated.

Follow the procedure below to add a system type:

1. On the left navigation bar, click **Customer Configuration**, and then select the customer ID (halo_customer) from the list.

2. Navigate to the **Profile Configuration** tab and click **Configure** \> go to the **Profiles and Classification** tab and click **Configure** \> select a classification profile \> go to the **Assign Systems** tab and click **Configure**.

3. Upon opening, the **Assign Systems** page appears with the licensed system types.

4. To illustrate and showcase the list of system types available in the portal, a license generated with all client types is uploaded. However, in a typical business environment, you may only have one or a few system types depending on the environment. That implies that by default, only the systems that you have licensed will be displayed.

   ![Assign systems #1.png](https://help.secude.com/__attachments/a_0a29215b5bba4d8eb610c30fc12ac1d0b72d82710585e7be2d7c230027299bfe/Assign%20systems%20%231.png?cb=1472bafb23e883912c15cf99d83d0e04)

   *Assign systems page #1*
5. Select a system type and click the plus icon to add the corresponding system type details.

6. Enter the following details on the *Add System ID* page. For illustration, the Windchill system is selected.

   ![Assign systems #2.png](https://help.secude.com/__attachments/a_a319e9c49ad74b214dab991021bf904911068ce6cbe8ca0f705f523dd395e216/Assign%20systems%20%232.png?cb=8d1c0e8a325a8e50266248c0ac65025e)

   *Assign systems page #2*
7. **System Unique ID** − Enter your system's **System Unique ID** . For information on how the System Unique ID is created, please refer to the section below referred to "[Creating a System Unique ID for Clients](https://help.secude.com/haloengine/6.10/phase-7-assign-systems.md#ID)".

8. **Description** − Enter a description (optional).

9. Click **Save**. Repeat the same steps for other systems.

   **Results**:
   1. A confirmation message appears after adding or updating the system ID.

   2. Click **Reload Configuration** to apply the changes.

**Related tasks**

1. You can manage the systems using the **Edit** and **Delete** icons.

2. You can view system details by clicking the **Assign System Details** icon.

3. After making changes to the classification engine, click **Reload Configuration** to apply the changes. The page will redirect to the login page once the reload completes.

4. Note: Two profiles cannot have the same **System Unique ID**.

**Creating a System Unique ID for Clients**

Please make sure the names are case-sensitive when using the System Unique ID in Assign Systems and Client Systems.

**HaloCAD for Teamcenter**

Here, the **System Unique ID** must be the Teamcenter Server's hostname that is added as the FMS target in the proxy configuration. For example, if your Teamcenter Server's hostname is TEAMCENTER01, the **System ID** must also be **TEAMCENTER01**when configuring it with the HaloCAD Configuration Tool. The same name must also be supplied in the System Unique ID field.

**HaloCAD for Windchill**

Here, the hostname of the Windchill Server that is specified during HaloCAD for Windchill configuration must be the **System Unique ID** . For example, if your Windchill Server's hostname is **WINDCHILL01** , the **System ID** must also be WINDCHILL01 when configuring it with the HaloCAD Configuration Tool. The same name must also be supplied in the System Unique ID field.

**HaloCAD for Keytech**

For example, if you specify the **System Unique ID** as **KEYTECH01**, then the same ID must be used in the HaloCAD Configuration Tool (System ID=KEYTECH01) while configuring its properties.

**HaloCAD for Autodesk Vault**

Here, the hostname of the Vault Server that is specified during HaloCAD for Autodesk configuration must be the **System Unique ID** . For example, if your Vault Server's hostname is **VAULTCLNT01** , the **System ID** must also be VAULTCLNT01 when configuring it with the HaloCAD Configuration Tool. The same name must also be supplied in the System Unique ID field.

**HaloCAD for SOLIDWORKS PDM**

For example, if you specify the **System Unique ID** as **SWDPDM01**, then the same ID must be used while executing the installer (System ID=SWDPDM01).

**HaloENGINE_API**

For example, if you set the System Unique ID to **RESTclient** (System ID=RESTclient), the same ID must be used when calling the APIs.

---
version: "6.10"
language: "en"
---
# Phase 5. Configure HaloENGINE Features

For any type of licensed system, the first step is to enable the monitor.

Prerequisite: Verify that the HaloENGINE license is active. Refer to the section "[Phase 2. Activate License (First time)](https://help.secude.com/haloengine/6.10/phase-3-activate-license-first-time.md#lic)".

1. On the left navigation bar, click **Customer Configuration**, and then select the customer ID (halo_customer) from the list.

2. On the **HaloENGINE Features** tab, click **Configure** . The *HaloENGINE Features* page appears as shown in the figure below:

   ![Enable Monitor..png](https://help.secude.com/__attachments/a_d31838af9ff0bb262bd1accd99ff47079e43d2cc5dca2bf6d056c0e00d732b0d/Enable%20Monitor..png?cb=269c99a0813706a0eac4db1ff1bbb198)

   *Enable Monitor*
3. Enabling the Monitor is the first step.

4. Click on the slider button to enable **Monitor** ,and then click **Apply Configuration**.

   **Results**:
   1. A confirmation message appears after changing the default configuration.

   2. Click **Reload Configuration** to make the changes take effect.

## **Enable Classification/Action Engine**

Follow the steps below to enable the classification engine:

1. Click the slider button to enable or disable the **Classification/Action Engine**.

2. The **Choose Locales** button is enabled automatically.

3. Click **Choose Locales** . The **Choose Locale** page appears, as shown in the figure below:

   ![Locales.png](https://help.secude.com/__attachments/a_4e187dcc37e04ad9381d50d2f4aaae437f26a6021286eca7490a9478b062f476/Locales.png?cb=06f8a2c4a120db1454ef01606ffcfb27)

   *Locales*
4. Search and select one or more texts for translation. For example, en_US.

5. Click **Apply**.

   **Results**:
   1. Selected texts for translation are added to the list.

   2. You can either press **Apply Configuration** now and then reload configuration to let the changes take effect, or you can configure further settings and then press **Apply Configuration**.

## **Monitor Configuration**

Prerequisite: Ensure that Monitor is enabled, as mentioned above.

Follow the steps below to configure the Monitor:

1. On the*HaloENGINE Features* page, click **Monitor Properties**.

2. The *Monitor Configuration* page appears as shown in the figure below:

   ![Monitor Configuration.png](https://help.secude.com/__attachments/a_334832741e724803c63175a27ae0eae5007083a6574ea7a8f9a08b70cdd83e0d/Monitor%20Configuration.png?cb=49d04f010d5dee6b949c2cd7644ba306)

   *Monitor Configuration*
3. Configure Monitor, Syslog, and Sentinel Log individually, as described in the following sections.

### **Monitor Properties**

Follow the steps below to configure the monitor properties:

1. On the **Monitor** tab, click **Configure** and then enter the following details on the *Monitor Properties*page as shown in the figure below:

   ![Monitor Log Configuration.png](https://help.secude.com/__attachments/a_fe2452298df1e3ab9513e4dc4ad246c3d27dc509e2c42387ccc8a52af163751e/Monitor%20Log%20Configuration.png?cb=474ef27d5c5de522446b8f33ab0b8c23)

   *Monitor Log Configuration*
2. **Enable Monitor Local Log** − Select Yes or No to enable or disable the local monitor log. If enabled, the default path is `C:\Program Files\Secude\HaloENGINE\logs\customer_tenants\halo_customer`.

3. **Monitor Log Format** − Choose one of the following monitor log formats (CEF/LEEF/JSON). Please note that it is not possible to change the log format once Halochain is configured, and the field will be disabled once you enable Halochain.

4. **Enable Halochain** − Select Yes or No to enable or disable the **Halochain** feature. If enabled, the default Halochaincertificate path is `C:\Program Files\Secude\HaloENGINE\config\customer_tenants\halo_customer.`

5. **Halochain Certificate Password** − Enter a password for Halochain and click **Generate Halochain Certificate**. You will receive a confirmation message upon creating a certificate.

6. Click **Apply**.

   **Results**: A confirmation message will appear after the properties are successfully updated.

#### **Syslog Properties**

Prerequisite: Ensure that Monitor Local Log is enabled.  
**Requirements**

Please make sure that the following requirements are met:

1. UDP/TCP enabled.

2. The firewall accepts UDP/TCP packets on the configured port.

3. To forward audit logs to SPLUNK/RSA, you need to configure the audit Syslog accordingly.

Follow the steps below to configure the Syslog properties:

1. On the **Syslog** tab, click **Configure** and then enter the following details on the **Syslog Properties**page as shown in the figure below:

   ![Syslog Properties.png](https://help.secude.com/__attachments/a_2203d63c3d9f53ad1764456aa3710c598fefc3dec68b89363987b7b99a85ad3d/Syslog%20Properties.png?cb=8d91d6d83642e5f1d583fe03a355aa6a)

   *Syslog Properties*
2. **Enable Syslog Monitoring** − Select Yes or No to enable or disable the Syslog.

3. **IP Address/FQDN** −If enabled, enter the IP address/FQDN.

4. **System Log Port** −Enter the system log port number. The default port is 514.

5. **System Log Protocol** −Enter the system log protocol (UDP/TCP). The default protocol is UDP.

6. **Syslog Facility** −Enter the Syslog facility (KERN/USER/SYSLOG/AUDIT). The default facility is SYSLOG.

7. Click **Apply**.

   **Results**: A confirmation message will appear after the properties are successfully updated.

#### **Sentinel Log**

Prerequisite: Microsoft Sentinel must be configured. Please refer to the section "[Forwarding Logs to Microsoft Sentinel](https://help.secude.com/haloengine/6.10/prerequisites.md#Sentinel)".

Follow the steps below to configure the Sentinel log properties:

1. On the **Sentinel Log** tab, click **Configure**and then enter the following details as shown in the figure below:

   ![Sentinel Log.png](https://help.secude.com/__attachments/a_67f0ccc21ebee7c30e045e8b37255125b34c2cd6748f0d82d5ba0defd19435b0/Sentinel%20Log.png?cb=bbb1dc55d765a023849e91a1f8426d19)

   *Sentinel Log*
2. **Enable Sentinel Log** − Select Yes or No to enable or disable the Sentinel Log.

3. **Sentinel Workspace ID** − Enter the **Workspace ID** of your Microsoft Entra ID. For example, `395ar44h-h8u3-1kl2-c7n1-21xc6pdlmn86`.

4. **Shared Key** − Enter the **Primary Key** of your **Workspace ID.** For example, `/mjnjgjbKIUTv5M/FJDBFDmdfnidfidi8ujsasusd09uu=ndhdihdkij`.

5. Click **Apply**.

   **Results**: A confirmation message will appear after the properties are successfully updated.

**What to do next**

1. After configuring **Monitor** ,**Syslog** , and **Sentinel Log** , click **Reload Configuration** to apply the changes.

2. Test the log after configuration.

**How to obtain logs in Microsoft Sentinel?**

Prerequisites:

1. Ensure the HaloENGINE Admin Portal is restarted after configuring Sentinel properties.

2. Perform actions like uploading and downloading only after the admin portal is configured to generate and forward sufficient logs.

Follow the steps to obtain logs in Microsoft Sentinel.

1. Log in to the Microsoft Azure portal.

2. In the search bar, type **Microsoft Sentinel**. As you start typing, the list filters according to your input.

3. Select **Microsoft Sentinel** from the search results.

4. The **Microsoft Sentinel** page appears. Here, you need to click **Create**at the top of the page.

5. The page displays available workspaces.

6. Select your workspace.

7. Navigate to **General** \> **Logs** . Forwarded logs will be stored in the `HALOCORE_CL` table.

8. Type `HALOCORE_CL` in the right-side query panel. As you start typing, the list filters based on your input.

9. Select the table `HALOCORE_CL` and choose the appropriate query to fetch the logs. For example, where `action_s contains ""`

10. Run it to get the results.

11. Based on the query applied, logs will be retrieved.

---
version: "6.10"
language: "en"
---
# Phase 6. Monitor Log Dashboard

The HaloENGINE dashboard is an information management tool that visually monitors and displays important performance indicators and metrics, providing an overview of your company's data upload and download events. It uses tables, graphs, charts, and other visual components to display data. HaloENGINE may be viewed and updated in real-time, giving users accurate and up-to-date information when they need it. It is also possible to load a previously generated log file into the dashboard to get a visual picture.

As a prerequisite, make sure the database connection has been established. On the left navigation bar, click **Dashboard** . The following page is the default view. Note: If you receive a "*Failed to get data*" connection error, MongoDB may not have been installed or started yet. In that case, install MongoDB and/or start it manually.  
![Default dashboard view.png](https://help.secude.com/__attachments/a_0f1e0fcb9be2e72ad01a6a93dacb5ce296fe735a08039aaf9283f6b31eb48b5e/Default%20dashboard%20view.png?cb=3f231d3c2c15f596d51ef40ab933678e)

*Default dashboard view*

You can use several elements available in the dashboard user interface to personalize how your data is presented. The dashboard allows you to see both persistent and non-persistent logs.

**Persistent log** : This is real-time log data obtained directly from the HaloENGINE log files. If you want to review a log file permanently, you can upload it using the **Upload Logs** option. These logs are then displayed in the Historical Data section.

**Non-persistent log** : This option is useful when you need to access a previously saved log file or a log file from another HaloENGINE. Such log files can be uploaded using the **Upload Logs** option.

## Upload Logs

Follow the steps below to upload a log file for both persistent and non-persistent options.

1. Click the **Menu** icon and then **Upload Logs**.

2. The *Upload Log Files* page appears as shown in the figure below:

   ![Upload log files.png](https://help.secude.com/__attachments/a_c4b2496827e9235b9d13063ac65b9cfd220aee16d36e3457a55abfc451e55366/Upload%20log%20files.png?cb=59c61d4dc742cab4f63f5b6b0c6256a7)

   *Upload log files*
3. Select either the **Non-persistent** or **Persistent**option.

4. Upload or drag your log files to the page.

5. The name of the uploaded log files appears in the list. If you want to remove an uploaded file, click the **Remove this file** icon.

6. Click **Upload**.

   **Results**:
   1. You will receive a confirmation message after successfully uploading the logs.

   2. The dashboard presents the uploaded log file with visual features.

   3. The populated data can be filtered by Historical Data, Products, and Date Range.

## Customization

Dashboard logs allow users to customize the layout, design, and information based on their preferences. You can change the chart's layout or style by clicking on the Grid, Bar, or Pie elements.

1. The uploaded log IDs appear in the list of **Historical Data** . By selecting one ID, the dashboard will automatically visualize the specified log entry. If you want to remove the uploaded data, click the **Delete** icon.

2. By selecting the **Start Date** and **End Date** in the calendar, the logged items will be displayed within that timeframe.

3. By clicking the **More Filters** icon, you can filter the Products, Events, Actions, Source Type, and Sensitivity Labels.

4. If you want to clear the filtered/selected data, click the **Clear** **Filters** button.

5. If you want to remove the uploaded Non-persistent log data, click the **Clear Session**button.

## Scheduler

This option allows you to define the number of days the logs in the specified path should be maintained. Upon reaching a specified number of days, the logs will be automatically deleted from the MongoDB database.

1. Click on the **Scheduler** , the *Scheduler File Path* page appears as shown in the figure below:

   ![Scheduler file path.png](https://help.secude.com/__attachments/a_8fb4e4c2a1b031446b0fe7ba959268c44c8ebf4e6e5c40f6838846b941420d3f/Scheduler%20file%20path.png?cb=e86b0175a764dffa1184022737989c68)

   *Scheduler file path*
2. Click **+Add Row**, the fields will be visible on the page.

3. Enter the log path in **Path** .For example:`C:\Program Files\Secude\HaloENGINE\logs\customer_tenants\halo_customer`

4. Enter the number of days in **Age**that the log should be kept. For example: 10

5. Click **Save**.

   **Results**:
   1. You will receive a confirmation message after successfully configuring the scheduler.

   2. The logs will be cleared after 10 days.

   3. To add additional paths, click **+Add Row** and enter the information described above.

   4. To remove a path, click the remove **"** X**"**icon.

## **Configure IP and Files**

**IP Config**

This option allows you to specify the geographical location of the log entries. For example, if the U.S. is specified, log items associated with that region will be highlighted.

1. Click on the **Configure IP and Files** , and the *Configure IP Address \& File Groups page*appears as shown in the figure below:

   ![IP Config.png](https://help.secude.com/__attachments/a_d3077d5b7c48c41cfdecbb51cfe82bea16b7826fd7ced72778d9c9517457ed91/IP%20Config.png?cb=fcf79b9f2d0ac43ce5289f97b5ceb82d)

   *IP Config*
2. Click **+Add Row**, the fields will be visible on the page.

3. Click the **IP Config** tab and enter the IP address and place. For Example:

   1. **IP Address** : `10.41.*.*`

   2. **Place** : `Europe`

4. Click **Save**.

   **Results**:
   1. The IP Address data will be shown on the dashboard based on the provided log files.

   2. To enter more IP addresses, click **+Add Row** and enter the details as above.

   3. To remove an IP address, click the **Remove**icon.

**Files Config**

This option allows you to define file types. For example, if pdf is specified, log items that correspond to this file type will be highlighted.

1. Click on the **Configure IP and Files** , and select the **Files Config**tab.

   ![Files Config.png](https://help.secude.com/__attachments/a_ceef5142cb3dc38c81f9cf68755dfa6b7b56592982f04a64c16bfaa27f8ffe01/Files%20Config.png?cb=ef3f3fe33afc0dce75df9b2866547ab9)

   *Files Config*
2. Click **+Add Row**, the fields will be visible on the page.

3. Enter the file types and name of the file types. For Example:

   1. **File Types** : `txt`, `pdf`, `xml`

   2. **Name**: Office file

4. Click **Save**.

   **Results**:
   1. The file type data will be shown on the dashboard based on the provided log files.

   2. To enter more file types, click **+Add Row** and enter the details as above.

   3. To remove file types, click the **Remove**icon.

## Select Charts

This option lets you enable or disable dashboard charts and rearrange them by dragging into your preferred order.

1. Click on the **Select Charts** , and the *Select \& Order Charts*page appears as shown in the figure below:

   ![Select charts.png](https://help.secude.com/__attachments/a_ca372f0e8a2c8135f1aab72aa6f660d408471a1f3c0d14834b02bbf049f91eaf/Select%20charts.png?cb=209c708581110771af94b5f62848f62d)

   *Select charts*
2. Select the **Enable**checkbox next to each chart you want to appear on the dashboard, and then drag and drop them into the order you want them to appear.

3. Click **Save** .

   **Results**:

   1. You will receive a confirmation message after successfully configuring the chart order.

   2. The charts will be displayed in the given order.

   3. To restore the charts to the default view, click **Reset** . You will receive a confirmation message saying "*Are you sure you want to reset to default* " click **Yes** to confirm.

   4. Number Cards are displayed at the top of the dashboard to show the records. Key metrics such as total users, total events, total actions, and total processed data are displayed. Select the **Number Cards** check box to display the cards, or uncheck it to hide them.

## Sample Screens

![HaloCORE_Dashboard.png](https://help.secude.com/__attachments/a_3a481195d266ba88e0e40449b8e6cb7b2cfc7d78c0ac1aa30d7d06e7e6dd16fa/HaloCORE_Dashboard.png?cb=0df9c8a539579439503f55f3b1358627)

*Sample 1*  
![HaloCORE_Dashboard_1.png](https://help.secude.com/__attachments/a_c6f70d87bcbda8ef9a25865e19205dccfabe9e15eb52d7923270a2ed89cb8207/HaloCORE_Dashboard_1.png?cb=681a32f1ec37b292c204cb5b558f123b)

*Sample 2*

---
version: "6.10"
language: "en"
---
# Prerequisites

This chapter describes the prerequisites that must be completed before installing and configuring HaloENGINE. These steps ensure that the product integrates smoothly with your organization's security and compliance infrastructure. The following setup tasks are required:

1. Register an application in Microsoft Entra ID.

2. Provide Microsoft Office 365 subscription details.

   * Create and configure sensitivity labels.

   * Configure recommended URLs, addresses, and ports for MPIP.

   * Enable support for TLS 1.2 at the client workstation for Microsoft Entra ID.

3. Ensure HaloENGINE Tomcat service runtime conditions are met.

4. Obtain the HaloENGINE license.

5. Configure User Management Settings in the Azure portal.

6. Set up Microsoft Sentinel.

Completing these prerequisites in advance helps streamline the deployment process and ensures that HaloENGINE functions as intended within your environment.

## Register an Application in Microsoft Entra ID

This section will guide you through registering an application, obtaining the Client ID and Directory ID, and assigning permissions to the application.  
**Microsoft documentation**

Registering an application in Microsoft Entra ID establishes a trust connection between your application and the identity provider, the Microsoft identity platform.

The information in the Microsoft documentation overrides any information published in this section. For a comprehensive description, refer to Microsoft documentation.

Prerequisite: You must have sufficient permissions to register an application with your Microsoft Entra ID tenant.

### Create an Application

Follow these steps to register the application:

1. Log in to the [Microsoft Entra admin center](https://entra.microsoft.com/) using an account that has administrator privileges.

2. If you have access to multiple tenants, click the Settings icon in the top menu and select the tenant for which you want to register the application from the **Directories** + **subscriptions**menu.

3. You will be directed to the homepage.

   ![0_Intial Screen.png](https://help.secude.com/__attachments/a_eeaf0da2cb0f6e4b6c47824c1309a110e1d5ced89774243041e05cc267ec84ea/0_Intial%20Screen.png?cb=7474bc6a49931803f8de1518c0a94eca)

   *Selecting Microsoft Entra ID*
4. Click **Identity** \> **Applications** \> **App registrations**on the left of the navigation pane.

5. On the **App registrations** page, click the **New registration** page or **Register an Application** button (this button appears only if no applications have already been created).

   ![1_New application registration.png](https://help.secude.com/__attachments/a_3a32cb5cef73a7a6c5c63d3b724ff2e3ead3411343f1fb94b56c6a15ba0b9419/1_New%20application%20registration.png?cb=5ea4d32fc9fa86b48bc627cd26dbcd0e)

   *New application registration*
6. On the**Register an application** page, enter the registration details for your application.

   ![2_Web client application details.png](https://help.secude.com/__attachments/a_9e2f648a6368d8abca8699719f9ba119ccfe30ce80459c45d6c84e88d68d4705/2_Web%20client%20application%20details.png?cb=194653041fa68ff12bcf1d4a00fa447d)

   *Application details*
   1. In the **Name**field, enter an appropriate application name.

   2. Under **Supported account types** , select the option **Accounts in this organizational directory only (single tenant)**. As of now, the HaloENGINE only supports a single tenant.

   3. Under **Redirect URI** : Select **Web** , and then type a valid redirect URI for your application. For example, `https://localhost`.

   4. When finished, click **Register**.

7. The home page of the new application is created and displayed.

   ![3_Application ID and Tenant ID.png](https://help.secude.com/__attachments/a_85813cc6acee0d17986a1ee86304ae29fcffecd53bcc2febfa6371e61562f628/3_Application%20ID%20and%20Tenant%20ID.png?cb=dd7877a9998bda8c020421c568d86783)

   *Application ID and Tenant ID*
8. The following values are shown on the portal once registration is complete. To copy and save the ID value in a text editor, hover your cursor over it and click the **Copy to clipboard**icon.

   1. **Application ID** -- It is also referred to as **Client ID**.

   2. **Directory ID** -- It is also referred to as **Tenant ID**.

**Save the authentication parameters**

In a text editor (such as Notepad), copy the value of **Application (client) ID** and **Directory (tenant) ID** , andsave it for initializing the HaloENGINE Tomcat Service.

### Add Required Permissions

To protect content with MIP SDK, you must provide the necessary API permissions to the application created in the previous section.

1. In the sidebar of the application page, select **API permissions** . The **API permissions** page for the new application registration appears.

2. Click **Add a permission** button. The **Request API permissions** page appears.

3. Under the **Select an API** setting, select **APIs my organization uses**. A list appears containing the applications in your directory that expose APIs.

4. In the search box, type in the name of the permission indicated in the "Required Permissions" table below. Alternatively, you could scroll to find the API.

5. For example, type **Microsoft Information Protection Sync Service** into the search box. The following figure shows how the API is listed:

   ![4_API selection.png](https://help.secude.com/__attachments/a_f4d178ba610030e1b1777f1dbb89986dfb9835e4c74be36bcf4cfa15a8fc889c/4_API%20selection.png?cb=8c1d6c022930f601c05243b73c4d1c61)

   *API selection*
6. Now, click on the displayed API. You can see two permissions on the page − **Delegated permissions** and **Application permissions**.

7. Click **Application permissions** button and then under the **Permission** section, select the check box near "**Read all unified policies of the tenant**."

   ![5_Adding permission.png](https://help.secude.com/__attachments/a_d0bc61f4ddc977ea3732945337df85586c2ae6c765ed7a49de802fc724f5ae09/5_Adding%20permission.png?cb=283bf698511ce2a773a9e566419cf2a8)

   *Adding permission*
8. Click **Add permissions**.

9. Repeat the steps outlined above to add the other required permissions listed in the "Required permissions"table below.

10. You will be taken back to the **API permissions** page, where the permissions have been saved and added to the table with the status "**Not granted**."

    ![6_Required API Permissions without admin consent.png](/__attachments/a_ee96b5178cb4b5b28f49e092ac21df6e511b378e12ef89ce45f20406904d8ed1/6_Required%20API%20Permissions%20without%20admin%20consent.png?cb=57439cfdb17d4c7139f554d7b872b40d)

    *Required API Permissions*
11. Click **Grant admin consent** **for your company** button. You will be prompted to accept the consent confirmation; click **Yes**to the question.

12. After accepting the admin consent, the **Status** will change to "**Granted**."

    ![7_API Permissions with admin consent.png](/__attachments/a_a190eeed66418f50e2e11152aaf8afaf253ab1da2019185a999d1907093f8761/7_API%20Permissions%20with%20admin%20consent.png?cb=5aba9f9a908dd0e49f4d54bcf01910c5)

    *API Permissions with admin consent*
13. The following table lists the required permissions.

|                        **API / Permission Name**                        |      **Display Name**       |  **Type**   |                                                        **Description**                                                         |
|-------------------------------------------------------------------------|-----------------------------|-------------|--------------------------------------------------------------------------------------------------------------------------------|
| Microsoft Graph                                                         | `User.Read`                 | Delegated   | Sign in and read the user profile. This API permission is added by default, but the HaloENGINE Tomcat Service does not use it. |
| Azure Rights Management Services (Microsoft Rights Management Services) | `Content.DelegatedWriter`   | Application | Create protected content on behalf of a user                                                                                   |
| Azure Rights Management Services (Microsoft Rights Management Services) | `Content.Writer`            | Application | Create protected content                                                                                                       |
| Microsoft Information Protection Sync Service                           | `UnifiedPolicy.Tenant.Read` | Application | Read all unified policies of the tenant                                                                                        |

*Required permissions #1*

**Additional Permission (Only for Decryption)**

The permissions mentioned above are adequate for applying the MPIP label to a file with the owner as SPN (Service Principal Name) ID or any user email ID. Additionally, the HaloENGINE Tomcat Service requires the following superuser privilege for the decryption function when the owner is not as SPN.  

|                        **API / Permission Name**                        |  **Display Name**   |  **Type**   |                        **Description**                         |
|-------------------------------------------------------------------------|---------------------|-------------|----------------------------------------------------------------|
| Azure Rights Management Services (Microsoft Rights Management Services) | `Content.SuperUser` | Application | Read all protected content for this tenant in the Azure portal |

*Required permissions #2*

### Upload the Certificate in the Azure Portal

The HaloENGINE Tomcat Service relies on certificate-based authentication to access MPIP services. Therefore, you must enter your certificate information in the registered application before proceeding with the configuration.

Prerequisites:

1. **Certificate**:

   1. Ensure that you have a valid certificate containing the following key properties: `-KeyExportPolicy Exportable` and `-KeySpec Signature`.

   2. The certificate can also be self-signed. Note: As a best practice and for security reasons, use a self-signed certificate only in a test environment. It is not recommended for production environments.

2. **Local Computer** certificate store: The certificate required for MPIP authentication must be installed in the Local Computer certificate store, along with the Root CA and Intermediate CA certificates.

   1. If the certificate is CA-signed, install all related certificates in their respective stores (Root, Intermediate, and Personal).

   2. If the certificate is self-signed, install it in both the Trusted Root Certification Authorities and Personal stores of the Local Computer.

To upload the public key of the certificate, follow the steps below:

1. In the sidebar of the new application page, select **Certificate \& secrets**.

2. Under the **Certificate** section, click **Upload certificate** . The **Upload certificate**dialog appears as shown in the figure below:

   ![Upload certificate_1.png](https://help.secude.com/__attachments/a_7d2c73364492e70f34dcb4a824c49e59ebb45739f9784e783b44c0684d80b06c/Upload%20certificate_1.png?cb=9b028533c34b642a22254eac5af1b8b2)

   *Upload certificate #1*
3. Click on the folder icon to select the certificate and click **Open** . For illustration purposes, the file `DESKTOP001.cer` is used.

4. Now, click **Add**. The certificate will get uploaded, and its thumbprint will be displayed on the page as shown in the figure below:

   ![Upload certificate_2.png](https://help.secude.com/__attachments/a_80a8d6ecc4a494c11dc0ca26b28e0d6035d32c75554d7cc1e59a85edc2e9ab08/Upload%20certificate_2.png?cb=0623c0f3126f69195dfa9f8b7d86687e)

   *Upload certificate #2*

## Office 365 Subscription Details

1. Fully configured Microsoft Purview Information Protection.

2. An Azure subscription is required to use Azure RMS and the MPIP functionality.

3. A working Microsoft Entra ID service must be available.

4. Transport Layer Security (TLS) 1.2 or higher must be enabled to ensure the use of cryptographically secure protocols at all client workstations. Please refer to the section "[Enable Support for TLS 1.2 at the Client Workstation for Microsoft Entra ID](https://help.secude.com/haloengine/6.10/prerequisites.md#TLS)".

5. Audit logging: Your Azure subscription must include Log Analytics on the same tenant as Microsoft Entra ID.

### Create and configure Sensitivity Labels

As an administrator, you can create, configure, and publish sensitivity labels for various levels of content sensitivity based on your organization's classification taxonomy. Use names or terms that are familiar to your users. Consider starting with label names like Personal, Public, General, Confidential, and Highly Confidential if you don't already have a taxonomy in place. For more details, please refer to Microsoft online documentation.

### **Recommended URLs, Addresses, and Ports for MPIP**

MIP SDK doesn't support the use of authenticated proxies. Therefore, ensure that you set the Microsoft 365 endpoints to bypass the proxy. View a list of endpoints at "[Microsoft Online Documentation](https://docs.microsoft.com/en-us/microsoft-365/enterprise/urls-and-ip-address-ranges?view=o365-worldwide)". However, Microsoft recommends the following:  

|                                                                                                                                    **Addresses**                                                                                                                                     |                   **Ports**                    |
|--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|------------------------------------------------|
| `*.protection.outlook.com` `40.92.0.0/15`, `40.107.0.0/16`, `52.100.0.0/14`, `52.238.78.88/32`, `104.47.0.0/17`, `2a01:111:f403::/48`                                                                                                                                                | TCP 443                                        |
| `*.aadrm.com`, `*.azurerms.com`, `*.informationprotection.azure.com`, `ecn.dev.virtualearth.net`, `informationprotection.hosting.portal.azure.net`, `*.office.com` (add `substrate.office.com` if you don't want to add all sub-domains), `crl3.digicert.com`, `crl4.digicert.com` . | TCP 443, 80                                    |
| **For event logging** `*.events.data.microsoft.com`                                                                                                                                                                                                                                  | TCP 443                                        |
| **National Cloud**                                                                                                                                                                                                                                                                   | **Microsoft Entra ID authentication endpoint** |
| Microsoft Entra ID for the US Government                                                                                                                                                                                                                                             | `https://login.microsoftonline.us`             |
| Microsoft Entra ID (global service) For details on Microsoft Entra ID endpoints, please refer to "[++Microsoft Online Documentation++](https://docs.microsoft.com/en-us/azure/active-directory/develop/authentication-national-cloud#azure-ad-authentication-endpoints)".            | `https://login.microsoftonline.com`            |

*Recommended endpoints*

### **Enable TLS 1.2 for Microsoft Entra ID Authentication**

To improve the security posture of the tenant and to remain in compliance with industry standards, Microsoft Entra ID stopped supporting the following Transport Layer Security (TLS) protocols and ciphers:

1. TLS 1.1

2. TLS 1.0

3. 3DES cipher suite (TLS_RSA_WITH_3DES_EDE_CBC_SHA)

To authenticate with Microsoft Entra ID, TLS 1.2 must be enabled on the client workstation. For instructions, refer to the Microsoft documentation on enabling TLS 1.2. Please see this [Microsoft article to enable TLS 1.2](https://learn.microsoft.com/en-us/troubleshoot/azure/active-directory/enable-support-tls-environment?tabs=azure-monitor).  
**Microsoft documentation**

The information in the Microsoft documentation overrides any information published in this section.

Secude is not liable for changes to the content of this section because it was extracted from the Microsoft article at the time when the HaloCAD manual was prepared. Do check the most recent updates in this regard from the Microsoft documentation.

In summary, the following steps must be performed:

1. Update the Windows Operating System

2. Update .NET Framework

3. Set the following registry settings:

| **S.No** |                              **Windows Registry**                              |                                    **Values**                                     |
|----------|--------------------------------------------------------------------------------|-----------------------------------------------------------------------------------|
| 1        | `[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\.NETFramework\v4.0.30319]` | `"SystemDefaultTlsVersions"=dword:00000001` `"SchUseStrongCrypto"=dword:00000001` |
| 2        | `[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\v4.0.30319]`             | `"SystemDefaultTlsVersions"=dword:00000001` `"SchUseStrongCrypto"=dword:00000001` |

*Registry entries*

## Conditions for Running the HaloENGINE Tomcat Service

Before you begin, make sure that the following prerequisites are met in your system:

**Deny log on as a service** **policy**

If the service is running under a specific user or a specific group, ensure that the user is not restricted by the **Deny log on as a service** policy (Local Security Policy \> Security Settings \> Local Policies \> User Rights Assignment). If the user(s) exist, the "*Error 1069: The Service did not start due to a logon failure"* message appears while running the HaloENGINE Tomcat service.

**Allow non-admin users to access a private key (without full admin rights)**

During installation, the HaloENGINE gets the required Microsoft Entra ID application details and certificate thumbprint. When the HaloENGINE Tomcat service starts, it tries to connect to the MPIP services using the details entered during installation. As part of this process, it validates the certificate thumbprint against the certificate installed in the **Local Computer** certificate store. The thumbprint entered in the installation wizard must match the one available in the Local Computer certificate store.

If the service runs under a non-administrative user account, the user may not have sufficient permissions to access the certificate's private keys when the certificate is installed in the Local Computer store. This restriction prevents successful authentication with MPIP services. To resolve this issue, grant the user **Read** permission to access the certificate's private key by following the steps listed below.

Any errors encountered during this process are recorded in the log file. If the verification succeeds, the service proceeds with initialization.

**Prerequisites**

1. The required certificates (machine certificate, root CA, and intermediate CA) are already installed.

2. The private key is stored in the **Windows Certificate Store** under **Local Computer**.

3. You have administrative rights to perform the setup.

Follow the procedure below to grant read access:

1. Open **Certificate Manager** as Administrator.

2. Press **Win + R** , type mmc, and press **Enter**.

3. In the console, go to **File** and select **Add/Remove Snap-in**.

4. Select **Certificates** from the list and click **Add**.

5. Choose the **Computer account** , then click **Next** , followed by **Finish** , and then **OK**.

6. In the left panel, expand **Certificates (Local Computer)** , expand **Personal** , and select **Certificates**.

7. Identify the certificate that contains the private key.

8. Right-click the certificate, select **All Tasks** , and then select **Manage Private Keys**.

9. In the **Permissions** window, click **Add** and enter the non-admin username (for example, TESTIL) and click **OK**.

10. Select the **Read** permission, click **Apply** , and then click **OK**.

    ![Non Admin User.png](/__attachments/a_732e3f47d00dce45c6f21d91f7a710bc79f9aa44284bc61b25772ed58d21504e/Non%20Admin%20User.png?cb=20b53018a82791a1a73ab679395cf49d)

    *Granting private key access to a non-admin user*

## Obtain the HaloENGINE License

Before installing the HaloENGINE, we recommend obtaining the license file (`license.lic`) from Secude support to enable the HaloENGINE functionalities. The license file you received from Secude will include specific features and system types. This implies that only the system types specified in the license are accessible via their respective endpoints.  
**Avoid renaming the license file.**

Once you have received the license file from Secude, use it exactly as is, without changing its name. Renaming the file prevents the license from activating.

The following picture illustrates how the client communicates with the HaloENGINE.  
![HaloENGINE_System Types.png](https://help.secude.com/__attachments/a_bac5ad985453e1b8cf59dfdfc94080ad6249c102b8cab81a48f27775c6777017/HaloENGINE_System%20Types.png?cb=2c8eebaf5148d84d359cdc2f375830fb)

*System types and protocol*

The table below will assist you in deciding the type of license you should obtain from Secude.  

| **Customer Requirement** | **License Specification** |                                                                      **Description**                                                                      |
|--------------------------|---------------------------|-----------------------------------------------------------------------------------------------------------------------------------------------------------|
| Monitor                  | Monitor                   | A customer environment that only needs the monitoring feature.                                                                                            |
| Block                    | Monitor + Block           | A customer environment that just requires the blocking feature. However, monitoring is included as a standard feature.                                    |
| Block and Protect        | Monitor + Block + Protect | A customer environment that requires blocking and protecting features. A full license with all three features (Monitor, Block, and Protect) must be used. |

*Obtaining license*

## User Management Settings

Make a default (also known as regular) administrator account after installing the HaloENGINE component. This account is referred to as "Super Admin," and it has greater access than a typical administrator account. This account has full access to your HaloENGINE component.

### **User Accounts**

|         **User Account 1**         |               **User Account 2**                |               **User Account 3**                |
|------------------------------------|-------------------------------------------------|-------------------------------------------------|
| Default Super Admin account        | Customer_Admin                                  | Customer_User                                   |
| Role: ROLE_SUPER_ADMIN             | Role: ROLE_CUSTOMER_ADMIN                       | Role: ROLE_CUSTOMER_USER                        |
| User validation: Locally validated | User validation: Microsoft Entra authentication | User validation: Microsoft Entra authentication |

*User Accounts*

#### **Settings in Azure Portal**

User management is often included with Microsoft Azure and involves several request exchanges between the HaloENGINE Admin Portal and the identity provider, Microsoft Entra ID.  
**Microsoft documentation**

Any application that wants to use Microsoft Entra ID for authentication must be registered in its directory. The information in the Microsoft documentation overrides any information published in this section. For a detailed explanation, please see the Microsoft documentation.

In the Azure portal, follow the steps below to configure user authentication and authorization settings.

##### **Step 1: Create a New Web Application**

1. You can either leverage an existing Web (Redirect URI) application or create a new one in Azure Portal. To serve as an example, the Web application **User Management** is created.

2. When registration is complete, the Overview page displays the **Application ID** and **Tenant ID** values. These values uniquely identify your application on the Microsoft identity platform. To preserve the values, copy them to the clipboard and paste them into a text editor (such as Notepad).

##### **Step 2: Authentication Settings**

1. In the left navigation pane, select **Authentication**.

   ![1_User Management.png](https://help.secude.com/__attachments/a_ebca479aef6eb172db5b04adfc20302667c3abe5965654b985620578b483e271/1_User%20Management.png?cb=e687eccd070373d7ae3eebda619f3291)

   *Authentication settings*
2. Under the **Web** section, click **Add URI** and enter the following reply URLs one by one:

   1. `https://login.azure.net/authResponse`

   2. HaloENGINE Admin portal URL:

      * `https://<ip>:<port>/haloengine-admin/login/oauth2/code/<tenant name>` (for example, `https://10.91.0.65:8746/haloengine-admin/login/oauth2/code/halosecude`)

      * Or `http://<localhost>:<port>/haloengine-admin/login/oauth2/code/<tenant name>` (for example, `http://localhost:8383/haloengine-admin/login/oauth2/code/halosecude`)

3. Under **Front-channel logout URL** section, enter the URL − `https://login.azure.net/logout`.

4. Under the **Implicit grant and hybrid flows** section, select **Access tokens,** and **ID tokens**checkboxes.

5. Click **Save**.

##### **Step 3: Certificates \& Secrets**

1. In the left navigation pane, click **Certificates \& secrets**.

2. Under **Client secrets** , click **+ New client secret**.

3. On the **Add a client secret** page, enter a **Description** , choose the **validity period** under **Expires** , and click **Add**.

4. After clicking **Add** , a new row appears under **Client secrets**.

   ![Secretkey.png](https://help.secude.com/__attachments/a_38c84512cff835f6ffa7873e90de74eebd564c2cc3d8b32122494e8120a1ff27/Secretkey.png?cb=cf381e8f5b9ed12eae22de0990a48ebe)

   *Client secret value*
5. Copy the **Value**field immediately, as it will only be displayed once.

6. Store this value securely and use it for [Tenant Configuration](https://help.secude.com/haloengine/6.10/phase-10-tenant-configuration.md).

##### **Step 4: Token Settings**

1. In the left navigation pane, select **Token configuration** and click **Add groups claim**.

   ![2_Token Settings.png](https://help.secude.com/__attachments/a_ab6492a279095aa12d45e616019f0fc8677d7b61aa5916fdc665105ac7978e26/2_Token%20Settings.png?cb=c1a7a26b77185b099a2a7744957f8d8d)

   *Token Settings*
2. Select the following options:

   1. Security groups

   2. Directory roles

   3. All groups

3. Click **Save**.

##### **Step 5: Expose API**

1. In the left navigation pane, select **Expose an API**.

   ![3 Expose an API_1.jpg](https://help.secude.com/__attachments/a_4b2c77a43fff7169f573ce5a31720a1f0b86add0d95b35d07857c96625084702/3%20Expose%20an%20API_1.jpg?cb=a954dcef83ec0d68f0256f197c470065)

   *Adding scope#1*
2. Click **Add a scope** and enter the scope following `api://` in **Application ID URI** . In this example, `api://halocoreadmin` is used.

3. Click **Save and Continue**.

4. Again, click **Add a scope** and enter the following values:

   ![3 Expose an API_2.jpg](https://help.secude.com/__attachments/a_443623d4cb428113cd9800d7da9e30bdea78134433861a998ba7b34bba004c28/3%20Expose%20an%20API_2.jpg?cb=730764ac08efcd49b9aa13c5d382e2ae)

   *Adding scope #2*
   1. **Scope name** : enter `Config.ReadWrites`

   2. **Who can consent**?: select Admins and users

   3. **Admin consent display name**: enter HalocoreAdminConsent

   4. **Admin consent description**: enter Halocore Read and Write

   5. **State** : select **Enabled**

5. Click **Add scope**. You can see the scope displayed in the UI.

6. Copy the generated scope `api://halocoreadmin/Config.ReadWrites` to the clipboard and save it in a text editor (such as Notepad).

##### **Step 6: Create Roles**

1. In the left navigation pane, select **APP roles**.

2. Click **Create app role** and enter the following values:

   1. **Display name**: ROLE_CUSTOMER_ADMIN

   2. **Allowed member types** : select **Users/Groups**

   3. **Value**: ROLE_CUSTOMER_ADMIN

   4. **Description**: CUSTOMER_ADMIN

   5. **Do you want to enable this app role?** -- Select this option.

   6. Repeat the above steps for the role **ROLE_CUSTOMER_USER**.

      ![4 Roles_1.png](/__attachments/a_9e3c015a7dc7fc3d170bf44632e5596ecc99bc074c13610bc65b230063bbacd7/4%20Roles_1.png?cb=11da6270d2b91e226c084c757869976d)

      *Adding Roles*
3. Click **Apply**.

4. The roles are added to the list.

   ![4 Roles_2.jpg](https://help.secude.com/__attachments/a_7861ca8500224723631bcf37cfa48be489f6bbe37b4399017343ecb79a16aea9/4%20Roles_2.jpg?cb=1b4f2adcbf64ad1e568429c63016af71)

   *Create Roles*

##### **Step 7: Apply Role to Users**

1. In the **Microsoft Entra ID** pane, select **Enterprise applications**.

   1. The **Enterprise Applications** page will appear with a list of existing Service Principals in your tenant.

   2. In the search box, enter your application name. In this example, **User Management** is entered in the search box.

      ![5 Enterprise Application #1.png](/__attachments/a_2d80a0ae4959a64f63862fede23d4fa18d8c007355f520dd62a07257710f5295/5%20Enterprise%20Application%20%231.png?cb=0854dc3b64f389a9c011730468f16572)

      *Apply role to user #1*
   3. The search result will be displayed.

   4. Now, click on the link from the list. The **Overview** page of the application will appear:

      ![5 Enterprise Application #2.png](/__attachments/a_6d4c9a06219b8403ad90feec33736df92569c84666e44cb4fed70c37c42be506/5%20Enterprise%20Application%20%232.png?cb=2b905be304400bba81775e8ea6984513)

      *Apply role to user #2*
   5. Click **Assign users and groups** . The **Users and groups**page will appear.

   6. On the **Users and groups** page, click **Add user/group** . The **Add Assignment** page will appear.

   7. Under **Users and groups**:

      * Click **None Selected**and search for a user (for example, John).

      * Click **Select** and **Assign**.

        ![5 Enterprise Application #3.png](/__attachments/a_360e4b21a241064a5e3807b4844811977bde57e579b68b8fc50ad24cebebcb66/5%20Enterprise%20Application%20%233.png?cb=f24e61049c3da03348205535b166c63b)

        *Adding users*
   8. Under **Select a role**:

      * Click **None Selected** and search for the role ROLE_CUSTOMER_ADMIN.

      * Click **Select** and **Assign**.

        ![5 Enterprise Application #4.png](/__attachments/a_9e7dd2feb1c1b8a118de6483b32edf98aa57388ef9ddf9b2da68105aa542ebe5/5%20Enterprise%20Application%20%234.png?cb=1e539949bb949d05d0ef53670714d327)

        *Apply role to user #3*
   9. Repeat the above steps for the role ROLE_CUSTOMER_USER (for example, user Derek is assigned to this role).

2. **Related tasks** : After the initial configuration of the HaloENGINE Admin Portal, you need to use the above values to configure tenant details. Please refer to the section "[Phase 7. Tenant Configuration](https://help.secude.com/haloengine/6.10/phase-10-tenant-configuration.md)".

## Forward Logs to Microsoft Sentinel

Microsoft Sentinel is a scalable, cloud-native security information and event management (SIEM) that delivers an intelligent and comprehensive solution for SIEM. Microsoft Sentinel provides cyberthreat detection, investigation, response, and proactive hunting, with a bird's-eye view across your enterprise. To begin using Microsoft Sentinel, the log analytics workspace must be configured.

### Configure Microsoft Sentinel

The explanation given in this section is only meant to serve as an example. Only the fundamental procedures for creating a workspace are shown in this section. Please refer to the [Microsoft documentation](https://docs.microsoft.com/en-us/azure/sentinel/) for a detailed explanation of the configuration and settings. The information in the Microsoft documentation overrides any information published in this section.

Prerequisite: Ensure that you have permission to perform this procedure.

1. Log in to the Microsoft Azure portal.

2. In the search bar, type **Microsoft Sentinel**. As you start typing, the list filters according to your input.

3. Select **Microsoft Sentinel** from the search results.

4. The **Microsoft Sentinel** page will appear. Here, you need to click **Create**at the top of the page.

5. On the **Add Microsoft Sentinel** **to a workspace** page, click **Create a new workspace**.

6. The **Create Log Analytics Workspace** page will appear as shown below, and you must enter the required details on this page.

   ![Creating Azure Sentinel 1.png](https://help.secude.com/__attachments/a_00eb51ad5d994ddf32b74b09e8e202a61f55e33aeeb39e082fb461a0d7f20c75/Creating%20Azure%20Sentinel%201.png?cb=923eec101935a4579a82e1035362469b)

   *Workspace #1*
7. Select a resource group from the list.

   1. Provide a name for your workspace.

   2. Choose a region from the list.

8. Once that is done, you can leave other options as-is, and then click on **Review + Create** and finally click on **Create** after the validation.

   ![Creating Azure Sentinel 2.png](https://help.secude.com/__attachments/a_a7622287079d16185763aeea16c7bab9529698043688da8427492ebac596c06a/Creating%20Azure%20Sentinel%202.png?cb=175f6d75d407cd40c030031fbd9b4cc4)

   *Workspace #2*
9. The new workspace will be listed as follows:

   ![Creating Azure Sentinel 3.png](https://help.secude.com/__attachments/a_5b6c55accffd126ebde1e6b646bdea9d2a677c8b2a2a9fa95169c0dba6a8ac19/Creating%20Azure%20Sentinel%203.png?cb=bb5a67305f3fdc10c08c823af6273141)

   *Workspace #3*
10. Select the new workspace and click **Add** . The **Add**button will only be enabled if you have the required permission.

11. The connection between Microsoft Sentinel and Log Analytics is successfully created.

#### Fetch Key Details from Log Analytics Workspace

This section describes how to obtain the Log Analytics agent keys. Log Analytics agent keys are required to transfer logs from the HaloENGINE Admin portal to Microsoft Sentinel.

1. On the search bar, type **Log Analytics workspace**. As you start typing, the list filters according to your input.

2. Select**Log Analytics workspace** from the search results.

3. The **Log Analytics workspace** page now includes the new workspace you created in the previous section.

4. Select the new workspace.

5. In the menu, select **Settings** \> **Agents**.

6. The page will provide the necessary information, including the **Workspace ID** and **Primary Key**.

   ![Creating Azure Sentinel 4.png](https://help.secude.com/__attachments/a_ac26f14d8bf604c2d9db0a1e444942a6bf12b6e29f853fb7dd9cac76826e87bf/Creating%20Azure%20Sentinel%204.png?cb=5123dc29ab434498ffcb74b9aacc00f3)

   *Workspace #4*
7. In a text editor (such as Notepad), copy the values of the **Workspace ID** and **Primary key,** and save them for configuring the "[Sentinel Log](https://help.secude.com/haloengine/6.10/phase-8-configure-haloengine-features.md#Sentinel)" in the HaloENGINE Admin portal.

---
version: "6.10"
language: "en"
---
# Release Notes

## Introduction

The release notes provide brief and high-level descriptions of the new features of HaloENGINE. Before installing HaloENGINE, it is recommended to read the release notes to understand any current limitations or bugs that may apply to this version of the software.

## Product Description

HaloENGINE is a Java-based classification engine that applies business logic and integrates with the Microsoft Purview Information Protection service to fetch the sensitivity labels for configuration in the admin portal. Using metadata, it classifies and organizes data while enforcing schemas and action rules, serving as the core component that works with the HaloCAD for PLM/PDM solution to protect data.

## Requirements

The following system requirements table outlines the minimum and recommended technical specifications, including software and network requirements, necessary to run the product.  

|  **Components**  |                                                                                    **Details**                                                                                    |
|------------------|-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| Operating System | Supported only on Microsoft Windows Server 2022 or later with the latest system updates installed.                                                                                |
| Applications     | 1. MongoDB Compass 7.0.7 2. Requires **.NET** Framework 4.6.2 and above. 3. The HaloENGINE Admin portal supports the most recent versions of Microsoft Edge, Chrome, and Firefox. |

*Requirements*

## Prerequisites

Before installing the HaloCAD component, ensure that the following prerequisites are met:

1. An application of type Web is registered with Microsoft Entra ID.

2. An active Office 365 subscription is available.

3. Access to the recommended URLs is enabled.

4. TLS 1.2 or later is enabled on all client workstations to ensure secure communication.

For more information, refer to the **Installation Manual**.

## Code Quality and Security

Secude focuses on software quality and security. This is accomplished by adhering to and exceeding best practices in development, testing, and quality control. Secude has chosen SonarQube as the first building block for building and implementing a robust continuous code quality assurance (QA). SonarQube is a platform for static code analysis for continuous inspection of code quality. It performs automatic reviews of code to detect bugs, code smells, unit test coverage, and security issues in 29 programming languages.

SonarQube is utilized throughout the development process at Secude, and only the highest marks are accepted for a product to be released. It helps to regulate code quality from the beginning of development, find and repair issues promptly, and improve overall software stability.

Each build report can be found under its relevant version heading in this release notes.

**Reliability Rating**

1. A = 0 Bugs

2. B = at least 1 Minor Bug

3. C = at least 1 Major Bug

4. D = at least 1 Critical Bug

5. E = at least 1 Blocker Bug

**Security Rating**

1. A = 0 Vulnerabilities

2. B = at least 1 Minor Vulnerability

3. C = at least 1 Major Vulnerability

4. D = at least 1 Critical Vulnerability

5. E = at least 1 Blocker Vulnerability

**Security Review Rating**

The Security Review Rating is a letter grade based on the percentage of Reviewed (Fixed or Safe) Security Hotspots.

1. A = \>= 80%

2. B = \>= 70% and \<80%

3. C = \>= 50% and \<70%

4. D = \>= 30% and \<50%

5. E = \< 30%

**Maintainability Rating**

A=0-0.05, B=0.06-0.1, C=0.11-0.20, D=0.21-0.5, E=0.51-1

The Maintainability Rating scale can be alternatively stated by saying that if the outstanding remediation cost is:

1. \<=5% of the time that has already gone into the application, the rating is A

2. Between 6 to 10%, the rating is a B

3. Between 11 to 20%, the rating is a C

4. Between 21 to 50%, the rating is a D

5. Anything over 50% is an E

## Build 6.10

This chapter provides an overview of the updates and quality insights included in this release. It covers the fixed issues, improvements, limitations, new features, and known issues, along with a summary of SonarQube's key parameters to highlight code quality metrics and analysis results.

### New Features

There are no new features to highlight in this release.

#### Improvements

This section lists improvements added to the current release.

1. Updated the REST SDK to use the REST JSON interface. HENGINE-3279

2. Updated HaloENGINE to support Apache Tomcat 10.1.52. HENGINE-3280

#### Limitations

This section lists the limitations of the current release.

Currently, Wildcard **\***is only supported when defining categorization rules and custom pre-expressions. HENGINE-1760

#### Fixed Bugs

This section lists the fixed issues in the current release.

1. Fixed an issue where the parent label was listed separately in the label list on the Action Rule page. HENGINE-3270

2. Restored the `getLocalSetMetadata()` function required for Teamcenter integration. The function was previously available in the `haloengine-proto-rest.jar`, but was missing after it was replaced by **haloengine-restclient** in the recent update. This fix ensures that Teamcenter can fetch values from HaloENGINE during file upload and correctly set the `ip_classification` attribute. HENGINE-3272

3. Fixed an issue that caused automatic logout in the HaloENGINE portal and logged an exception in the admin log. HENGINE-3282

4. Fixed an issue that prevented file extensions from being deleted in the CAD file types configuration. HENGINE-3283

#### Known Issues

This section describes the known issues with the current release.

1. The file type will be displayed as '**unknown**' when an already labeled (MPIP) non-office file is downloaded. HENGINE-1393

2. When downloading an assembly file with many dependent files from the Windchill workspace and selecting the **Open in Creo** option, the document is downloaded and opened in the Creo application. Still, the temporary files are saved in the HaloENGINE temporary folder. HENGINE-3074

3. Logs will not appear in the HaloENGINE Dashboard if the Scheduler file path is specified. HENGINE-3072

4. During the upgrade flow on the **Welcome Page** , while importing configuration, server and client certificates are imported into the Admin Portal even when the **Without certificate** option is selected. HENGINE-3290

#### Function as Designed

Beginning with this release, the dashboard displays Total Users, Total Actions, and Total Processed as "0", and File Types, Regions, and System Name as **null** or **unknown**when old monitor logs are used. Only the new PLM monitor logs are supported. HENGINE-3288

## Quality Gate Report

Please see the table below for a list of SonarQube's key parameters for this version. Refer to the "[Code Quality and Security](https://help.secude.com/haloengine/6.10/release-notes.md#code)" section for more information on rating definitions.  

|         **Metric**         | **Value** |
|----------------------------|-----------|
| Coverage                   | 80%       |
| Maintainability Rating     | A\*       |
| Reliability Rating         | A\*       |
| Security Hotspots Reviewed | A\*       |
| Security Rating            | A\*       |

*Quality Gate report*

---
version: "6.10"
language: "en"
---
# Setting Up Classification Engine

This chapter describes how to set up HaloENGINE.

## Quick Start Set Up

The process of configuring the Classification Engine is shown in high-level detail in the figure below.  
![HaloENGINE_Setting up Classification Engine.png](https://help.secude.com/__attachments/a_9637e3700827b6230ae3555c54505082d0bc75962745ecb4106addbfa99521fe/HaloENGINE_Setting%20up%20Classification%20Engine.png?cb=00bfa3a0fddcdb413c4d1f0fe376884c)

*Setting up the Classification Engine*

The license file obtained from Secude specifies the available features and supported system types. Accordingly, you can access only the system types listed in your license.

This chapter describes the Monitor, Block, and Protect features that apply across various system types, including Windchill, Teamcenter, Keytech, Autodesk Vault, SOLIDWORKS PDM, and HaloENGINE_API. For illustration purposes, Windchill is used as the visual example throughout this chapter. Refer to the HaloCAD for PLM/PDM Operations Manual if you would like to view the metadata, log, and user interface for a particular system type.

## Logging into the Admin Portal

Follow the steps below to configure the HaloENGINE features and classification properties:

1. After reloading, you will be directed to the login screen, as seen in the figure below.

   ![Login page after initial configuration.png](https://help.secude.com/__attachments/a_bf26c532dee7bc6644fb233e9be1fbcca55dde8583f2825ef8d267dfd0f5a700/Login%20page%20after%20initial%20configuration.png?cb=2d11f2fe4f7ccec9209ff41787272fc7)

   *Login page after initial configuration*
2. Enter the password that was assigned in the initial configuration. Note: Copying and pasting are not allowed in this field.

3. **Results**:

   1. The HaloENGINE Admin Home page is the first page displayed after you log in to the portal.

   2. Please refer to the following section.

**Invalid credentials or the number of sessions exceeded**

You might occasionally receive the message "*Invalid credentials or number of sessions exceeded*" while attempting to enter the admin portal. One of two things could be the cause of this message:

1. Entered an invalid password.

2. Opened a second session, or even suddenly ended the current one by closing the tab rather than logging out of the application (wherein the session remains internally active). You might need to clear the browser cache in this case.

## HaloENGINE Admin Portal Home Page

When an administrator logs in to the Admin Portal, the **Home** page is displayed as the default landing page. This page provides several options that assist you in managing and configuring the portal. Before proceeding with other administrative tasks, it is recommended to familiarize yourself with the main elements of the Home page and understand how to interact with them. The Home page appears as shown in the following figure. The key sections of the Home page are highlighted below.  
![Home Page.png](https://help.secude.com/__attachments/a_46190f18ef002e12994e44299959f2c8bd095c39a97beab791af7ef5832d1879/Home%20Page.png?cb=6d4c5d2287453e5301eeb9bc37e971f0)

*Home page*  
**Directory Access**

After completing the configuration, there will be a set of folders with essential files created on the HaloENGINE installed location. The default location is `C:\Program Files\Secude`. It is recommended to ensure that the `C:\Program Files\Secude\HaloENGINE\config` directory allows accessing it in your system. To allow access, you can assign folder permissions to "ALL APPLICATION PACKAGES".

## **UI Elements Description**

Each UI element is briefly described in the following table.  

| **S.No** |                                                                                                                                                      **Elements**                                                                                                                                                       |                                                                            **Description**                                                                             |
|----------|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1        | ![Plus.png](https://help.secude.com/__attachments/a_0fa3b2962d3bf2c5c38a0b11eda669eaf81e20496b2a6029a6cd9213e442102e/Plus.png?cb=c4bed187299105f07ede301b2ce3227b)                                                                                                                                                                             | Use this icon to create a customer ID, profile, property, rule, client, and create (server or self-signed) certificate.                                                |
| 2        | ![Edit Icon.png](https://help.secude.com/__attachments/a_ac399427074f39a39fb11b16df0c27100c1ad4079c63195d4e403a139c951a31/Edit%20Icon.png?cb=0bafc69a05201a041d88e0e3d1b91335)                                                                                                                                                                 | Use this icon to edit an existing customer ID, profile, property, rule, and client.                                                                                    |
| 3        | ![Details.png](https://help.secude.com/__attachments/a_2a03ae720b58b7aa3ef7757ab2bc641d3d015d5f1426909a57550aaa430f3679/Details.png?cb=5dd77e31cfae9b23b359ed82054d796f)                                                                                                                                                                       | Use this icon to view the details of the customer, profile, property, service, and rule.                                                                               |
| 4        | ![Copy.png](https://help.secude.com/__attachments/a_376cc489c9f59451426fdd8e1c5538b63dd3cd9b882e54424a45995861cdf651/Copy.png?cb=22f2953df2ec788052a1b7420d5b288e)                                                                                                                                                                             | Use this icon to copy an existing profile, property, and rule. For example: Select an existing profile \> Click **Copy** icon \> Modify the name \> Click **Save**.    |
| 5        | ![Delete Icon.png](https://help.secude.com/__attachments/a_d3d2aea343f2d948a86a1e1b487a4eede9affb4a342a9532bfb3d949803a0236/Delete%20Icon.png?cb=44824a3858e5250b12ff7633db933ddc)                                                                                                                                                             | Use this icon to delete an existing profile, property, rule, client, and Keystore.                                                                                     |
| 6        | ![Up arrow.png](https://help.secude.com/__attachments/a_00c7b2c2484443282505f2a4fafc95eca360b2b303f58e2740fb992266d6046e/Up%20arrow.png?cb=f34ea2142e4fb8122de9284c7310690c)                                                                                                                                                                   | Use this icon to move a rule to the top.                                                                                                                               |
| 7        | ![Down arrow.png](https://help.secude.com/__attachments/a_514c9ae419db099ca95b189c400000a14f7384cd92adf9972247baf150b66ef7/Down%20arrow.png?cb=aaf338ed80ede8a91fe0dc5dc8db6a6e)                                                                                                                                                               | Use this icon to move a rule to the bottom.                                                                                                                            |
| 8        | ![Restore button.png](https://help.secude.com/__attachments/a_4a397accbf310525eaeeafcdcdb7261c9315daacb1360cd23a7809410ead8714/Restore%20button.png?cb=156c54cebc915b189f0c545e81b6e013)                                                                                                                                                       | Use this icon to revert to the previous settings.                                                                                                                      |
| 9        | ![Save button.png](https://help.secude.com/__attachments/a_f434cb31ee42dc089e6b698ab8c2c21878cc84c2ff68a49573e793e2e09bccf3/Save%20button.png?cb=d8c4f03d14e33e22e6e13fe62e6c10a6)                                                                                                                                                             | Use this icon to save the current settings.                                                                                                                            |
| 10       | ![Export icon.png](https://help.secude.com/__attachments/a_2570515538dfc9ec71dc45749403e7574806559155624dbc982e94d379a6fb42/Export%20icon.png?cb=03e402b442e51e434c9fd5b78877de1e)                                                                                                                                                             | Use this icon to export a certificate/profile and download service logs.                                                                                               |
| 11       | ![Import icon.png](https://help.secude.com/__attachments/a_e1bacdf058cfac72ab9af1462844cb58305de630604eb6fa7adec9fadffe1a54/Import%20icon.png?cb=cbbe41d01e85269cd4f9b45b33dd84db)                                                                                                                                                             | Use this icon to import a certificate/profile. For example: Click **Import Profile** icon \> Click **Select Profile zip file** \> Select the file \> Click **Import**. |
| 12       | ![Slider button.png](https://help.secude.com/__attachments/a_9559ac4957ef71938ea38fbc07d67e80c29e3ffcddc0a3b47a9bae378481b602/Slider%20button.png?cb=a2e16a2c0d1be9b4dc8e5c5b37f232ca) ![Deactivate.png](https://help.secude.com/__attachments/a_b03890b4ac1fbfaed0a2dfdc9281f7d86e945308b72aebf4c7e3b148483f58f6/Deactivate.png?cb=514534a4eea1c3749dffc23f9fdd0faa) | Use this slider button to enable/disable a setting.                                                                                                                    |
| 13       | ![Attach icon.png](https://help.secude.com/__attachments/a_6ec2f6b762f5bb5819c7a11bb189c3b4ae44cc589965ed685c630173ced5d554/Attach%20icon.png?cb=4aa63b55647bae72aa60e50ae0d163f2)                                                                                                                                                             | Use this button to attach a file.                                                                                                                                      |
| 14       | ![image-20260410-080009.png](https://help.secude.com/__attachments/a_907417f60bb3f6430ab6a06f3b326c973d48540b1e3345e90e22209b9233ae5e/image-20260410-080009.png?cb=c05cce41e3e1d8d1f772e6ab8cbdddd7)                                                                                                                                           | Breadcrumb This UI pattern is a secondary navigation link that helps users track their location within the application.                                                |

*Elements Description*

---
version: "6.10"
language: "en"
---
# System Configuration

The initial configuration settings on the System Configuration page can be updated at any time. This page also handles certificate and password management. You can set a password policy if necessary for your business environment, but it is not mandatory.  
![System Configuration.png](https://help.secude.com/__attachments/a_85fcd30850e8c4e0122cebe57fffa0560dd293613ff763b6a7c68b876c3dfd7f/System%20Configuration.png?cb=85f5770c4cb14d9926c332396869022a)

*System Configuration page*

## HaloENGINE Configuration

**Basic Configuration**

Follow the steps below to update the basic HaloENGINE configuration:

1. Login admin portal.

2. On the left navigation bar, click **System Configuration** , and then on the **HaloENGINE Configuration** tab, click **Configure**.

3. Update the following:

   1. Log level

   2. Path for HaloENGINE configuration files

   3. Path for HaloENGINE system log

   4. Retention period of HaloENGINE log

   5. Retention period of Tomcat log

   6. Enable/disable remote access

4. To make basic configuration changes take effect, click **Apply** and then click **Reload Configuration** in the left navigation bar.

   ![HaloENGINE Configuration.png](https://help.secude.com/__attachments/a_a43860505d4606031d6e876718c6c89c5ca0b9063aff699bc8c3d77b75cf5488/HaloENGINE%20Configuration.png?cb=ccd96e834f1f3d1dd630fc98bef2df7b)

   *HaloENGINE Configuration*

   **Results**:
   1. The page will be directed to the login page once the reload is done.

   2. If any changes are made to Remote Settings, please restart the HaloENGINE Tomcat service.

**Password Policy**

HaloENGINE's password policy requires a minimum of 12 characters and a maximum of 30 characters to increase security. However, the length of a company's password policy is determined by security requirements, regulatory obligations, and industry best practices. Therefore, you can configure or update your length seamlessly on this page.

1. Select the **Password Policy** tab and enter the following details as shown in the figure below:

   ![Password policy.png](https://help.secude.com/__attachments/a_437422acb1df07896d564c464780efb6bcd1bb677a60d7bcf0cdee7a22c7ab97/Password%20policy.png?cb=d9032d062356d0bc87bfce5d806e46f2)

   *Password policy configuration*
2. **Password minimum length** − Enter the minimum number of characters required for your password. The default setting allows more than 12 characters.

3. **Password maximum length** − Enter the maximum number of characters required for your password. The default setting allows up to 30 characters.

4. **No. of special character** − Enter the number of special characters that should be included in your password. The default setting requires at least one special character. Note: If you set a Password Policy that includes more than one special character, you must input the password continuously. For example, if you set the **No. of special character** to 2, input them one after the other (for example, Pass234567!$). Entering special characters apart (for example, Pass!234567$) in the new password field will not be accepted.

5. Click **Apply**.

   **Results**:
   1. You will receive a confirmation message after successfully updating the password policy, followed by a warning message, "*Please change your Password*."

   2. On the warning message screen, click **Change Password** . The **Change Admin Password** screen appears. Enter your current password, create a new password, and confirm it in the text boxes provided. For more details, please refer to the section "[Change Password](https://help.secude.com/haloengine/6.10/system-configuration.md#CP)".

   3. The admin portal will restart automatically, and you must enter a new password to access it. The current password cannot be reused."

### Import/Export Configuration

Exporting the configuration is important because the exported configuration file can be imported during a new installation, allowing retention of existing settings, reducing the time and effort needed for reconfiguration, ensuring consistency across environments, and minimizing the risk of misconfigurations or errors.

Follow the steps below to update the import/export configuration:

1. On the left navigation bar, click **System Configuration** , and then on the **Import/Export Configuration** tab, click **Configure**.

2. **To import**:

   1. Select either **Upload with Certificate** to import the configuration file along with the existing certificate, or **Upload without Certificate** to import the configuration file without the certificate.

   2. Click on the button and select the `HaloENGINE-admin-config.zip` file from the **Open**dialog box.

   3. **Results**: You can see the name of the zip file displayed on the page.

      ![Import Configuration.png](/__attachments/a_ca126fb5d953bc2558694a8b449bb1274ed02bf76eb6a6fa4e0802e560110f7f/Import%20Configuration.png?cb=082aa300724a70976d10cd3e14a5007e)

      *Import Configuration*
3. **What to do next:** Restart the HaloENGINE Tomcat service for the configuration update to take effect.

4. **To export**:

   1. Click **Export Configuration** and then click **Export Config**button.

   2. Please wait while the file `HaloENGINE-admin-config.zip` is downloaded.

### CAD File Types Configuration

Use this page to add a new CAD file extension that will enable encryption and decryption for CAD-compatible file formats.

To add a new file extension, follow the steps below:

1. On the left navigation bar, click **System Configuration** , and then on the **CAD File Types Configuration** tab, click **Configure**.

2. The *CAD Filetypes* page appears as shown in the figure below:

   ![CAD File Types Configuration.png](https://help.secude.com/__attachments/a_1cafd107bbb7ebd48fc5295ee4be182528bf3801f867f140a7e6e0c268a97a7f/CAD%20File%20Types%20Configuration.png?cb=bfcf002be2d185a44f2b80da8b1b10f7)

   *CAD File Types Configuration*
3. **Option 1**:

   1. To change the Creo Iteration of a file type from the existing list.

   2. Turn ON the **Enable Creo Iteration** slider for the file type. In this example, `.iam` is enabled with Creo Iteration.

4. Click **Save**.

   **Results** : You can see a confirmation message after saving the file type. In the example below, the `.iam` row gets appended to the end of the list with **Creo Iteration Enabled = true**.  
   ![Creo Iteration Enabled.png](https://help.secude.com/__attachments/a_4f1cd622d1a1d1c96e2ba58ce568719b4fa44c06c287b2b2833a1124e71ff0fc/Creo%20Iteration%20Enabled.png?cb=1881221beee323a1324e81c344ba0f3f)

   *Creo Iteration Enabled*
5. **Option 2**: To add a new file extension.

   1. Click the plus icon and enter the file extension along with Creo Iteration Enabled = true/false status.

   2. Click **Save**.

      **Results** : After saving the file type, a confirmation message appears, and the new entry is added to the list. Click **Reload Configuration** to apply the changes.
6. **To find a file extension:**

   1. Click **Search File Extension** . The **Search File Extension**page appears.

   2. Enter the file extension in **Search File Extension**and click **Search**.

      **Results** : The results of the search will be automatically listed. You can manage the file extension using the **Edit** or **Delete** icon.  
      ![Search File Extension.png](/__attachments/a_2f1911ec0474aaa76513b12996b14aca49a2907760e9aaca305a97e353ac26a5/Search%20File%20Extension.png?cb=b675dd0aeebe24609e8d597fb5f3b8ae)

      *Search File Extension*

### **Download Logs**

The HaloENGINE logs and Tomcat logs can be downloaded via the admin portal using the following procedure:

1. On the left navigation bar, click **System Configuration** , and then on the **Download HaloENGINE/Tomcat Logs** tab, click **Configure**.

2. The *Download HaloENGINE/Tomcat Logs*page appears as shown in the figure below:

   ![HaloENGINE and Tomcat logs.png](https://help.secude.com/__attachments/a_b85fe9473fe1aaf0ea87e1f893886dc82274fb5e53a594959b56bbbe1a16264f/HaloENGINE%20and%20Tomcat%20logs.png?cb=83af3085ba059fb431924c301a3f3b99)

   *HaloENGINE and Tomcat logs*
3. To download the HaloENGINE logs:

   1. Enter the number of days and then click **Download HaloENGINE** **Logs**.

   2. **Results** : A zip file (`HaloENGINE-Log`) will be downloaded to the default download location.

4. To download the Tomcat logs:

   1. Enter the number of days and then click **Download Tomcat Logs**.

   2. **Results** : A zip file (`tomcat-Log`) will be downloaded to the default download location.

5. Please note that you can only enter the value within the range that is defined on the *HaloENGINE Configuration* page for HaloENGINE log retention and Tomcat log retention.

### HaloENGINE Admin Activities Log

Halochain scrutinizes the log file `HaloENGINE_Admin_Activities.log` for any modifications and shows the results.

1. On the left navigation bar, click **System Configuration** , and then on the **HaloENGINE Admin Activities Log** tab, click **Validate**.

2. The *HaloENGINE Admin Activities Log*page appears as shown in the figure below:

   ![Admin Activities log.png](https://help.secude.com/__attachments/a_50a7760a7b15d4f49eef3b092648b8910cf9fb64a5a28588414c9c541e687e7a/Admin%20Activities%20log.png?cb=4204899188572db3db10a83c6d9f9a9e)

   *Admin Activities log*
3. Click **Validate Logs**.

   **Results**:
   1. You will receive the message "*The log file has been validated and no manipulated entries found*.", if no manipulation is identified.

   2. If manipulation is detected, you will obtain the following output:

      ![Halochain output.png](/__attachments/a_3363894de4a460d42af6ce1c119adb1c4abfaaf85856b2664167c208630984d5/Halochain%20output.png?cb=e70bd52b61c6367b701df3c3e08568a1)

      *Halochain output*

### Monitor Log Validation

Halochain is a powerful feature that scrutinizes audit log files such as `HaloENGINE_Monitor.log` and `HaloENGINE_Admin_Activities.log` for any manipulation.

**Prerequisites:**

1. Make sure that you have enabled Halochain in Monitor Properties. Please refer to the section "[Monitor Properties](https://help.secude.com/haloengine/6.10/phase-8-configure-haloengine-features.md#Halochain)".

2. It is recommended to enable the Halochain feature during the initial configuration of the HaloENGINE. This is because Halochain is designed to work with a fresh `HaloENGINE_Monitor.log` file. In case you enable it at a later stage, you need to back up the `HaloENGINE_Monitor.log` file and then delete or empty the log file to start the validation.

Follow the procedure below to validate the audit log file:

1. On the left navigation bar, click **Customer Configuration**, and then select the customer ID (halo_customer) from the list.

2. On the **Monitor Log Validation** tab, click **Configure**.

3. The *Monitor Local Log* *Validation*page appears as shown below:

   ![Monitor log validation.png](https://help.secude.com/__attachments/a_86850ecdcdc9467151cc4268b05cf937c992f262d751276cde3e371ee3625ade/Monitor%20log%20validation.png?cb=37f0049438bad7ccf4277f223400ea1c)

   *Monitor log validation*
4. Click **Validate Logs**.

   **Results**:
   1. If no manipulation is detected, you will see the message: *The log file has been validated and no manipulated entries found*.

   2. The following output appears if manipulation is detected.

      ![Portal Halochain output.png](/__attachments/a_8524f3530a28fe448cf49ed57a08c68b1d1bc8879d2b622dc281f7fe53519ae3/Portal%20Halochain%20output.png?cb=29b6e6ed3697d21d981d1e7cc5d79a22)

      *Halochain output*

### Log Out

Logging out means terminating the current user's access to the portal. When the **Log Out** button is pressed, the portal is notified that the current user intends to terminate the login session.

A logged-in user's login session expires after 20 minutes. The user will no longer be able to use the portal after this period has passed. The user will be automatically logged out and redirected back to the login screen.

### Change Password

You can change your password for security concerns by following the steps below:

1. Click **Change Password**in the top right corner.

   ![Change login password#1.png](https://help.secude.com/__attachments/a_91cc31a88ac0ebf0239048dd42df45df2b2796aa13e9b0a1b94cdfa4204e6843/Change%20login%20password%231.png?cb=e7b95a457519c7da78c3052ea9f0e70e)

   *Change login password #1*
2. The *Change Admin Password* dialog appears as shown in the figure below:

   ![Change login password#2.png](https://help.secude.com/__attachments/a_b3165a278ba0fbc8cfe1caf07f407520d4bfd72cc804891ddf089a96395ff913/Change%20login%20password%232.png?cb=0df719591e21680d29c3bfba0b522a40)

   *Change login password #2*
3. Enter the current password.

4. Enter your new password and re-enter again.

5. Click **Save**.

### Reset Administrator Password

Use the following procedure to reset, update, or change your administrator password.

1. Copy `haloengine-password-config-<version>.zip` file to the desktop and extract it.

2. Open Command Prompt with administrator rights and change directory to `haloengine-password-config-<version>\bin`.

3. Type `haloengine-password-config.bat -h` to display the help information.

   For example:

   `haloengine-password-config.bat -confPath <Full path of HaloENGINE config directory> -newPwd <new password for the login>`

   `haloengine-password-config.bat -confPath "C:\Program Files\Secude\HaloENGINE\config" -newPwd TestHalo!2345`

**When to reset and change the password?**

HaloENGINE Admin portal provides the option of either changing or resetting your password. You can change the password when you know the current password. If you have forgotten the current password, you could reset (create a new) password using the tool.

---
version: "6.10"
language: "en"
---
# System Requirements

This section describes the minimum and recommended system requirements for installing and running the application. It specifies the software dependencies, operating systems, and network prerequisites. Ensuring that the target environment meets these requirements is essential for a successful deployment, optimal performance, and reliable operation of the system.  

|  **Components**  |                                                                                    **Details**                                                                                    |
|------------------|-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| Operating System | Supported only on Microsoft Windows Server 2022 or later with the latest system updates installed.                                                                                |
| Applications     | 1. MongoDB Compass 7.0.7 2. Requires **.NET** Framework 4.6.2 and above. 3. The HaloENGINE Admin portal supports the most recent versions of Microsoft Edge, Chrome, and Firefox. |

*Requirements*

---
version: "6.10"
language: "en"
---
# Troubleshooting

This page will help you through the most common problems that may arise during the installation and configuration of the HaloENGINE, which are described below.

As the first step in troubleshooting, make sure that your HaloENGINE version is up to date. Each release of HaloENGINE adds new features and fixes many problems. Installing the latest version may clear any problems without the need for further troubleshooting.

## Forgot your Admin Portal Password

**Symptoms**

Login fails with the error message "*Invalid credentials*".

**Background**

Entered the wrong password to access the HaloENGINE Admin Portal.

**Probable Cause**

No matter how careful you are, there may be times when you are unable to access the admin portal because you can't remember your password.

**Recommended Action**

1. Run Command Prompt as an administrator.

2. Type `haloengine-password-config.bat -h` to reset the password.

3. Log in with the new password.

### Cannot Log in to Microsoft after Configuring the Tenant

**Symptoms**

The user login fails with the following error message.  
![Microsoft Sign-in error message.png](https://help.secude.com/__attachments/a_0053d6f9b1fce351583cd66419123e3486e6cb5433ce6a06fd82da3b61485cce/Microsoft%20Sign-in%20error%20message.png?cb=a10f20cddb321f4db1cc53da787f266a)

*Microsoft Sign-in error message*

**Background**

The above error occurs when a user logs in to a HaloENGINE Admin Portal using Microsoft Sign-In.

**Probable Cause**

The Tenant ID/Client ID you entered on the *User Domain-Tenant Configuration* page is either incomplete or incorrect.

**Recommended Action**

1. Check that the Tenant ID/Client ID given on the *User Domain-Tenant Configuration* page is correct.

2. Log in to the admin portal.

### Unable to Load the Admin Portal

**Symptoms**  
![Site can't be reached.png](https://help.secude.com/__attachments/a_3c04b19df5bd4a382dd008307bc21bfa11817c397920d26d005862f2eeaf1b32/Site%20can't%20be%20reached.png?cb=f9a56fe10021cdf646de3a73c0a15430)

*Error message*

The above error message appears in the browser when attempting to open the HaloENGINE Admin Portal using the HTTPS protocol.

**Background**

The above-mentioned message appears when the user deletes the server and client certificates.

**Probable Cause**

Removing the server certificate permanently removes all other certificates (including client and CA certificates) and causes the admin portal to operate via the HTTP protocol only. This is expected behavior.

**Recommended Action**

1. Manually change the protocol from HTTPS to HTTP and the port to 8383.

2. Clear your web browser's HTTP Strict Transport Security (HSTS) settings. Please see this link for additional details: [How to clear HSTS settings in Chrome and Firefox.](https://www.thesslstore.com/blog/clear-hsts-settings-chrome-firefox/)

### **Unable to load the Admin Portal or PDM Client could not connect to HaloENGINE**

**Symptoms**

1. [Error message](https://help.secude.com/haloengine/6.10/troubleshooting.md#error1) occurs in the browser when opening the HaloENGINE Admin Portal.

2. HaloCAD for SOLIDWORKS PDM client cannot connect to HaloENGINE.

**Background**

The error mentioned above occurs when the admin portal is attempted to open via `https://[server_IP]:8746/haloengine-admin/` but does not open. When a client tries to connect to the portal, it is unable to connect.

**Probable Cause**

The HaloENGINE's IP address was modified after it was initially configured. It indicates that HaloENGINE attempts to run with the old IP address.

**Recommended Action**

**Action 1:**Use a static IP address

It is not recommended to frequently change the IP address of systems in a large network. Changing HaloENGINE's IP address affects communication with the PDM Client.

**Action 2:** Update the IP address in`hc-servlet.xml`

**Proactive action:**Make sure that the FQDN is used to generate the HaloENGINE server certificate instead of the system IP address.

In some circumstances, a strategic change in IP addresses is required due to network restructuring, security incidents, or significant infrastructure upgrades. In this circumstance, follow the steps below:

1. Locate the XML file in `C:/Program Files/Secude/Tomcat/webapps/haloengine-server/WEB-INF/hc-servlet.xml`.

2. Open the XML file and update the `publishedEndpointUrl` with the new IP address.

       	<jaxws:endpoint id="HaloEngineProcessInterface"
               implementor="com.secude.haloengine.server.impl.HaloEngineProcessPortImpl"
               wsdlLocation="WEB-INF/haloengine-server-process.wsdl" address="/process"
               publishedEndpointUrl = "https://19.41.14.188:8746/haloengine-server/process" />
               
           <jaxws:endpoint id="HaloEngineMonitorEndpoint"
               implementor="com.secude.haloengine.server.interfaces.audit.HaloEngineServerMonitorPortImpl"
               wsdlLocation="WEB-INF/haloengine-server-monitor.wsdl" address="/monitor"
               publishedEndpointUrl = "https://19.41.14.188:8746/haloengine-server/monitor" />   
               
           <jaxws:endpoint id="HaloEngineStatefulEndpoint"
               implementor="com.secude.haloengine.server.interfaces.stateful.HaloEngineStatefulPortImpl"
               wsdlLocation="WEB-INF/haloengine-stateful-process.wsdl" address="/stateful_process"
               publishedEndpointUrl = "https://19.41.14.188:8746/haloengine-server/stateful_process" />

3. Save the document.

4. Restart the Tomcat service.

5. Launch the admin portal via `https://[new_server_IP]:8746/haloengine-admin/`

6. HaloENGINE now runs on the new IP address, and other clients can communicate with it.

### **Unable to Access Admin Portal on Localhost**

**Symptoms**

The following error message (`NET::ERR_CERT_COMMON_NAME_INVALID`) appears in the browser when attempting to load the HaloENGINE Admin Portal.  
![Privacy error.png](https://help.secude.com/__attachments/a_1b79ac5a33233817057f39dfa5de98d799813e016cd5bce90e3eabc73940cc8f/Privacy%20error.png?cb=669a6325974c55e0bbc5d6b41b39bc2a)

*Privacy error message*

**Background**

The above-mentioned issue occurs when the admin portal is attempted to open on localhost - `https://localhost:8746/haloengine-admin/`.

**Probable Cause**

After restarting the Tomcat service, the admin portal runs on localhost via HTTPS, and the browser displays an error message `NET::ERR_CERT_COMMON_NAME_INVALID`. This indicates that the certificate's common name does not match.

**Recommended Action**

1. Open a new browser.

2. Enter the HaloENGINE server's FQDN manually in the browser instead of using localhost. For example: `https://SVIN0225:8746/haloengine-admin/`.

### Unable to Access the Admin Portal with FQDN

**Symptoms**

HaloENGINE Admin Portal cannot launch properly.

**Background**

When attempting to access the admin portal via `https://FQDN:8746/haloengine-admin/`, it does not open.

**Probable Cause**

The IP address of the HaloENGINE-installed server machine can change after the initial configuration.

**Recommended Action**

By default, the HaloENGINE server's Fully Qualified Domain Name (FQDN) is automatically configured in the `hc-servlet.xml` file, preventing dynamic IP issues. However, if you are still unable to access the admin portal, please add an entry to your hosts file that links your dynamic IP address to the appropriate FQDN. Furthermore, whenever your IP address changes, you must update the hosts file with the new address and the associated FQDN.

For example: "`<current_ip_address> <FQDN>`".

### **Protection Fails**

**Symptoms**

Protection does not happen, or protection fails.

**Background**

When a user downloads a file, no protection is applied to the chosen file.

* For office files, the label is applied, and the file opens unprotected.

* For non-native files, no label is applied, and an error appears.

**Probable Cause**

This problem happens when one or more of the following conditions are met:

1. **Case 1**: If the Classification Engine is turned off.

2. **Case 2**: If no Action/Classification rules are configured under Download Rules.

3. **Case 3:**If the HaloENGINE Tomcat Service stops unexpectedly.

4. **Case 4**: If the certificate used by the HaloENGINE has expired.

5. **Case 5:** If the System Unique ID on the Admin Portal does not match the System ID on the client system.

**Recommended Action**

1. **Case 1** : Check that the **Classification Engine** is turned on.

2. **Case 2**: Make sure to include an appropriate classification rule, followed by a suitable action rule.

3. **Case 3**: Check that the HaloENGINE is running; if not, restart it manually.

4. **Case 4**: Make sure to upload the same valid certificate that is already installed on the Windows Server machine where the HaloENGINE is installed.

5. **Case 5:** Check that the name entered in the admin portal's **System Unique ID** field matches the name entered in the **System ID** (in configuration properties). Also, make sure the names are case-sensitive. Make sure that the client system name matches the name entered in the admin portal's **System Unique ID** field. Also, make sure the names are case-sensitive. For example, if your client system name is 'MYDESKTOP', but you enter 'mydesktop' in the **System Unique ID** field, you will receive an error due to case sensitivity.

6. Re-try downloading now.

### Dashboard Fails to Load

**Symptoms**

The dashboard window displays the error message "*Failed to get data*".

**Background**

HaloENGINE is installed in a custom location with an inbuilt MongoDB option during installation. After initializing the HaloENGINE admin portal, the Monitor log dashboard fails to load.

**Probable Cause**

HaloENGINE is installed in the Desktop location path.

**Recommended Action**

As a best practice, it is not recommended to install it on the HaloENGINE desktop location. However, if you install it on a desktop location, you will encounter this type of error. To resolve it, you need to grant sufficient permission to the Network Service.

---
version: "2.4"
language: "en"
---
# HaloCAD Add-on for Autodesk Revit

## HaloCAD Add-on for Autodesk Revit

This page provides a complete collection of HaloCAD Add-on for Autodesk Revit documentation.

### Documentation

*

  #### [Technical Reference Manual](https://help.secude.com/halocad-add-on-for-autodesk-revit/2.4/technical-reference-manual.md)

#### [Installation Manual](https://help.secude.com/halocad-add-on-for-autodesk-revit/2.4/rv-installation-manual.md)

*

  #### [Operations Manual](https://help.secude.com/halocad-add-on-for-autodesk-revit/2.4/rv-operations-manual.md)

*

  #### [Release Notes](https://help.secude.com/halocad-add-on-for-autodesk-revit/2.4/rv-release-notes.md)

---
version: "2.4"
language: "en"
---
# Appendix

This section provides supplemental information.  
**Installer Version Requirement**

When uninstalling the HaloCAD add-on, use the installer for the currently installed version, whether you run it by double-clicking the installer or from the command line. Using a different installer version may result in errors.

## Uninstalling the HaloCAD Add-on for Revit

When you no longer use the add-on, you may uninstall the application. Uninstalling removes all files and registry settings that were added to your computer during the initial installation.

**Method #1**

1. Click **Start** menu \> go to **Control Panel** \> **Programs** \>**Programs and Features** \> **Uninstall a Program** \>select**HaloCAD Add-on for Revit** application from the list \> right-click and select **Uninstall** option or double-click on the installer `HaloCAD_Revit_Setup.exe` file.

2. Depending on your Windows security settings, you may get a security warning as "*Do you want to allow the following program to make changes to this computer* ?". If you get this security warning, click the **Yes** button to confirm that you want to uninstall the add-on.

3. The HaloCAD installer checks the current user session for any supported CAD applications running in the background and, if any are detected, displays the following message prompting you to close them before continuing with the uninstallation.

   ![Uninstall message #1.png](https://help.secude.com/__attachments/a_6c0db3d7d91a3a4c8bc5653b3a906644af40024a2973dbe02d16156cdb1d9289/Uninstall%20message%20%231.png?cb=0d11eb86820c594eab46542db513388a)

   *Uninstall message #1*
4. Click **OK** and close all HaloCAD-supported CAD applications.

5. Redo [step 1](https://help.secude.com/halocad-add-on-for-autodesk-revit/2.4/rv-appendix.md#Step1), and the following confirmation message appears.

   ![Uninstall Message #2.png](https://help.secude.com/__attachments/a_1d90e7a065a9eb56975b5293660480a5f7b8837f797ca22094a584cbc666edd2/Uninstall%20Message%20%232.png?cb=01f9c93f6587010b0f0f41c162ce1176)

   *Uninstall Message #2*
6. Click **Yes** to confirm the uninstallation of HaloCAD from your computer.

7. When prompted with the following message, click **Yes** to delete the identity of the currently logged-in user from the ongoing session(`%AppData%\Roaming\Secude\HaloCAD\revit)`, or **No**to proceed with the uninstallation without removing the identity. This prompt does not appear if no HaloCAD session has been initiated.

   ![Uninstall message #3.png](https://help.secude.com/__attachments/a_68958cd39e7f50afbf4b3a86cd7f966fec9e4e8177b25a0172fdf8d62f1a812e/Uninstall%20message%20%233.png?cb=d25d6758d286a79a0f7d61c6f8c32beb)

   *Uninstall message #3*
8. The HaloCAD add-on has been uninstalled successfully. Click **OK**to close the dialog box.

   ![Uninstall message #4.png](https://help.secude.com/__attachments/a_278ded481c1e689e09299fa583bea9a33e4f4f051245d8b42a66de069225a4a9/Uninstall%20message%20%234.png?cb=b0d919572248e680bf8a65786ad3d2f6)

   *Uninstall message #4*

**Method #2**

The add-on can be removed using the command line, as illustrated in the sample below.

1. Open a command prompt.

2. Navigate to the add-on installer's directory.

   1. **Option 1** : Uninstall without deleting the identity of the currently logged-in user: `HaloCAD_Revit_Setup.exe -uninstall`

   2. **Option 2** :Uninstall deleting the identity of the currently logged-in user: `HaloCAD_Revit_Setup.exe -uninstall -clearcache <yes>`

3. The uninstalling process is complete.

## Uninstalling the HaloCAD Reader Add-on for Revit

Uninstalling reader add-on is also similar to that of the full version.

**Method #1**

1. Click **Start** menu \> go to **Control Panel** \> **Programs** \>**Programs and Features** \> **Uninstall a Program** \>select**HaloCAD Reader Add-on for Revit** application from the list \> right-click and select **Uninstall** option or double-click on the installer `HaloCAD_Reader_Revit_Setup.exe` file.

2. The uninstallation process for the Reader version is similar to that of the Full version; refer to the above section and follow the on-screen instructions to complete the process.

**Method #2**

The add-on can be removed using the command line, as illustrated in the sample below.

1. Open a command prompt.

2. Navigate to the add-on installer's directory.

   1. **Option 1** : Uninstall without deleting the identity of the currently logged-in user:`HaloCAD_Reader_Revit_Setup.exe -uninstall`

   2. **Option 2** :Uninstall deleting the identity of the currently logged-in user: `HaloCAD_Reader_Revit_Setup.exe -uninstall -clearcache <yes>`

3. The uninstalling process is complete.

---
version: "2.4"
language: "en"
---
# Installation Manual

## About this Manual

This manual walks you through the process of installing and configuring the following HaloCAD add-ons:

1. HaloCAD Add-on for Revit

2. HaloCAD Reader Add-on for Revit

**Reference**

All technical manuals are included with the product package you have purchased.

Administrators should first read the Technical Reference Manual to understand the add-on's architecture, learn about the prerequisites, and activate a license key. They should also refer to the Release Notes to learn about the supported CAD applications before following the instructions in this document.

---
version: "2.4"
language: "en"
---
# Installing the HaloCAD Add-on for Revit

This chapter describes how to install and configure the HaloCAD Add-on for Revit. This manual just briefly explains steps 1-3, which cover the prerequisites, obtaining the licensing key, and creating an encrypted JSON file; for more information, please refer to the Technical Reference Manual.

## Step 1: Fulfill the Prerequisites

1. Refer to the Release Notes to learn about supported operating systems, file types, and CAD applications.

2. Before installing the add-on, make sure all prerequisites are fulfilled.

Please refer to the section "[Prerequisites](https://help.secude.com/halocad-add-on-for-autodesk-revit/2.4/technical-reference-manual.md#pre)".

## Step 2: Obtain the License Key

Obtain the license key and choose whether to activate it automatically or manually.

Please refer to the section "[License Administration](https://help.secude.com/halocad-add-on-for-autodesk-revit/2.4/technical-reference-manual.md#lic)".

## Step 3: Create an Encrypted JSON File

To ensure a secure installation, create an encrypted JSON file using this admin tool and share it without exposing the original tenant details. When the encrypted JSON file is ready, place it with the HaloCAD installer. By reading data from the `hc.conf.enc` file, the installer activates the license and bypasses the "[Initialization](https://help.secude.com/halocad-add-on-for-autodesk-revit/2.4/rv-installing-the-halocad-add-on-for-revit.md#Initialization)" screen, which would otherwise ask for Microsoft Entra ID application details.

Please refer to the section "[Secure Installation (Recommended)](https://help.secude.com/halocad-add-on-for-autodesk-revit/2.4/technical-reference-manual.md#secure)".

## Step 4: Install the Add-on

You can install the add-on in the following modes:

1. **Graphical Mode**

   Graphical mode installation is an interactive, graphical user interface-based method that is driven by a wizard.

2. **Silent Mode**

   Silent-mode installation is a non-interactive method of installing the add-on using command lines.

3. **Via System Center Configuration Manager**

   With System Center Configuration Manager (SCCM), the add-on is deployed on the targeted computers across your enterprise.

### **Graphical Mode**

**Before you begin**

The following prerequisites must be met:

1. A user who installs the HaloCAD Add-on must have administrator rights.

2. Ensure that all active and open CAD applications are closed. If not, HaloCAD prompts a warning message as "*Please close all the CAD applications to proceed with the installation of HaloCAD Add-on for Revit.*"

3. Ensure that the HaloCAD Reader Add-on for Revit is not installed on the same workstation. If it is already installed, HaloCAD prompts a warning message as "*No supported CAD applications are available in the system. (OR) Remove the Reader version of this product.*"

4. Ensure that your Microsoft Entra tenant details are ready when the installation UI requests them. As an alternative, you can use `hc.conf.enc` for a secure and automated installation.

**Installation Procedure**

Install the add-on using the GUI-based setup program provided in the installation package.

1. Double-click the installer `HaloCAD_Revit_Setup.exe` file.

2. Depending on your Windows security settings, a prompt may appear stating, *"Do you want to allow the following program to make changes to this computer?"* If this warning appears, click **Yes** to continue with the installation.

3. When the installer starts, the **Startup** dialog appears, followed by the **Welcome** dialog.

   ![Startup dialog.png](https://help.secude.com/__attachments/a_9dbc91edc0c382cfd65835a85e1b1d62d795e350f9ca36d80f900b324cbf9057/Startup%20dialog.png?cb=d9e07e20e8b57ec9785bd1d4c09a3806)

   *Startup dialog*  
   ![1 Welcome dialog.png](https://help.secude.com/__attachments/a_e181dbc67514eb760836ff2d850f4ec7c61fc781bce3e93cde452c9409b3e40b/1%20Welcome%20dialog.png?cb=cbe52c16ade3725f1f1c80e458767b99)

   *Welcome dialog*
4. Click **Next** to continue the installation. The installer UI includes a link to the product's online documentation. When you click **Online Help**, the installation help page opens in your browser.

5. The **End-User License Agreement (EULA)** dialog appears.

   ![2 End-User License Agreement dialog.png](https://help.secude.com/__attachments/a_255351a94053267b194a88abb2abefeecfd599f8bb6e7f2d8b5a3ea8b6289dce/2%20End-User%20License%20Agreement%20dialog.png?cb=39a040fb17e7c99b5aa4c5bcbc0907d3)

   *End-User License Agreement dialog*
6. Read the End-User License Agreement. If you agree to the terms, select **I accept the terms in the License Agreement** and click **Next** to continue.

7. The CAD application version selection dialog appears.

   ![3 CAD Application Selection dialog.png](https://help.secude.com/__attachments/a_1bee55569493d5d6d841724fa7f0a8645c4940648b9934c266d6914c2aeae406/3%20CAD%20Application%20Selection%20dialog.png?cb=db6aa0da02492c632dc7f6a08db09562)

   *CAD application version selection dialog*
8. Select the installed **Revit** application version in your system and click Next. To review or modify installation settings (if needed), click **Back**to return to the previous screens.

9. The installation begins, and the progress is displayed in the dialog.

   ![4 Installing dialog.png](https://help.secude.com/__attachments/a_22a32d499ed9800df40c1fc8828dd2430f5ed528bce10e0bb7831284b599447a/4%20Installing%20dialog.png?cb=9f50728faf87be02258a8e085abe4d73)

   *Installation progress dialog*
10. When the installation is complete, a message appears confirming that the add-on has been successfully installed.

    ![5 Installation completed successfully dialog.png](/__attachments/a_8ffd6957e67a31181d17b20a0346d724cedee1b96a658bb070695f582629dc8d/5%20Installation%20completed%20successfully%20dialog.png?cb=240c30b320322cea750d525e0b5e8107)

    *Installation completed dialog*
11. Click **Next** to proceed.

12. The initialization dialog appears. To prevent connectivity issues, ensure that the correct Microsoft Entra ID application details are entered on the screen. Note**:** If the `hc.conf.enc` file is included with the installer, this initialization screen is skipped and only the completion dialog is shown. The initialization screen appears only when the `hc.conf.enc` file is not present in the installer folder.

    ![6 App ID details.png](/__attachments/a_a6048edbb0a1fda400abb14cd75e9346eb4d0e5d59cbce78ebd7af5bacb3c9a3/6%20App%20ID%20details.png?cb=40f716a17d545a61fb53b87abedce2ba)

    *Initialization dialog*
    1. **Application ID** : Enter the unique identifier of your registered application. For example, `v6ca776-c74e-437d-98ef-662ecb5751tt`.

    2. **Redirect URI** : Enter the URI, that was provided when registering the native application in the Azure portal. For example, `https://localhost`.

    3. **Tenant ID:** If the registered application is **Single tenant** , you need to enter the globally unique identifier of your tenant if not, you can leave it empty. For example, `9c1cfc28-1ec6-44ea-bec6-e3492ef0cd16`.

    4. **Cloud Type** : **Commercial** is selected by default. Based on your Azure subscription and configuration, select the required cloud type from the list: Commercial, Custom, Germany, US_DoD, US_GCC, US_GCC_High, US_Sec, US_Nat, or China_01. If you select **Custom** , enter the appropriate URLs in the **Protection Cloud URL** (for example, `https://api.aadrm.com`) and **Policy Cloud URL** (for example, `https://dataservice.protection.outlook.com`) fields.

    5. **Enable Federal Information Processing Standards (FIPS):** Enable this option to use encryption algorithms that comply with FIPS standards. When enabled, MPIP uses only FIPS-compliant encryption algorithms, and when disabled, it uses standard encryption algorithms. If this option was not enabled during installation, it can later be enabled through a registry entry. For more details, please refer to the section "[Step 5 Modify Registry Settings](/halocad-add-on-for-autodesk-revit/2.4/rv-installing-the-halocad-add-on-for-revit.md#HRS)".

    6. Click **Next**.

13. Once the initialization is complete, a success message appears as shown below.

    ![7 Completing the HALOCAD setup dialog.png](/__attachments/a_754f579cc9a953e987e3cc76f2b4fa581f432fb025fe181173aa7ff9110537d6/7%20Completing%20the%20HALOCAD%20setup%20dialog.png?cb=0b4945958eda14eda5fd958504f1fef8)

    *Initialization completed dialog*
14. Click **Close** to close the installation wizard.

**Post-installation checks**:

1. To view the add-on, open the **Revit Application** \> **HaloCAD** tab.

2. **Masking Personally Identifiable Information (PII)** :By default, the HaloCAD Add-on masks Personally Identifiable Information (PII) in logs, such as email names, file paths, and IP addresses in the MIP SDK logs. In HaloCAD logs, information such as the label name, label ID, engine ID, policy ID, and watermark text is masked with asterisks. To view PII in clear text, create the following registry entry in Path: `Computer\HKEY_CURRENT_USER\SOFTWARE\Secude\HaloCAD Add-on for Revit`

   **Name** : `mipallowpii`, **Type** : `REG_SZ`, **Value** : `true`

   The log files are located at the following paths:
   * **MIP SDK log** : `%AppData%\Roaming\Secude\HaloCAD\revit\mip\logs\mip_sdk.miplog`

   * **HaloCAD log** : `%AppData%\Roaming\Secude\HaloCAD\revit\halocad.log`

3. If your network infrastructure includes a proxy server that provides access to external websites. Then, to connect to the Secude License Manager URL, you need to manually add the Proxy settings in the add-on. To do so, create a registry entry in the root directory, `Computer\HKEY_LOCAL_MACHINE\SOFTWARE\Secude\HaloCAD Add-on for Revit`

   **Name** : `proxyuri`, **Type** : `REG_SZ`, **Value** : The format is, `<URL>:<PORT>`. For example, `http://10.41.0.130:808`

### **Silent Mode**

Besides graphical mode, the add-on can be installed in silent mode, which does not require user involvement or display a user interface. It is a convenient way to streamline installation using the command at once.

1. Open the Command Prompt with elevated rights (Run as Administrator).

2. Navigate to the add-on installer directory.

3. To know the list of options available in silent mode, follow the steps given below:

   **Type** `HaloCAD_Revit_Setup.exe -help`

   **Press** `Enter`

   **Output**

   ...

   `HaloCAD_Revit_Setup.exe -install -application <Revit 2026| Revit 2025| Revit 2024> -applicationid <azure_application_id> -redirecturi <azure_redirect_url> -tenantid <azure_tenant_id for Single-tenant app|null for Multi-tenant app> [-cloudtype <Commercial|Custom|Germany|US_DoD|US_GCC|US_GCC_High|US_Sec|US_Nat|China> -protectioncloudurl <protection cloud url> -policycloudurl <policy cloud url>] -enablefipsmode <true|false>`

   `[Default Parameters: cloudtype - Commercial and enablefipsmode - false]`

   `HaloCAD_Revit_Setup.exe -uninstall`

   `To delete HaloCAD cache through Silent Mode Uninstallation`

   `HaloCAD_Revit_Setup.exe -uninstall -clearcache <yes>`

   `For Silent Mode Installation if ENC file already exists in the same location`

   `HaloCAD_Revit_Setup.exe -install -application <Revit 2026| Revit 2025| Revit 2024> -enablefipsmode <true|false>`

4. The following command illustrates how to install the add-on using the Azure application details.

   `HaloCAD_Revit_Setup.exe -install -application "Revit 2026" -applicationid v6ca776-c74e-437d-98ef-662ecb5751tt -redirecturi https://localhost -tenantid 9c1cfc28-1ec6-44ea-bec6-e3492ef0cd16 -cloudtype Custom -protectioncloudurl https://api.aadrm.com -policycloudurl https://dataservice.protection.outlook.com -enablefipsmode true`

5. The example below shows how to install the add-on using the `hc.conf.enc` file located in the same installation location.

   `HaloCAD_Revit_Setup.exe -install -application "Revit 2026" -enablefipsmode true`

6. Press `Enter`.

7. The installation is complete.

### **Via System Center Configuration Manager**

Microsoft System Center Configuration Manager (SCCM) is an administrative tool that allows organizations to deploy operating systems and applications to Windows users efficiently and cost-effectively across their environment.

Using SCCM, the HaloCAD add-on can be deployed silently and automatically to specific target computers throughout the enterprise.

**Before You Begin**

1. Ensure that you have reviewed the prerequisites described in the Graphical Mode section.

2. We recommend adhering to best practices when creating a deployment procedure.

3. For guidance on preparing your environment, refer to the official Microsoft online documentation.

**Deployment Using SCCM**

This guide assumes that an SCCM environment is already configured. After configuration, you can use the silent mode commands described in the Silent Mode section to deploy the add-on.

## Step 5: Modify Registry Settings

Prerequisite: To modify the add-on registry entries, first launch the CAD application and sign in to Microsoft Purview Information Protection to ensure that an active HaloCAD session is established.

Note: Only the registry entries listed in the table below should be modified.

The HaloCAD registry entries are grouped into two sections: **HKEY_CURRENT_USER** and **HKEY_LOCAL_MACHINE**. Depending on your requirements, you can modify the following settings:

1. `HKEY_CURRENT_USER\SOFTWARE\Secude\HaloCAD Add-on for Revit`. Once you have logged into the HaloCAD Session, open Registry Editor, navigate to this path, and modify the desired registry key. For example, to change the log level, double-click **loglevel** , change the "Value data" using the values listed in the table below, and then click **OK**.

   1. loginterval

   2. loglevel

   3. logsize

2. `HKEY_LOCAL_MACHINE\SOFTWARE\Secude\HaloCAD Add-on for Revit`: enable_fips (This entry does not require an active HaloCAD session.)

|  **Name**   | **Default Value** | **Type**  |                                                                                                                                                                                                                                                                                          **Description**                                                                                                                                                                                                                                                                                           |
|-------------|-------------------|-----------|----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| loginterval | `30`              | REG_SZ    | It automatically removes log files that are older than the default retention period. By default, log files older than 30 days are deleted.                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| loglevel    | `0X00000003 (3)`  | REG_DWORD | Log level information is logged in the `halocad.log` file. * Error---0. Logs error events that prevent program execution. * Record---1. Records all the details about the behavior of the application. * Warning---2. Logs unexpected exceptions that indicate potential problems. * Information---3. A standard log level that highlights the progress of the application. * Verbose---4. Debug events are logged. * Verbose 1---5. Debug 1 events are logged. * Verbose 2---6. Debug 2 events are logged. * Verbose 3---7. Debug 3 events are value. * Verbose 4---8. Debug 4 events are logged. |
| logsize     | `1024`            | REG_SZ    | The `halocad.log` file is created at the start of a HaloCAD session and is stored in the default parent location directory. To have control over log file size, HaloCAD allows you to configure backup/archive the current log file with a timestamp when it exceeds the default size of `1024 MB,` and creates a new one. Format: `halocad<ddmmyy_hhmmss>.log`                                                                                                                                                                                                                                    |
| enable_fips | `false`           | REG_SZ    | Enable or Disable FIPS Mode 1. true: MPIP uses only FIPS-compliant encryption algorithms. 2. false: MPIP uses standard encryption algorithms.                                                                                                                                                                                                                                                                                                                                                                                                                                                      |

*Configuration in the HaloCAD Registry*

**What to do next**

1. If the encrypted configuration file was placed with the installer:

   1. You can launch the CAD application and start using the HaloCAD features immediately.

   2. The license is activated silently in the background.

   3. For details on protecting CAD files, refer to the Operations Manual.

2. If the encrypted configuration file was not placed with the installer:

   1. You must activate the license manually.

   2. Follow the instructions in the "UI-based Manual License Activation" section of the Technical Reference Manual.

---
version: "2.4"
language: "en"
---
# Installing the HaloCAD Reader Add-on for Revit

This chapter describes how to install and configure the HaloCAD Reader Add-on for Revit.

**Before you begin**

The following prerequisites must be met:

1. A user who installs the HaloCAD Reader Add-on must have administrator rights.

2. Ensure that all active and open CAD applications are closed. If not, HaloCAD prompts a warning message as "*Please close all the CAD applications to proceed with the installation of HaloCAD Reader Add-on for Revit.*"

3. Ensure that the HaloCAD Add-on for Revit (full version) is not installed on the same workstation. If it is already installed, HaloCAD prompts a warning message as "*No supported CAD applications are available in the system. (OR) Remove the full version of this product.*"

4. Ensure your Microsoft Entra tenant information is ready to enter when the setup process prompts you to perform a manual installation. Alternatively, for a safe and automatic installation, use `hc.conf.enc`. In both cases, the tenant information must be the same as that used in the full version installation. However, the licensing key is different for each of the add-ons. Refer to the sections "License Activation" and "Secure Installation" in the Technical Reference Manual for further information on the various methods for activating a license key and automatic initialization.

**Installation Procedure**

Install the application by using the GUI-based setup program that is provided in the installation package.

1. To begin the interactive installation, double-click the installer `HaloCAD_Reader_Revit_Setup.exe` file. For the installation procedure, follow the installation wizard or refer to the full version.

2. The reader add-on can be installed and configured in the same manner as the full add-on. The command line to execute the silent installation is `HaloCAD_Reader_Revit_Setup.exe -help` and follow the commands.

3. **Post-installation checks:**

   1. To view the add-on, open the **Revit Application** \> **HaloCAD** tab.

   2. Similar to the full version, the Reader add-on also masks personally identifiable information (PII) in logs. To view PII in clear text, create the following registry entry in Path: `Computer\HKEY_CURRENT_USER\SOFTWARE\Secude\HaloCAD Reader Add-on for Revit`

      **Name** : `mipallowpii`, **Type** : `REG_SZ`, **Value** : `true`

      The log files are located at the following paths:
      * **MIP SDK log** : `%AppData%\Roaming\Secude\HaloCAD\revit\mip\logs\mip_sdk.miplog`

      * **HaloCAD log** : `%AppData%\Roaming\Secude\HaloCAD\revit\halocad.log`

      * For more details, please refer to the section "[Step 5: Modify Registry Settings](/halocad-add-on-for-autodesk-revit/2.4/rv-installing-the-halocad-add-on-for-revit.md#HRS)".

   3. If your network infrastructure includes a proxy server that provides access to external websites. Then, to connect to the Secude License Manager URL, you need to manually add the Proxy settings in the add-on. To do so, create a registry entry in the root directory, `Computer\HKEY_LOCAL_MACHINE\SOFTWARE\Secude\HaloCAD Reader Add-on for Revit`

      **Name** : `proxyuri`, **Type** : `REG_SZ`, **Value** : The format is, `<URL>:<PORT>`. For example, `http://10.41.0.130:808`

**What to do next**

1. If the encrypted configuration file was placed with the installer:

   1. You can launch the CAD application and begin using the reader add-on right away to view the protected file.

   2. The license is activated silently in the background.

   3. For details, refer to the Operations Manual.

2. If the encrypted configuration file was not placed with the installer:

   1. You must activate the license manually.

   2. Follow the instructions in the "UI-based Manual License Activation" section of the Technical Reference Manual.

---
version: "2.4"
language: "en"
---
# Operations Manual

## About this Manual

This manual provides comprehensive guidelines and step-by-step instructions for working with **HaloCAD solutions (Label** and **Protect)** . For information on deployment and configuration, refer to the **Installation Manual** included in the product package.

## General FAQs

This section answers the most frequently asked questions (FAQs). For additional inquiries, please contact your sales representative or the support team.

1. **What does HaloCAD provide for an organization?**

   HaloCAD solution protects engineering CAD files and enforces security across their entire lifecycle.

2. **How many variants does HaloCAD have?**

   HaloCAD is available in three variants:

   1. HaloCAD Add-on for CAD applications -- a standalone add-on

   2. HaloCAD for PLM

   3. HaloCAD Reader Add-on for CAD applications

3. **What is the difference between the HaloCAD Add-on for CAD and the HaloCAD for PLM?**

   HaloCAD Add-on for CAD is a standalone solution for organizations that do not store CAD files in PLM. It enforces protection through user engagement.

   HaloCAD for PLM integrates with the respective PLM application and includes the capabilities of HaloCAD PROTECT and HaloCAD MONITOR. The MPIP label is applied automatically, based on the rules defined in the Classification Engine, without requiring user intervention.
4. **What distinguishes the HaloCAD Reader add-on from the HaloCAD Standalone (full add-on)?**

   HaloCAD Standalone Add-on (Full Version) protects CAD files using Microsoft Purview Information Protection solution. This version is licensed.

   HaloCAD Reader Add-on allows viewing of files protected by the HaloCAD Standalone Add-on. This version is free of charge.
5. **What languages are supported by the HaloCAD add-on?**

   Currently, the HaloCAD add-on only supports English.

6. **Does the HaloCAD Add-on support all native CAD file types?**

   Yes, the HaloCAD Add-on supports all CAD native file types.

7. **What happens if an unauthorized person tries to open a HaloCAD-protected CAD file?**

   The process begins with user authentication, which verifies the user's identity. If authentication fails, an error message is displayed, and access is denied.

8. **Who decides what labels should be used for various CAD drawings and how they are managed in the background?**

   An administrator manages labels (user rights) in the Microsoft Purview portal, while engineers can create profiles, classification schemas, and action rules based on the sensitivity of their data.

9. **What if I don't want a certain file to be protected?**

   If you do not want the file to be protected, you can apply the **"No Protection"** label, which does not include any policy settings.

10. **Can I create my own labels?**

    Yes, HaloCAD allows users to create custom permission labels.

## How does it work?

This chapter provides a high-level explanation of the underlying processes and interactions between the system components to help you understand how HaloCAD protects sensitive data.

### License Enforcement

After installation, HaloCAD programmatically sends a license validation request to Secude's License Manager when a user attempts to start a session for the first time by opening the CAD application. Based on the administrator's installation method, one of the following scenarios applies:

**Case 1:**

If the license is activated automatically during the installation process, the user can continue using all HaloCAD features without interruption.

**Case 2:**

If the license has not been activated, the user will receive an error message and will be unable to access HaloCAD features. For information on license activation, refer to the **License Activation** section of the Technical Reference Manual.

### Applying Protection using HaloCAD Add-on

At a high level, HaloCAD workflow involves the following steps:  
![Common_Full_How does it work.png](https://help.secude.com/__attachments/a_9120768d12087bfda541bb703a8f4b86dada6a890da3226db19fdc35bc8be2aa/Common_Full_How%20does%20it%20work.png?cb=50711313c7ce5ba3f2660fd6bb68bbeb)

*HaloCAD protection*

1. To create new CAD files, the user launches the CAD application and logs into the HaloCAD session for the first time.

2. HaloCAD connects to the Microsoft Entra tenant. In this manual, `halosecude.onmicrosoft.com` is used as an example tenant.

   1. Microsoft Entra ID prompts the user for authentication.

   2. After successful authentication, Microsoft Purview Information Protection (MPIP) labels are downloaded for the logged-in user (`john@halosecude.onmicrosoft.com`).

3. File protection: The user (John) selects and applies two different labels to two separate files.

4. HaloCAD enforces document protection based on the selected label. When a sensitivity label is applied, it is stored in the document metadata, and the corresponding protection settings are enforced to secure the content.

5. **File-Sharing** : Assume that `john@halosecude.onmicrosoft.com` shares the files with multiple users. **Users A** ,**B** ,and **C** receive **File 1** , while **User D** receives **File 2**.

6. Content consumption: Users A, B, C, and D attempt to access the protected files. Microsoft Entra ID authenticates each user, and the file opens upon successful authentication. Access permissions such as **View, Edit, Print, Copy, Export,** and **Change** are granted based on the applied label. Different permission levels may be assigned to individual users or user groups.

   Note: The user who initializes HaloCAD is considered the author and is granted full access rights to the document. For more information on labels, refer to the Microsoft documentation.

   1. File 1 - Full access is granted to `User A@halosecude.onmicrosoft.com`.

   2. File 1 - Read-only (view-only) access is granted to `User B@halosecude.onmicrosoft.com`.

   3. File 1 - `User C@halosecude.onmicrosoft.com` is denied access and cannot open the file.

   4. File 2 - Access was previously granted to `User D@halosecude.onmicrosoft.com` but has been revoked due to risky or suspicious activity.

**Logged-in user (HaloCAD session)**

In this document, the term "logged-in user" refers to the individual or user account that launches the CAD application and signs in to Microsoft Entra ID through the Microsoft Sign-In application. This may differ from the operating system user currently signed in. Collectively, this is referred to as the "HaloCAD session."

### Viewing a Protected File Via the HaloCAD Reader Add-on

At a high level, HaloCAD workflow involves the following steps:  
![Common_Reader How does it work.png](https://help.secude.com/__attachments/a_a96d80489ed0c0f1002b90454de724afc9f1bfb8ee1673daff551842e651e858/Common_Reader%20How%20does%20it%20work.png?cb=dd0cedef1a51cb05fe460946f52fff25)

*HaloCAD Reader Add-on*

1. The user selects two files that are protected by HaloCAD.

2. When the user logs in to the HaloCAD session for the first time, a connection to Microsoft Purview Information Protection is required. Microsoft Entra ID authenticates the user.

3. HaloCAD indicates that the files can be opened only in read-only mode. In this scenario, the user is authorized to open File 1.

4. File 2 does not open because the user does not have the required permissions.

By design, saving is restricted once a protected file is opened in a session to prevent protected content from being copied to an unprotected file. HaloCAD shows a restriction message. In a fresh session, unprotected files can be created and saved without any restrictions.

## Get Started with HaloCAD

This section describes how to protect a file, open a protected file, and use the HaloCAD Reader add-on.

### Permission Levels and Usage Rights

#### **Basic Permissions**

The following table lists the basic permissions and the usage rights that they contain:  

| **S.No** |    **Permission Level**     |                                                       **Usage Rights (Allowed Recipient Actions)**                                                        |
|----------|-----------------------------|-----------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1        | View                        | Open and read the data (also known as "Read-only"). It includes Zoom and view from different angles (for CAD file types).                                 |
| 2        | Edit                        | Edit the file and save it                                                                                                                                 |
| 3        | Copy                        | Extract data (including screen captures) from the file into the same or another file.                                                                     |
| 4        | Print                       | Print the content                                                                                                                                         |
| 5        | Export                      | Save the content to a different filename (Save As). Also includes "Export to PDF".                                                                        |
| 6        | Change Rights               | Changing the label that is applied to a file includes removing protection and saving it as an unprotected file.                                           |
| 7        | Owner (Full Control rights) | Grants all rights to the file and all available actions can be performed. Also includes the following permissions: 1. Remove protection 2. Relabel a file |

*Basic Permissions*  
**Author (creator) of a file**

The author of a file has all the rights and actions mentioned in the above table. Also includes the following permissions:

1. Open file after the expiry date

2. Revoke access

#### **Custom Permissions**

The following table lists the custom permissions and the usage rights that they contain:  

| **S.No** | **Permission Level** |                                              **Usage Rights (Allowed Recipient Actions)**                                              |
|----------|----------------------|----------------------------------------------------------------------------------------------------------------------------------------|
| 1        | Viewer               | Open and read the data (also known as "Read-only"). It includes Zoom and view from different angles.                                   |
| 2        | Reviewer             | Viewer's allowed permissions plus: 1. Edit 2. Save the file                                                                            |
| 3        | Co-Author            | Reviewer's allowed permissions plus: 1. Print 2. Extract data (including screen captures) from the file into the same or another file. |
| 4        | Co-Owner             | Co-Author's allowed permissions plus: 1. Export 2. Change Rights                                                                       |
| 5        | Only for me          | Grants all rights to the file and all available actions can be performed only by the author of the file.                               |

*Custom Permissions*

### HaloCAD Screen Introduction

After installing the HaloCAD add-on, the HaloCAD tab appears in the CAD application, as shown in the figure below:  
![HaloCAD in Revit.png](https://help.secude.com/__attachments/a_e3976fe4037234fd617330b555fb53b9275c35eae472f0501c59e8c33185c26d/HaloCAD%20in%20Revit.png?cb=00ed91a0c5d651b07d1d90d8d5957699)

*HaloCAD in Revit*

The table below outlines each element of the HaloCAD menu.  

| **S.No** |                                                                               **Icon**                                                                                |                                                                                                                                                                                                                                                                                                                                         **Description**                                                                                                                                                                                                                                                                                                                                         |
|----------|-----------------------------------------------------------------------------------------------------------------------------------------------------------------------|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1        | ![Status icon.png](https://help.secude.com/__attachments/a_39341cec115e747aed87652076fed65fd03e15a879292c5ce8233c3efe80e9e6/Status%20icon.png?cb=ce9418192203a4b0d6c6149b5cbf59df)           | The **Status**icon displays the status of the file. ![Status UI.png](https://help.secude.com/__attachments/a_cb03035e04687e8f3268fcbc22cdb255b2d3b1a067b2e5b8bb7a3c0da1c775a2/Status%20UI.png?cb=e87873309072ed1574f6cca1a7a2ac90) 1. **Connected as**: Name of the logged-in user 2. **Owner**: Author of the document 3. **Sensitivity**: Name of the label applied 4. **Permissions**: Rights on the file 5. **Expire access**: Displays the details of how long a user can access the labeled file 6. **Revoke Access** button**:**Revokes access granted for a protected document 7. **Reset**button: Logs off a user from the current active session. The button will be disabled unless the user logs in again. |
| 2        | ![About icon.png](https://help.secude.com/__attachments/a_f5795f9b3e9ac3fb1a64a2afcc4a8e6b3298ec4ba26c6032e0637e362a710542/About%20icon.png?cb=cfc1f9a8ecfc4512526b8bd681ce04ed)             | The **About**icon displays the application version and license information. For details on license activation, refer to the "License Activation" section of the Technical Reference Manual. ![About Screen.png](https://help.secude.com/__attachments/a_4ac33f6ea5086af1387a090945365d43f113349cd4edf5a7d8b127ff81b3deaa/About%20Screen.png?cb=03b3e1db0e4336b0ce9d993fdc0031b3)                                                                                                                                                                                                                                                                                                                                       |
| 3        | ![Sensitivity icon.png](https://help.secude.com/__attachments/a_602450e4f229069ad14cdb69a65c6416d4f093e6e655d57885180bcd4e147eb0/Sensitivity%20icon.png?cb=466bc90a180e87e1e1401e8940eebb25) | The **Sensitivity** icon enables and disables the **HaloCAD**ribbon. ![HaloCAD RIBBON.png](https://help.secude.com/__attachments/a_5ace89ffd84eb681794ded7d81d8f5d90610376e62f55d96102766ea77b14ba6/HaloCAD%20RIBBON.png?cb=6107f0aaf7b088a42e0dc10354485b6c) Pencil icon -**Click to change label**: 1. Downloads the available labels. 2. Allows changing an applied label.                                                                                                                                                                                                                                                                                                                                          |
| 3        | ![Sensitivity icon.png](https://help.secude.com/__attachments/a_602450e4f229069ad14cdb69a65c6416d4f093e6e655d57885180bcd4e147eb0/Sensitivity%20icon.png?cb=466bc90a180e87e1e1401e8940eebb25) | ![Sensitivity after connecting.png](https://help.secude.com/__attachments/a_27c27f0712f77134d31523f79572f79d6476616b959d0c984108a5cfa31e6f0e/Sensitivity%20after%20connecting.png?cb=12048eebfd4163f4f403e79be958fa19) 1. Green check mark -**Click to set label**- applies the selected label or removes the existing label. 2. Red cross mark -**Click to cancel**- cancels the selected label. 3. **Sensitivity** labellist - displays the labels.                                                                                                                                                                                                                                                                  |

*Overview of screen elements*

### How to Protect a CAD File?

**Prerequisites**

* To protect organizational data by using sensitivity labels, configure protection settings for each label in the **Microsoft Purview portal**.

* To set a default label for documents, configure the following setting in the **Microsoft Purview portal** : Go to **Label policies** \> **Settings** \> **Documents** \> **Default settings for documents** \> **Apply a default label to documents**, and then select a label from the list.

To protect a CAD file, perform the following steps:

1. Open the Revit application, and then open an existing file or create a new file.

2. For new or unprotected files, the **Sensitivity** status displays **Not set** if no default label is configured in the policy. If a default label is configured, the configured default label is displayed. In this example, no default label is set.

3. On first login, HaloCAD prompts for **Microsoft Sign-In Assistant** authentication.

   ![Microsoft Sign-In Assistant invoking message.png](https://help.secude.com/__attachments/a_322c2186aa7abc76784afc4c2c7d989dc3c664e92afbbfae0e89e09aff157e3f/Microsoft%20Sign-In%20Assistant%20invoking%20message.png?cb=b10bfafa8b8dc478e16cac3e3c30e743)

   *Microsoft Sign-In Assistant invoking message*
4. Click **OK**and enter your credentials.

   ![Microsoft Sign in1.png](https://help.secude.com/__attachments/a_3897799d54b8abb27ab1d014a06f8e801f472417fd29969bb0abe270fee3e4ca/Microsoft%20Sign%20in1.png?cb=fa89340e00cf832438fead49e4bee0a3)

   *Authentication sign-in prompt*
5. After authentication, HaloCAD connects to Microsoft Entra ID and caches the user credentials.

6. Go to the **HaloCAD** tab and click **Sensitivity**.

7. To apply the label to the active document, click the pencil icon (**Click to change label**).

8. A notification appears indicating that labels are being downloaded from Microsoft Purview Information Protection.

   ![Please wait message.png](https://help.secude.com/__attachments/a_f8f045fb6ea1d9ec0895bb02df166f2bb49076af2fcb4ebea5bdd58c4134e757/Please%20wait%20message.png?cb=8c8fb5b524d72959028244e9c5ec0f97)

   *Fetching the labels*
9. From the **Sensitivity** list, select a label, and then click the green check mark (**Click to set label**) to confirm the selection.

   ![Downloaded labels for the signed in user.png](https://help.secude.com/__attachments/a_0dc040db98e18f0a5b2344c2417eabf416b66c17565e21a876d0a6ec58a546d5/Downloaded%20labels%20for%20the%20signed%20in%20user.png?cb=c1daf6155eac7f06d1675799f92e2c29)

   *Downloaded labels for the signed-in user*
10. For a new file, click **Save** and specify a file name.

11. For an existing file, an additional save action is not required. When the label is applied by clicking the **Click to set label** (check mark) icon, the file is saved automatically.

**Result**

* The selected label is applied to the active document.

* The selected label is displayed on the HaloCAD ribbon, along with the color configured in the Microsoft Purview portal.

* To clear the credential cache, click **Reset** in the **Status**UI.

![Label selection.png](https://help.secude.com/__attachments/a_6b1883fb1405ca1f154099cb63388f3c588a67dcac7d97cd0aa75927fdefff02/Label%20selection.png?cb=31024bdd8fa60921a673affe79b18481)

*File with applied label*

#### **Cancel, Remove, Relabel, and More**

1. **Canceling Label Selection** : If you have selected an incorrect label, you can cancel it by clicking the red cross icon (**Click to Cancel**). This will remove only the selected label that has not yet been applied to the file.

2. **Removing Protection** : To remove an existing label and keep the file unprotected, select the **No Protection** label from the list. Note: Whenever you change a label, click the green check mark icon (**Click to set label**) to apply the updated label. The file will be saved, and the label will be applied to the active document.

3. **Relabeling** : If you want to apply a different label or modify protection settings (Custom Permissions) after a label has already been applied, first click the pencil icon (**Click to change label** ) and then select a new label from the list. For more details, refer to "[Example 7: Custom Permissions Label](https://help.secude.com/halocad-add-on-for-autodesk-revit/2.4/rv-operations-manual.md#CPL)".

4. **Revoke Access** - If an author does not want a user to access the shared file for security reasons, you can prohibit it by clicking **Revoke Access** in the **Status** UI. Please refer to the section "[Example 10: Revoke a File](https://help.secude.com/halocad-add-on-for-autodesk-revit/2.4/rv-operations-manual.md#revoke)".

#### Log out an Active User

This section describes how to log out the currently active user from HaloCAD. Logging out ends the active session and allows another user to log in.

1. Go to the **HaloCAD** tab \> click **Status** \> click **Reset**.

2. When the following message appears, click **Yes**.

   ![Reset Clear cached credentials #1_2.png](https://help.secude.com/__attachments/a_68d750b6aa047184373622fbab0f0917e2ead5732e22a6f082ca03daf3f2e8e9/Reset%20Clear%20cached%20credentials%20%231_2.png?cb=883a859681b430cb98051260ecafa62b)

   *Clear cached credentials #1*
3. When the next message appears, click **OK**.

   ![Reset Clear cached credentials #2_2.png](https://help.secude.com/__attachments/a_34e0eeeace67bd2852ace4fd1d82004201ec4ce7070d47c2129c2def0dd437b5/Reset%20Clear%20cached%20credentials%20%232_2.png?cb=23441a9334f41a354fcf13df9ea57418)

   *Clear cached credentials #2*
4. Restart the application.

**Result**

* After relaunching the application, users can log in to a new HaloCAD session using their credentials.

* If you do not relaunch the CAD application, HaloCAD displays the following message: *"For HaloCAD to work properly you should relaunch the application now".*

* Click **OK**, and then relaunch the application.

**Next step**

1. **Log in after reset:** After restarting the application, when you open a protected file or click the pencil icon (**Click to change label** ), HaloCAD prompts you to use the Microsoft Sign-In Assistant. Click **OK**, and then sign in with your credentials.

   ![Microsoft Sign-In Assistant invoking message.png](https://help.secude.com/__attachments/a_e3d5a7113a3cac66543681efca0623000f9074e127fb27561fc700b25cf09d73/Microsoft%20Sign-In%20Assistant%20invoking%20message_2.png?cb=1f27eeff142b5b05e48f95f0e760e276)

   *Microsoft Sign-In Assistant invoking message*
2. For more information about HaloCAD functionality, see **Common scenarios**.

### How to Export a Protected CAD File to a PDF File?

To convert / export / save a protected file as PDF:

1. Go to the **File** tab \> click **Export** \> **PDF**\> choose a location and enter a file name.

2. Click **Export** on the**PDF Export**dialog.

**Result**: An exported PDF file is saved with protection.

The protected file may need to be viewed after being exported. To open a protected file, follow the instructions below:

**Prerequisite**: Ensure that the latest version of Acrobat Reader DC or Acrobat DC is installed.

1. Double-click the protected file or open the **Adobe** application, go to the **File** menu \> **Open** \> browse, and select the file.

2. Microsoft Sign-in prompts you to provide your credentials.

3. Enter the credentials and click **Sign in**.

   ![Opening a PDF file using MIP plug-in.png](https://help.secude.com/__attachments/a_15829a97d1b1b44e44f8eaaa62daac73805eadbaf2f8abfa1398fb5786de55fd/Opening%20a%20PDF%20file%20using%20MIP%20plug-in.png?cb=a809931c9881a9792aed85dec12846e7)

   *Protected PDF File*
4. To the question "*Do you want to stay signed in?* ", answer **Yes**.

**Result**:

* Upon successful authentication, the protected file is opened.

* If authentication fails, access to the file is blocked.

**Next step**

To see the actual permissions that are applied to the file, do one of the following:

* Click on the lock icon \> **Permission Details** \> **Document Properties** screen \> click **Show Details**.

* Click **File** \> **Properties** \> click **Security** tab \> **Document Properties** screen \> click **Show Details**.

### How to View a Protected File in HaloCAD Reader?

The reader add-on is intended for customers who do not have the full HaloCAD solution installed. Secude provides this viewer program to enable end users to view HaloCAD-protected files without having to install the standard (full) version of the HaloCAD solution on their desktops.  
**Reader add-on vs HaloCAD Standard add-on**

Both add-ons use the Microsoft Purview Information Protection security solution. However, the reader add-on cannot function as a HaloCAD Standard add-on; it is limited to opening and reading CAD files that are protected by the Standard/Full add-on.

Prerequisite: Make sure that the HaloCAD Reader Add-on for Revit is installed.

1. Double-click the protected file.

2. HaloCAD will prompt you about the Microsoft Sign-In Assistant before allowing you to access the file.

3. Click **OK.** Enter the credentials and click **Sign in**. (However, you do not require this validation if your cached account information is available.)

**Result**:

* A read-only version of the file opens with the following message.

  ![HaloCAD reader message.png](https://help.secude.com/__attachments/a_92f61e3b9e4ea45a741648a958f740e774539f7c170d2330e0e67df4c112c6c6/HaloCAD%20reader%20message.png?cb=0e0b5e54366731192218e4fb0a8fa7d9)

  *HaloCAD reader message*
* Click **OK**on the HaloCAD reader message.

* You can also observe the disabled pencil icon (**Click to change label**) in the Sensitivity ribbon, along with disabled tabs, panels, and buttons in the CAD application, as well as disabled permissions such as edit, copy, print, export, and change rights options.

  ![Disabled Click to change label icon.png](https://help.secude.com/__attachments/a_5580bf27917c01e1621d687695de629441bc0e45706f7591ff198f7e0546a68d/Disabled%20Click%20to%20change%20label%20icon.png?cb=8539579cb08ff6d32c747506b0fb6730)

  *Disabled Click to change label icon*

**Next step**

The reader add-on gives you the following options, similar to the standard add-on:

* To view the file's permissions, click the **Status**icon.

* To log out an active user from a HaloCAD session, click the **Reset**icon.

## Common Scenarios

This section presents common scenarios for illustrative purposes and provides general guidelines.

### Concept: Sensitivity Labels

MPIP labels can be customized to meet the requirements of each organization. These labels are defined and managed directly in the Microsoft Purview portal, and the HaloCAD Add-on retrieves them for user selection. When a sensitivity label is applied, the associated permission levels are automatically enforced on the document; any rights that are not explicitly granted are not assigned to the user. For example, a label applied to a CAD file with view-only permission allows users to view the content without any additional rights.

1. Let's say, for example, that you set up a label with "Viewer" permission. In this case, the user will be able to view MPIP-protected content, but the following actions and menus will be disabled:

   1. Pencil icon - **Click to change label** in the HaloCAD Sensitivity ribbon.

   2. All tabs, panels, and buttons in the CAD application.

   3. Edit, Copy, Print, Export, Change Rights, and Revoke options in the **Status** UI. Refer to [Example 1](https://help.secude.com/halocad-add-on-for-autodesk-revit/2.4/rv-operations-manual.md#EX1).

2. In contrast to the previous point, if you configure a label with 'Co-Owner' permission, the user will have full access to the file, including the ability to view, edit content, print, copy, and export the file, as well as change rights (labels). Refer to [Example 2](https://help.secude.com/halocad-add-on-for-autodesk-revit/2.4/rv-operations-manual.md#EX2).

3. For more details on labels, please refer to Microsoft Documentation.

### How to Open a Protected CAD File?

Follow the procedure below to view the protected file:

1. Click the protected file to open it.

2. When a labeled file is opened for the first time, a connection to the Microsoft Entra tenant is requested via the Microsoft Sign-In Assistant.

3. Click **OK**when prompted that the Microsoft Sign-In Assistant will be invoked and user credentials will be cached.

4. Follow the on-screen instructions to complete the authentication process.

5. After successful authentication, the file opens.

6. Access results for the same document may vary based on the applied policy settings. Please refer to the following examples.

#### Example 1: Label with Read-only Access

1. The MPIP label **HCAD Confidential** is applied to the following file. This label allows the logged-in (connected) user to view the file while restricting all other operations. To view the applied label and your file permissions, click the **HaloCAD** tab and then select **Status**.

   ![EX 1 User with restricted access #1.png](https://help.secude.com/__attachments/a_c9c74a8961934946e9cd82bd8b01365ac4098b3fc1880ef03ec4123aaf4e9310/EX%201%20User%20with%20restricted%20access%20%231.png?cb=e446225e1e22eae6f7a4041383e035c5)

   *User with restricted access #1*
2. In case you edit the drawing by using a command, you will receive the following HaloCAD pop-up.

   ![EX 1 User with restricted access #2.png](https://help.secude.com/__attachments/a_4e42a68f00ecc59f3a641618eefbb8af5d066adec2a6d97cb03df55db9bcf1e8/EX%201%20User%20with%20restricted%20access%20%232.png?cb=a6cfbac3a18931078987bd22ca3d7939)

   *User with restricted access #2*
3. Click **OK**.

**Behavior When Attempting to Copy, Save, or Capture Screen Data**

One of the most common ways confidential information is compromised is by copying it (Ctrl + C) or capturing it using tools such as Print Screen or the Snipping Tool and then transmitting it elsewhere. To prevent this, when a label without the **Copy** usage right is applied, the entire content is blanked out during copy or screen-capture attempts. Similarly, when the user clicks the **File** menu, options such as **Save** , **Print**, and other related actions are disabled because the user does not have the required authorization to perform these operations.  
![print Restriction.png](https://help.secude.com/__attachments/a_f44a50cb154c5b43ec684bf1abdf6db087369e8dda5d57950aad735537e23f56/print%20Restriction.png?cb=152ec6fe8610eacd363daee8e2a16314)

*HaloCAD prevents copying data*

**Behavior When Attempting to Relabel with Read-Only Permissions**

With "Read-only / View" rights, you are only allowed to view the content; all other options, including the tab, panel, button, and pencil icon - **Click to change label** on the HaloCAD Sensitivity ribbon, are disabled. As a result, the imposed protection cannot be relabeled or removed.  
![Disabled tab, buttons, and icons.png](https://help.secude.com/__attachments/a_0f5b16ca334319e7c274515dbf140ed9c74a711a9f101497c702ed33afc3c7f4/Disabled%20tab,%20buttons,%20and%20icons.png?cb=aebcf8af147e3a193fe03bca67adf537)

*Disabled tabs, buttons, and icons*

#### Example 2: Label with Full Control Access

The file shown below is labeled **HCAD Confidential** , which grants the user full access, therefore, all menus are enabled in the file. To view the applied label and your file permissions, click the **HaloCAD** tab and then select **Status**.  
![EX2 User with full access.png](https://help.secude.com/__attachments/a_9024949e90fb484e0f66ed3dc9ce97a1c10ccaf68de1af98a3bcb32066ec6bab/EX2%20User%20with%20full%20access.png?cb=ced84ac4ac132deafa982507887b741a)

*User with full access*

**What Happens if You Try to Relabel with Co-Owner Permission?**

With "Co-Owner" rights, you have complete control over the content and can relabel or remove the protection as needed by clicking the pencil icon - **Click to change label**on the HaloCAD Sensitivity ribbon.

#### Example 3: Unauthorized User Access

An unauthorized user who double-clicks on a protected CAD file receives the warning shown below. Note: An unauthorized user is anyone who is not listed in the allowed user list configured within the Microsoft Purview Information Protection sensitivity label.  
![Unauthorized user opening a protected file.png](https://help.secude.com/__attachments/a_856d20db3d7f5dd6745326639ef74bad7110fc8a5b9f2f3e29058d7954ec5387/Unauthorized%20user%20opening%20a%20protected%20file.png?cb=8d881ef2a0b16af3c70c9a836bd0e2f4)

*Unauthorized user opening a protected file*

#### Example 4: Label Deleted from Microsoft Purview Portal

For instance, a label is applied to a file and is removed from the Azure portal. Users could no longer open the protected file; however, the underlying protection remains the same. A user who tries to consume this protected file will receive the following message.  
![Ex 4Deleted Label in Azure Portal.png](https://help.secude.com/__attachments/a_05c5ca9f75cded3f868b61c5b39b1792f2c2c39d00521bb493efc68cfdd7fd73/Ex%204Deleted%20Label%20in%20Azure%20Portal.png?cb=adcdd6b2b1ffd7b307bbd55cbb5b0e4c)

*Warning message for the unavailability of a label*

#### Example 5: Label with Content Marking

Applying a watermark indicates what type of content it is and how it should be handled, and its presence in a file serves as a constant reminder to the user that the file contains sensitive information. The file below is labeled **HCAD Secret** and bears the watermark **Secret**.  
![Watermark.png](https://help.secude.com/__attachments/a_1f9f4d48f6706a70f95c436566ec857c93186a88f8ca9409773414c043f8dd71/Watermark.png?cb=0bfd6f1c31931ef8ce7bc921e106a469)

*Content with watermark*

#### Example 6: Other Use Case Scenarios

##### **Importing a file with a restricted/least permission label**

A restricted/least permission label refers to a label with the lowest permission, such as view-only access rights. A full permission label has full access rights, such as Edit, Export, Change Rights, and so on.

1. **Case 1** - When you import a source file protected with a restricted permission label into the destination file that is protected with a full permission label, the following HaloCAD pop-up message appears as *"Please confirm applying least permission label from import file? Yes - Current file will be updated with import file label "XXXXXXX" No - Import operation will be cancelled."*

   1. If **Yes** ,then the imported file's label will be applied to the destination file. For example, the **HCAD Public** label with view rights will be applied.

   2. If **No** ,then the import will be blocked and the parent assembly file will remain unchanged.

2. **Case 2** - When you import a source file protected with a "full permission" or "restricted permission" label into a destination file that is unprotected, the HaloCAD pop-up message appears as described in Case 1 above. The response (Yes or No) process will also follow the same procedure as in Case 1.

3. **Case 3**- When you import a source file protected with a "full permission" label into a destination file protected with a "restricted permission" label, the import is allowed and no label changes occur in the destination file.

##### **Labeling a File Without Protection**

Compared to a standard MPIP label, a **label-only MPIP label** adds metadata to a file without applying protection. In this context, *label-only* refers solely to metadata classification. The key difference between a standard **MPIP label** and a **label-only MPIP label** is that the standard label includes encryption and protection options, whereas the label-only variant does not. As a result, a **label-only MPIP label** can be applied to files that do not require protection but still need to be labeled for classification purposes.

**Prerequisite** : Make sure the **Control access** check box under **Choose protection settings for the types of items you selected** page is unchecked while defining the label-only in the Microsoft Purview portal.

**Other key points**

1. When a label-only MPIP label is applied to a file, the suffix (**Label Only** ) is appended to the label name. For example, if the label name defined in the portal is **HCAD Metadata** , it appears as **HCAD Metadata (Label Only)** after being applied to the file.

   ![Label only metadata.png](https://help.secude.com/__attachments/a_dd68ce290fafd94bbc943caba8465ee7105720371e8b2c00623438193bb62948/Label%20only%20metadata.png?cb=757d5f76840e7a26f2f827d57967bb5b)

   *MPIP label-only*
2. **Full rights**: A file with this label allows a user to have full rights on it.

3. **Notifications**: Similar to a standard MPIP label, the user will receive notifications when label-only is applied to a top-level parent file.

4. **With the HaloCAD Add-on**: The label details will be displayed in the Status UI, just like a standard MPIP label.

5. **Without the HaloCAD Add-on**: A file with a label-only MPIP label will behave like any other unprotected CAD file.

6. **Watermark**: A watermark option can be configured for a label-only MPIP label.

#### Example 7: Custom Permissions Label

**Difference Between Sensitivity Labels and Custom Permissions**

**Sensitivity Labels**

Sensitivity Labels are defined and managed by an organization's administrator in the Microsoft Purview portal. Each label includes a predefined set of permissions and is also referred to as administrator-defined permissions.

**Custom Permissions**

Custom Permissions are user-selectable permission sets available in the HaloCAD application UI. These permissions are defined by users and are also referred to as user-defined permissions.

##### **Protection using Custom Permissions from Microsoft Purview Portal**

**Prerequisite** : Make sure the custom permissions label in the portal is set to **Let users assign permissions when they apply the label**.  
![Custom permissions and other labels.png](https://help.secude.com/__attachments/a_11724c1c184285ed53cc71df71c952dc071374e16c7cdba9ea9c782236def10d/Custom%20permissions%20and%20other%20labels.png?cb=79b3128a59e46f39243148c26ea83813)

*Custom permissions and other labels*

Follow the procedure to apply the custom permissions label:

1. Open the Revit application, select a template, and then create objects.

2. Click the **Click to change label** icon.

3. When HaloCAD downloads the labels, custom permission labels (from the Microsoft Purview portal and user-defined labels) are listed in the Sensitivity ribbon.

4. For illustration, the custom permission label from Microsoft Purview is named **Custom Permissions (Portal)**.

5. Select the **Custom Permissions (Portal)** label from the list and click the green check mark (**Click to set label icon**).

6. The HaloCAD screen appears, as shown below.

   ![HaloCAD Custom permissions.png](https://help.secude.com/__attachments/a_f54c54f91e3914bf122c52985d4d05388bfde42cbc8754b2299f6b92e8621112/HaloCAD%20Custom%20permissions.png?cb=a7defa3e0a5bd8bac710fe5e2162e14a)

   *Custom permissions*
7. From the **Select Permission** list, choose the level of access you want users to have when protecting the [file: (Viewe](#)r - View Only / Reviewer - View, Edit / Co-Author - View, Edit, Copy, Print / Co-Owner - All Permissions / Only for me).

8. In **Enter Users, Groups, or Organizations**, specify who should have access to the file. Enter individual email addresses, group email addresses, or an organization domain, separated by commas, spaces, or semicolons.

9. In the **Expire Access** field, specify how long the labeled file can be accessed. Select **Never**for unlimited access, suitable for less sensitive content. For highly sensitive content, select an expiry date so that recipients (other than the owner) cannot access the file after that date.

10. Click the **Clear date selection** option to clear the previous date selection.

11. Click **Apply** to confirm the protection settings.

**Result:** The label is applied to the file.

**What happens when a user opens a custom permissions--labeled file?**

Based on the user's permissions, the file can be accessed accordingly. Note: The author of the document always has full rights to the file and can access it at any time, regardless of any custom permissions or expiry date configured in the label. The following example shows a label with custom permissions.  
![User with custom permission.png](https://help.secude.com/__attachments/a_b5beae2d93201a7910cfba7736a7e70b453082b4fd80db6fffae8704271a0ee1/User%20with%20custom%20permission.png?cb=9cda67d2002849a7fcab56e653bdc328)

*User with custom permission*

##### **Protection using Custom Permissions via HaloCAD Add-on**

In comparison to the previous section, the HaloCAD add-on also supports a **Custom Permissions** label. However, this label is defined at the application level within HaloCAD and is not obtained from the Microsoft Purview portal. The process for applying this label is the same as described in the previous section.

#### Example 8: Set an Expiration Date for File Access

**Prerequisites:**

1. Ensure that the expiration date is configured in the Microsoft Purview portal when using a static MPIP label.

2. Ensure that the expiration date is configured in the Custom Permissions label when using it via the Microsoft Purview portal or the HaloCAD add-on.

##### Why is File Expiration Necessary?

When files are shared with external vendors, access may continue even after a contract ends, creating security risks. To prevent this, set an expiration date on the file. This is a recommended practice when working with vendors or contractors. For example, if a file is shared with an expiration date of 31/12/2028, business partners will not be able to open it after that date. Each time the file is opened, HaloCAD displays the file's validity.  
![Validity of the file.png](https://help.secude.com/__attachments/a_65f7ab68dd695d044b1cc881253f15ee8faaad7decc587c7b0aa0ebaaf301aba/Validity%20of%20the%20file.png?cb=c0490b7d9d9b3be46dad4d4a8162da1f)

*Validity of the file*

##### **What Happens When a File Expires?**

When a user opens a file that has reached its expiration date in their current time zone, the labeled file cannot be opened. HaloCAD will prompt a message "*You do not have sufficient permissions to view this document."* This behavior is like unauthorized file access, as described in the section "[Example 3: Unauthorized User Access](https://help.secude.com/halocad-add-on-for-autodesk-revit/2.4/rv-operations-manual.md#EX3)".

##### **How to Open an Expired File**

Recipients cannot open an expired file. Only the file author can access it. If a recipient needs continued access, they must contact the author to obtain a new copy of the file with an updated expiration date.

#### Example 9: Remove protection from a file

To remove a label from a protected file, you must either be the file's owner or have full permission to remove protection.

#### Example 10: Revoke a File

Prerequisite: Ensure that the user who wants to revoke a file has the required license, as specified in the Release Notes under the Requirements section.

Revoke Feature: MPIP provides a revoke feature that prevents any new access attempts to a protected file, restricting access to all users except the author. Note that revoking access removes permissions for all users associated with that label.

##### Why Should a User Revoke a File?

A user may revoke access to a sensitive file if it was sent by mistake, accessed from a suspicious location, leaked, or if a recipient no longer requires access. In these scenarios, the author can immediately prevent further access by revoking the file. Note: Revoking does not delete the shared file, but users will no longer be able to open it. The **Revoke Access** button is available on the HaloCAD status screen.

##### **How to Revoke a File?**

1. To revoke a file, go to the **HaloCAD** tab \> click **Status** \> click the **Revoke Access** button. The following message will appear:

   ![Revoke access message #1.png](https://help.secude.com/__attachments/a_02301e372908bd1ae82c40911cd43f2cdd6eaa14f038a001322e7e7b96d7199e/Revoke%20access%20message%20%231.png?cb=21f826c9b4f1f75830f091b2c4d13483)

   *Revoke access message #1*
2. Click **Yes** to confirm revoking access and continue with [step 3](https://help.secude.com/halocad-add-on-for-autodesk-revit/2.4/rv-operations-manual.md#revokestep3). If you do not have the required license, it is not possible to revoke a file. In this instance, HaloCAD will show the alert as follows:

   ![Access denied revoking a file.png](https://help.secude.com/__attachments/a_aceac65a703560027c17cf05bac618623430be346ca600a4fc44d31741b762d6/Access%20denied%20revoking%20a%20file.png?cb=d570dfa29e3c2cced391d2cb6d45cb39)

   *Access denied when revoking a file*
3. The following message will appear:

   ![Revoke access message #2.png](https://help.secude.com/__attachments/a_4a69214e19e518010efe91627ddc47e4d783e90e718d1ea59c555fb2ab8f9f5b/Revoke%20access%20message%20%232.png?cb=f7e0b9aaf36f012b0f2972f48b09b866)

   *Revoke access message #2*
4. Click **OK**and save the file.

**Result:**

* Access to the file is revoked.

* Users who previously had access to the document can no longer open it.

##### **What Happens if a User Attempts to Open the Revoked File?**

Once the file is revoked, the user cannot open it, although the user has accessed it before. HaloCAD shows a generic message as "*You do not have sufficient permissions to view this document."* This behavior is like unauthorized file access, as described in the section "[Example 3: Unauthorized User Access](https://help.secude.com/halocad-add-on-for-autodesk-revit/2.4/rv-operations-manual.md#EX3)".  
**MIP SDK**

A revoked file can be accessed by the same user if it was previously opened by the same user in the same HaloCAD session. This is due to the actual behavior of the MIP SDK if you have defined the sensitivity label with the two options **Allow offline access** and **Users have offline access to the content for this many days,** the configured offline access allows users to continue to access the revoked file until the offline policy period ends.

##### **What Happens if a User Changes the Label?**

Assume User A shares a sensitive file with User B.

**Case 1:** If User B makes copies of the original document, revoking file access by User A will also revoke all copies, since the label remains unchanged.

**Case 2:** If User A has not revoked access and User B (with full rights) changes the label, revoking file access will not apply to that modified copy. However, the original document will still be revoked.

##### **How to Open the Revoked File?**

A recipient cannot open a revoked file. Only the file author can access it. If a recipient needs access, they must contact the author to obtain a new copy of the file.

## **Troubleshooting**

This chapter will help you overcome the most common problems with the HaloCAD solution.

### **Cannot Sign in to Microsoft Sign-In Assistant**

**Symptoms**

The user login fails with the following error message.  
![Error Message.png](https://help.secude.com/__attachments/a_ddd7a6ea48d3fb13774c2ff7a852fe106d78858d94c5ad1e697ed8ac56f16662/Error%20Message.png?cb=6d9b3e79084c244dd66b83c93336a910)

*Microsoft Sign-in error message*

**Background**

The above error occurs when a user logs in to a HaloCAD session using Microsoft Sign-In Assistant.

**Probable Cause**

As the Redirect URL specified in the request does not match the URL configured for the registered application, Microsoft Sign-in fails.

**Corrective Action**

1. **Case 1:** An incorrect Redirect URI was entered during the HaloCAD installation.

   1. Reinstall the HaloCAD Add-on using the correct **Redirect URI**.

   2. Launch the CAD application, click the pencil icon (**Click to change label**), and sign in using the Microsoft Sign-In Assistant.

2. **Case 2** : Redirect URIs use an improper scheme (such as `http://contoso.com`)

   1. Log in to the Microsoft Azure portal.

   2. On the home page, click the **Show Portal Menu** icon, then select **Microsoft Entra ID**.

   3. Under the **Manage** section on your tenant's **Overview** page, choose **App registrations**.

   4. Click **All Applications**, and enter your application name in the search bar.

   5. From the list, select your application.

   6. Click the **Redirect URIs** link or select **Authentication** from the **Manage**section on the application overview page.

   7. Verify that the reply URL begins with https://. If it does not, update it to https and save the changes.

      ![Incorrect Redirect URIs.png](/__attachments/a_a5e80d898ceb10c239dd767571f2f749b69ac7ce51f1be97fdb85f03556394cf/Incorrect%20Redirect%20URIs.png?cb=e53194da9917a03c5e13fc8432d01cf9)

      *Incorrect Redirect URIs*
   8. Now, sign in using the Microsoft Sign-In Assistant.

3. **Case 3**: Tenant ID provided for multi-tenant application

   1. Reinstall the HaloCAD Add-on without entering the **Tenant ID**.

   2. Open the CAD application, click the pencil icon (**Click to change label**), and sign in using the Microsoft Sign-In Assistant.

### **Labels are not Getting Downloaded in the HaloCAD Session**

**Symptoms**

The user could not download labels.

**Background**

The user logs in successfully in the HaloCAD session, but cannot download labels.

**Probable Cause**

Improper label configuration in the Microsoft Purview portal.

**Corrective Action**

1. Log in to the Microsoft Purview portal as a global administrator.

2. Ensure that the labels are configured to apply protection.

3. Verify that the user has the required policy to use the label.

4. For more details, refer to the Microsoft documentation.

### **Label not Found in the Policy**

**Symptoms**

HaloCAD prompts the following message:  
![Label not found.png](https://help.secude.com/__attachments/a_0fb6e9a2b9e745fa2579cefb5f9f08b78a31ddaed77d326b8e9daa21547d2682/Label%20not%20found_2.png?cb=42657b787053faa9668d2f34dee1ac87)

*Label not found error message*

**Background**

The above message is shown when you apply a label to a file and save it.

**Probable Cause**

Improper label configuration.

**Corrective Action**

Request your Microsoft Purview portal administrator to review the label and publish label policies.

### **Double Key Encryption Label could not be Applied**

**Symptoms**

HaloCAD prompts the following message:  
![Label could not be applied.png](https://help.secude.com/__attachments/a_9520cc6627fb938e720a300ab9c0214868158076affe80c6664ec3be31d46461/Label%20could%20not%20be%20applied.png?cb=a4d057352d6127ca811d925833449e95)

*DKE label error message*

**Background**

The above message is shown when you apply a Double Key Encryption (DKE) label to a file and save it.

**Probable Cause**

This issue occurs if the DKE service is stopped or unavailable.

**Corrective Action**

Make sure that the DKE service on the client's computer is active and accessible online.

### **Could not Connect to MPIP -- Case 1**

**Symptoms**

HaloCAD prompts the following message:  
![1_Azure RMS connection fails - wrong values.png](https://help.secude.com/__attachments/a_7015f1ca2ba97f61af646b37e012d496c842169e43ffa0f5b9ce8d4a0dcb0b7d/1_Azure%20RMS%20connection%20fails%20-%20wrong%20values.png?cb=082ddb7cd5d607e89817b925614b8284)

*MPIP connection warning message #1*

**Background**

The above error occurs when a user logs in to the HaloCAD session via Microsoft Sign-In Assistant.

**Probable Cause**

This issue occurs if one or more of the following conditions are true:

1. **Case 1** : You have entered the incorrect **Application (client) ID** , **Directory (tenant) ID** , and **Redirect URI**.

2. **Case 2**: You have closed the Microsoft Sign-In Assistant dialog unknowingly.

**Corrective Action**

1. **Case 1** : Make sure the correct values of **Application (client) ID** , **Directory (tenant) ID** , and **Redirect URI** are entered during the initialization.

2. **Case 2**: Relaunch the application and enter user credentials in the Microsoft Sign-In Assistant dialog.

### **Could not Connect to MPIP -- Case 2**

**Symptoms**

HaloCAD prompts the following message:  
![2_Azure RMS connection fails- Network issue.png](https://help.secude.com/__attachments/a_252456f7ef680e643be1edf4edc790a9f44fa267ff4ed04b273f65a9b7bb1a87/2_Azure%20RMS%20connection%20fails-%20Network%20issue.png?cb=55d7256dc1db86eb2959362ef8f9b728)

*MPIP connection warning message #2*

**Background**

The above error occurs when a user logs in to the HaloCAD session via Microsoft Sign-In Assistant.

**Probable Cause**

The most likely cause of this issue is that your network is preventing you from connecting to Microsoft Purview Information Protection.

**Corrective Action**

1. Review yourfirewalls or network infrastructure to establish a connection with Azure.

2. Check if your proxy limits the URL.

### **HaloCAD Activation Fails**

**Symptoms**

HaloCAD prompts the following message:  
![Exceeded maximum activation.png](https://help.secude.com/__attachments/a_4e8a70e5cfc59b81a94071df37938b1e4bf728ab47df7efcfebb88a29bd0d2f1/Exceeded%20maximum%20activation.png?cb=df5eb60ae6e98694e03d722487b3100f)

*HaloCAD Activation warning message*

**Background**

The above message is shown when you try to activate HaloCAD on a system.

**Probable Cause**

After a successful license activation, the license status changes to **Active** , and the **Total activations** count in Secude's License Server Manager increases by one. The total activation count increments with each activation.

For example, if you purchased ten HaloCAD licenses, you can activate HaloCAD up to ten systems. After the tenth activation, attempting to activate HaloCAD on another system will fail, and the License Server Manager will display an error indicating that the maximum number of activations has been reached.

**Corrective Action**

1. **Action 1:** Uninstall one or more HaloCAD add-ons that were previously activated on a CAD system, and then activate the license on the required CAD system.

2. **(Or) Action 2:** Purchase an additional HaloCAD license.

3. After completing the action, activate the license.

### **Incorrect License Key Error Message**

**Symptoms**

HaloCAD prompts the following message:  
![Incorrect license activation message.png](https://help.secude.com/__attachments/a_ba488df3f9b9a9ea7ce50b3f6f3a4716a7db91b20c38ac36fa38aaed08ac74ab/Incorrect%20license%20activation%20message.png?cb=cb267dc0092fe4945e1fb661682fcde4)

*Incorrect license activation message*

**Background**

The above message is shown when you try to activate HaloCAD on a system.

**Probable Cause**

There are various possible reasons, including a license key associated with another HaloCAD, an incorrect key, or an invalid key.

**Corrective Action**

Make sure to enter the correct licensing key, unique to this add-on, before activating it.

### **Why Am I Getting License Expiration Notifications?**

**Symptoms**

HaloCAD prompts the following message:  
![Prior message for expiration..png](https://help.secude.com/__attachments/a_347c8cfc6feaa527d5b3e774ea7f69aaf7e2a6d3e9d76f89ae5ef87e7627bf23/Prior%20message%20for%20expiration..png?cb=c97540b1f90a870ddaebd37429107c0b)

*HaloCAD notification*

**Background**

The above notification occurs once a day when a user logs into the HaloCAD session.

**Probable Cause**

When you run the CAD application and see a HaloCAD expiration alert, it means action is required to continue using the add-on.

Each license has an end date defined at the time of issue. When the license is within 30 days of expiry, the License Manager triggers daily notifications in HaloCAD. For example, if the license expires on September 30, 2028, notifications will begin appearing once per day starting September 1, 2028.

**Corrective Action**

1. Purchase a new HaloCAD license or renew the existing license.

2. Activate the license.

### **Other License-Related Error Messages**

|                 **HaloCAD License Error Messages**                  |                                     **Root Cause**                                     |                                                **Correction Action**                                                |
|---------------------------------------------------------------------|----------------------------------------------------------------------------------------|---------------------------------------------------------------------------------------------------------------------|
| The license validity period has expired                             | When your license had just expired.                                                    | Please contact Secude's representative to receive a new license.                                                    |
| The license is not enabled.                                         | When you try to activate a license key that is already disabled on the License portal. | Please contact Secude's representative to enable the license.                                                       |
| This device is blacklisted.                                         | When your device is blocked in the license portal for a specific reason.               | Please contact Secude's representative to enable the device.                                                        |
| This license cannot be activated before the start date: yyyy-mm-dd. | When attempting to activate a license before its start date.                           | Please make sure the license is activated on the start date.                                                        |
| Date header is not valid or set in past.                            | When the date or time on the machine is incorrect.                                     | Please make sure that the machine installed with the HaloCAD add-on is synchronized with the current date and time. |

*License-related error messages*

## Technical Support

Before contacting Technical Support, ensure that you have the following information available. Providing this information helps the support team investigate and resolve your issue more efficiently.

* Full contact details

* Product build version

* Date, time, and description of the error (include screenshots, if possible)

* Details of any third-party software used with the product

* Any additional information required to reproduce the issue

**Contact Technical Support**

Secude provides technical support through email [++support@secude.com++](mailto:support@secude.com). When contacting Technical Support by email, include your company details, a detailed description of the issue, and the relevant log files (if available). A support representative will respond to your inquiry.

**Additional Resources**

Visit the Secude website [++https://secude.com++](https://secude.com/) to learn about upcoming events, press releases, and to download white papers.

**Documentation Feedback**

Secude values your feedback and continuously strives to improve product documentation. To provide feedback, send an email to: [++documentation@secude.com++](mailto:documentation@secude.com)

Include the following details in your feedback:

* Product name and version

* Documentation topic

* Description of the suggestion or error

The technical documentation team reviews all feedback and incorporates relevant updates in future documentation releases.

---
version: "2.4"
language: "en"
---
# Release Notes

## Introduction

The release notes provide brief and high-level descriptions of the new features of HaloCAD. Before installing HaloCAD, it is recommended to read the release notes to understand any current limitations or bugs that may apply to this version of the software.

## Product Description

HaloCAD acts as the guardian of your CAD files by automatically protecting them with Microsoft Purview Information Protection (MPIP) labels whenever they leave your secure IT perimeter. As a plug-in for CAD applications, HaloCAD offers access to MPIP-protected files, including label handling and privilege enforcement. CAD users will not notice any differences in the handling of CAD files because protection takes place in the background. By seamlessly attaching MPIP labels to the CAD files while they are being created, it provides end-to-end security for those files.

## System Requirements

The following system requirements table specifies the minimum and recommended technical specifications, such as software and network resources, necessary to run the product.  

|       **Components**        |                                                                                                                                                                       **Details**                                                                                                                                                                        |
|-----------------------------|----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| Supported Operating Systems | Windows 11 or above with updates installed.                                                                                                                                                                                                                                                                                                              |
| Supported file types        | 1. Native file types: `.rvt`, `.rfa`, and `.rte` 2. Export file types: `.dwg`, `.pdf`, `.dwf`, `.dwfx`, `.ifc`, `.dxf`, `.sat`, `.stl`, `.obj`, `.fbx`, `.tga`, `.bmp`, `.jpeg`, `.jpg`, `.png`, `.tif`, `.dgn`, `.xml`, `.step`, `.stp`, `.gif`, `.avi`, and `.stpz` 3. Import files type: `.dwg`, `.dxf`, `.sat`, `.ifc`, `.step`, `.stp`, and `.stpz` |

*Requirements*

**Supported Autodesk applications for HaloCAD Add-ons**

You are currently viewing the release notes for the current build. For previous versions, please refer to their respective release notes.  

|  **CAD applications**  | **HaloCAD Add-on version** |
|------------------------|----------------------------|
| Revit 2024, 2025, 2026 | 2.3, 2.4                   |
| Revit 2023, 2024, 2025 | 2.1, 2.2                   |
| Revit 2022, 2023, 2024 | 2.0                        |

*Autodesk applications and HaloCAD Add-on version*

## Prerequisites

Before installing the add-on, ensure that the following prerequisites are met:

1. An application is registered with Microsoft Entra ID.

2. An active Office 365 subscription is available.

3. Access to the recommended URLs is enabled.

4. TLS 1.2 or later is enabled on all client workstations to ensure secure communication.

For more information, refer to the **Technical Reference Manual**.

## Code Quality and Security

Secude focuses on software quality and security. This is accomplished by adhering to and exceeding best practices in development, testing, and quality control. Secude has chosen SonarQube as the first building block for building and implementing a robust continuous code quality assurance (QA). SonarQube is a platform for static code analysis for continuous inspection of code quality. It performs automatic reviews of code to detect bugs, code smells, unit test coverage, and security issues in 29 programming languages.

SonarQube is utilized throughout the development process at Secude, and only the highest marks are accepted for a product to be released. It helps to regulate code quality from the beginning of development, find and repair issues promptly, and improve overall software stability.

Each build report can be found under its relevant version heading in this release notes.

**Reliability Rating**

1. A = 0 Bugs

2. B = at least 1 Minor Bug

3. C = at least 1 Major Bug

4. D = at least 1 Critical Bug

5. E = at least 1 Blocker Bug

**Security Rating**

1. A = 0 Vulnerabilities

2. B = at least 1 Minor Vulnerability

3. C = at least 1 Major Vulnerability

4. D = at least 1 Critical Vulnerability

5. E = at least 1 Blocker Vulnerability

**Security Review Rating**

The Security Review Rating is a letter grade based on the percentage of Reviewed (Fixed or Safe) Security Hotspots.

1. A = \>= 80%

2. B = \>= 70% and \<80%

3. C = \>= 50% and \<70%

4. D = \>= 30% and \<50%

5. E = \< 30%

**Maintainability Rating**

A=0-0.05, B=0.06-0.1, C=0.11-0.20, D=0.21-0.5, E=0.51-1

The Maintainability Rating scale can be alternatively stated by saying that if the outstanding remediation cost is:

1. \<=5% of the time that has already gone into the application, the rating is A

2. Between 6 to 10%, the rating is a B

3. Between 11 to 20%, the rating is a C

4. Between 21 to 50%, the rating is a D

5. Anything over 50% is an E

## Build 2.4

### New Features

There are no new features to highlight in this release.

#### Improvements

This section lists the improvements in the current release.

1. Added default values for silent command-line parameters. HCADRVT-169

2. Added support to display online documentation directly from the installer UI for both the standard and Reader add-on installers. When the **Online Help** button is clicked, the online documentation now opens in the user's default browser. HCADRVT-170

3. Improved token-sharing encryption and FIPS compatibility by ensuring proper OpenSSL FIPS context initialization and preventing failures in child processes during configuration decryption. HCADRVT-172

4. In previous releases, asterisks were used in MIP SDK logs to mask Personally Identifiable Information (PII), such as email names and IP addresses. This feature is now extended to HaloCAD logs to also mask information such as label name, label ID, engine ID, policy ID, and watermark text. HCADRVT-179

#### Fixed Issues

This section provides a list of the fixed issues in the current release.

1. Fixed an issue that prevented license deactivation during HaloCAD Add-on uninstallation, along with cache removal. HCADRVT-158

2. Fixed an issue where the application closed unexpectedly when saving to the Program Files folder with the add-on, without displaying an error message. HCADRVT-178

3. Fixed an issue where the exported PDF file was assigned an incorrect label. HCADRVT-177

4. Fixed an issue where a PDF file was generated or saved without **Export**permission. HCADRVT-182

#### Known Issues

This section describes the known issues with the current release.

1. When exporting a protected file using the **Show Rendering Dialog** option without the necessary export rights, the drawing is saved as a black screen. HCADRVT-41

2. When a protected PDF file is imported using **Link PDF/Import PDF**, it is not decrypted and is displayed as "Microsoft Azure Information Protection". HCADRVT-84

3. When exporting from a Revit file, a protected image file is exported with a `".p"` extension, such as `.ppng`, `.pbmp`, `.ptif`, or `.pjpg`. HCADRVT-85

4. When DKE files are available in recent documents and the DKE service is turned off, it takes longer to launch the Revit application and display the HaloCAD error restriction pop-up. HCADRVT-129

5. An incorrect HaloCAD error pop-up may appear when attempting to activate a license with only whitespace input. HCADRVT-184

6. Repeated "Revit" error pop-ups may appear when exporting a protected file to PDF (**Print** → **PDF**) without export rights. HCADRVT-183

## Quality Gate Report

Please see the table below for a list of SonarQube's key parameters for this version. Refer to the "[Code Quality and Security](https://help.secude.com/halocad-add-on-for-autodesk-revit/2.4/rv-release-notes.md#code)" section for more information on rating definitions.  

|         **Metric**         | **Value** |
|----------------------------|-----------|
| Coverage                   | 85.6%     |
| Maintainability Rating     | A         |
| Reliability Rating         | A         |
| Security Hotspots Reviewed | A         |
| Security Rating            | A         |

*Quality Gate report*

---
version: "2.4"
language: "en"
---
# Technical Reference Manual

## Introduction

Companies across industries, such as automotive, aviation, and high tech, create and manage their intellectual property (IP) based on drawings. These drawings are created digitally using computer-aided design (CAD) applications and are shared with users outside the organization owing to business considerations. It's essential to understand the potential risks associated with sharing business information. Comprehensive security measures are essential to reducing risks and safeguarding sensitive data. HaloCAD, a purpose-built data protection solution, is designed to help organizations achieve this objective effectively.

### How does HaloCAD protect your Data?

HaloCAD effortlessly integrates Microsoft Purview Information Protection (MPIP), formerly known as Microsoft Information Protection (MIP), the leading technology for Enterprise Digital Rights Management (EDRM). It acts as a shield for your CAD files by automatically labeling them with MPIP and manages data assets across your environment. HaloCAD modules can be used either in standalone mode or in combination with HaloCAD for PLM, which automatically protects file downloads, decrypts files during upload, and returns them to the PLM vault.  
![HaloCAD's high-level architecture.png](https://help.secude.com/__attachments/a_9749c43e9afe25abd6e3214db71a9d3cc5f9c6015f8e0fd0d7d0e4cb343c5f90/HaloCAD's%20high-level%20architecture.png?cb=9a10e8622ee0fddb28499b27d61f4613)

*HaloCAD Add-on for CAD applications*

### About this Manual

This manual provides administrators with the information required to successfully deploy HaloCAD components. It explains how to set up the HaloCAD environment, describes the overall architecture, lists the prerequisites and system requirements for each component, and offers step-by-step guidance for installation and configuration. The manual covers the HaloCAD Add-on for CAD, the HaloCAD Reader Add-on for CAD, HaloCAD for Viewers, HaloCAD for TCAI, and HaloCAD for PLM and PDM, along with detailed explanations to ensure smooth implementation and usage.

The term **HaloCAD Add-on for CAD** is a generic reference to the supported CAD applications, namely AutoCAD, Inventor, Revit, Creo, Solid Edge, NX, SOLIDWORKS, and DraftSight. Throughout this manual, any reference to this term denotes these supported CAD applications. Additionally, the HaloCAD Add-on for CAD includes a corresponding reader add-on for each of the above-listed applications, which is collectively referred to by the generic term **HaloCAD Reader Add-on for CAD**.

The term **HaloCAD for PLM** is a general reference to the supported PLM applications, namely Teamcenter, Windchill, and Autodesk Vault. Wherever this term appears in the manual, it denotes these supported PLM systems. Similarly, references to **HaloCAD for PDM** correspond to SOLIDWORKS PDM.  
This is the primary document that administrators should read before installing the HaloCAD components. After completing this, proceed with the installation and operations manuals.

### Features

1. **Business infrastructure**: HaloCAD connects effortlessly with existing infrastructure, making it simple to use and manage.

2. **CAD:**HaloCAD add-on seamlessly extends MPIP security to CAD files.

3. **Usage rights**: Applies label-based protection using Microsoft Purview Information Protection (MPIP) and user-defined custom permissions.

4. **Data security**: Sensitive information is protected persistently regardless of where it is moved, including mobile and cloud platforms.

5. **Data Access and Usage**: Policy enforcement for managing sensitive file access and usage.

   1. Policies specify who has access to sensitive files and what actions they can do with them.

   2. Furthermore, it specifies how data may be used, such as restrictions on viewing, editing, copying, printing, exporting, relabeling, or modifying the rights. Watermarks can be applied to documents that contain sensitive information.

6. **Seamless integration with PLM**: Automatically protects file downloads, decrypts files during upload, and returns them to the PLM vault.

## Quick Start Installation Summary - Standalone HaloCAD Add-on

The image below illustrates the high-level process of setting up the HaloCAD Add-on for CAD.  
![TechReference_Quick start - standalone .png](https://help.secude.com/__attachments/a_0624489f556ac096e13525dd314b42eb73c93861d436d7309f96fed3939f454a/TechReference_Quick%20start%20-%20standalone%20.png?cb=f5ead24b2b28007828631bad33621938)

*Quick start installation steps for HaloCAD Standalone Add-on*  
![TechReference_Quick Start Reader Add-on.png](https://help.secude.com/__attachments/a_b89103abd70699407a8130119feb9fe41268c91ed779886d8100b1fc4409fd3b/TechReference_Quick%20Start%20Reader%20Add-on.png?cb=e990f5d975398e57f2c86678eac3c685)

*Quick start installation steps for HaloCAD Reader Add-on*

**Reference Manuals**

The table below describes where to obtain information in the HaloCAD documentation set.  

|                                                                                **For information on**                                                                                |                   **Name of the Reference**                    |
|--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|----------------------------------------------------------------|
| 1. Prerequisites, architecture, and supported license activation methods 2. Secure installation using an encrypted JSON configuration file 3. Actions to take when a license expires | Please refer to the current manual.                            |
| HaloCAD Installation Options -- UI, Silent, and SCCM                                                                                                                                 | Refer to the Installation Manual for the add-on you purchased. |
| HaloCAD features, operations, and troubleshooting, if you face any issues                                                                                                            | Refer to the Operations Manual for the add-on you purchased.   |
| Overview of new features, resolved issues, known issues, and supported file types                                                                                                    | Refer to the Release Notes for the add-on you purchased.       |

*HaloCAD standalone add-on reference documentation*

## Quick Start Installation Summary - Integrated with PLM/PDM

The image below illustrates the high-level process of setting up the **HaloCAD Add-on for CAD** with **HaloCAD for PLM/PDM** environment.  
![TechReference_Quick start_PLM-PDM.png](https://help.secude.com/__attachments/a_c8cddfa0aa8311c6c9b22241bbd0f74b49aca9bd6f4d8682bdffb68c5d3b80a0/TechReference_Quick%20start_PLM-PDM.png?cb=f1f21476c16f52782f2d7c44f25661e8)

*Quick start installation steps for HaloCAD for PLM/PDM*

**Reference Manuals**

The table below describes where to obtain information in the HaloCAD documentation set.  

|                        **For information on**                         |                          **Name of the Reference**                          |
|-----------------------------------------------------------------------|-----------------------------------------------------------------------------|
| Step 1 -- Registering an Application in Entra ID.                     | Please refer to the current manual.                                         |
| Step 2 -- How to install HaloCAD Add-on for CAD.                      | Refer to the Installation Manual for the add-on you purchased.              |
| Step 3 -- How to install HaloENGINE.                                  | `HaloENGINE_Manual_Installation_EN_Online.pdf`                              |
| Step 4 -- How to install HaloCAD for PLM/PDM.                         | Refer to the Installation Manual for the HaloCAD for PLM/PDM you purchased. |
| Step 5 and Step 6 -- Workflow illustrating protection and decryption. | Refer to the Operations Manual for the HaloCAD for PLM/PDM you purchased.   |

*HaloCAD for PLM/PDM reference documentation*  
**About the Term "HaloENGINE Tomcat Service"**

The HaloENGINE Tomcat Service is a common component used in both the HaloENGINE and HaloCAD products. Since it was initially developed for HaloENGINE and later adopted across HaloCAD, all Tomcat instances in Secude appear under the name "HaloENGINE Tomcat Service."

## Quick Start Installation Summary - HaloCAD for Viewers

The image below illustrates the high-level process of setting up HaloCAD for Viewers.  
![TechReference_Quicl Start - Viewers.png](https://help.secude.com/__attachments/a_12ad97d51b1054fd8ce52f4db1779ff4fab38a50c495f7aafc861d464c0aa532/TechReference_Quicl%20Start%20-%20Viewers.png?cb=8eae1af140d7e0e42c619971fa5a0bf6)

*Quick start installation steps for HaloCAD for Viewers*

For HaloCAD for TCAI, follow the same Quick Start installation steps described for HaloCAD for Viewers. Refer to the HaloCAD for TCAI documentation set for additional information.

**Reference Manuals**

The table below describes where to obtain information in the HaloCAD documentation set.  

|                                                                                **For information on**                                                                                |                  **Name of the Reference**                  |
|--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|-------------------------------------------------------------|
| 1. Prerequisites, architecture, and supported license activation methods 2. Secure installation using an encrypted JSON configuration file 3. Actions to take when a license expires | Please refer to the current manual.                         |
| Installation Options -- UI, Silent, and SCCM                                                                                                                                         | `HaloCAD_Viewers_Manual_InstallationAndUsage_EN_Online.pdf` |
| Overview of new features, resolved issues, known issues, and supported file types                                                                                                    | `HaloCAD_Viewers_ReleaseNotes_EN_Online.pdf`                |

*HaloCAD* *for Viewers reference documentation*

## HaloCAD Architecture

The architecture is designed to provide secure and efficient management of CAD and PLM data through three core components: HaloCAD Add-on for CAD, HaloCAD for PLM, and the HaloENGINE.

### HaloCAD Add-on for CAD

A standalone solution that contains the HaloCAD PROTECT feature. It enables access to protected files, enforces associated privileges, and allows controlled modification of MPIP labels via direct interaction with the user.

HaloCAD Add-on for CAD leverages the Microsoft Purview Information Protection solution to provide persistent document security. During the process of creating a new CAD file, the user downloads MPIP labels using valid credentials, selects a suitable label, and applies it to the file. In the standalone add-on, no automation is available, as setting labels is done manually. Protected files can only be opened and modified by authorized users, and thus, protection remains even when multiple users access the file. The user's rights are governed by pre-established policies. The following figure shows the HaloCAD Add-on for CAD as a standalone add-on.  
![TechReference_Fullmode.png](https://help.secude.com/__attachments/a_dd553b8f4e109c3b945fe3aaf0c00758918848aace774379211fe3fdeeeee9ce/TechReference_Fullmode.png?cb=5de7b834c5831259fd3ce9a53184fccc)

*HaloCAD as a standalone add-on*

Note: When HaloCAD (standalone add-on) is integrated with HaloCAD for PLM, files are automatically protected based on predefined rules before the end user can access them.

### HaloCAD Reader Add-on for CAD

Secude offers a standalone reader add-on for CAD applications that lets you view MPIP-protected files containing sensitive data. It enforces 'read-only' privileges to all users and thus even authorized users cannot sneak sensitive information out by copying it or taking a screenshot. Additionally, it does not support the setting or modification of labels. Note: When a HaloCAD MPIP-protected file is shared with partners/suppliers, they don't need to install the HaloCAD Add-on for CAD on their machines; instead, just this simple reader add-on is sufficient. The following figure shows the HaloCAD Reader Add-on for CAD.  
![TechReference_Readermode.png](https://help.secude.com/__attachments/a_bbf5ef9fcbc5b10512a63f4c57d9c6f2cc39b8c66ca828b48c5c60b1b4f86780/TechReference_Readermode.png?cb=6f97dfb6cc11eb8a240f43c05257c24a)

*HaloCAD Reader Add-on for CAD*

### **HaloCAD for PLM**

**HaloCAD for PLM (HaloCAD for Teamcenter, HaloCAD for Windchill, and HaloCAD for Autodesk Vault)**

This solution integrates seamlessly with the PLM application, including the features of HaloCAD PROTECT and HaloCAD MONITOR, while utilizing Microsoft Purview Information Protection (MPIP), formerly Microsoft Information Protection (MIP), to provide Enterprise Digital Rights Management (EDRM) capabilities.

HaloCAD for PLM operates continuously in the background, monitoring file uploads and downloads. It connects to Microsoft Purview Information Protection to download sensitivity labels and handle file encryption and decryption.

During a file upload, it checks whether the file is already encrypted and, if so, automatically decrypts it before allowing it to be checked into the PLM Vault. Similarly, whenever a file is downloaded, HaloCAD for PLM automatically enforces protection in accordance with defined action rules, ensuring that all file operations adhere to security rules and keep data safe. It operates independently during the file check-in or upload process. However, during file check-out or download, it depends on the rules defined in the Classification Engine (HaloENGINE).  
![TechReference_HaloCAD for PLM.png](https://help.secude.com/__attachments/a_614db7c92dcedde749fb9aac4f7473d4d1e9efb03cb8de7a2aca01ac26e7d117/TechReference_HaloCAD%20for%20PLM.png?cb=0d6e3f609ae3d060a06c2d2cb11caf40)

*HaloCAD for PLM*  
**Separate Installation Requirement**

Ensure that HaloENGINE and HaloCAD for PLM are installed and configured separately on Windows servers.

**HaloENGINE**---A Java-based classification engine that implements the business logic of the architecture. It integrates with Microsoft Purview Information Protection to download sensitivity labels and make them available for configuration. HaloENGINE uses metadata to classify and organize data, and it also enforces classification schemas and action rules. All file downloads must comply with the rules defined in this engine, making it the central component of the architecture.

During file download, HaloENGINE receives relevant metadata from HaloCAD for PLM, determines the appropriate action based on the configured rules, and forwards the label and action information to HaloCAD for PLM for file processing (encryption).

**HaloCAD for PDM (HaloCAD for SOLIDWORKS PDM)**

This solution integrates HaloCAD PROTECT and MONITOR capabilities with the respective PDM application. It connects to Microsoft Purview Information Protection to download sensitivity labels and handle file encryption and decryption.

SOLIDWORKS PDM folders are actively monitored to ensure file security and compliance. When files are cut or copied from a SOLIDWORKS PDM folder to a non-SOLIDWORKS PDM folder, they are automatically intercepted and protected before reaching the destination. Conversely, when previously encrypted SOLIDWORKS application files or PDF files are copied or moved into a SOLIDWORKS PDM folder, they are seamlessly decrypted and saved for use within the environment.

**HaloENGINE**---A Java-based classification engine that implements the business logic of the architecture. As described in HaloCAD for PLM, it provides similar functionality when integrated with PDM.

All file copy/move must comply with the rules defined in this engine, making it the central component of the architecture.  
![TechReference_HaloCAD for PDM.png](https://help.secude.com/__attachments/a_1c2d7435bbd6efddc6b2f2d176e274917586fefa3b37a57fc888dab1c8673bd5/TechReference_HaloCAD%20for%20PDM.png?cb=18b66a80ae43cda05837e7c3713efbc8)

*HaloCAD for PDM*

For comprehensive details, please refer to the respective manuals as per your PLM environment:

1. If your environment is integrated with Windchill PLM, refer to the HaloCAD for Windchill Installation Manual.

2. If your environment is integrated with Teamcenter PLM, refer to the HaloCAD for Teamcenter Installation Manual.

3. If your environment is integrated with Autodesk Vault PLM, refer to the HaloCAD for Autodesk Vault Installation Manual.

4. If your environment is integrated with SOLIDWORKS PDM, refer to the HaloCAD for SOLIDWORKS PDM Installation Manual.

### HaloCAD for Viewers

HaloCAD for Viewers is a lightweight application designed to view HaloCAD-protected files in other CAD-Viewer applications with "View only" access to all users who have access to it. This application is useful for suppliers or partners who need to access HaloCAD-protected models or drawings in their environment. The high-level architecture of HaloCAD for Viewers is illustrated in the following figure.  
![TechReference_Arch of Viewers.png](https://help.secude.com/__attachments/a_5774ec68e6dee16cc09fcce17e9a6ea361e17d514f4d747cea60224568883391/TechReference_Arch%20of%20Viewers.png?cb=4adc86590e461620ae6eb174a6cf3542)

*HaloCAD for Viewers*

### HaloCAD for TCAI

HaloCAD for TCAI is a lightweight application that uses Microsoft Purview Information Protection functionality to decrypt HaloCAD-protected CAD files during bulk loading operations in Teamcenter integration with Autodesk Inventor. This enables protected Inventor files to be scanned and processed by the TCAI Bulk Loader.

The Teamcenter Integration for Autodesk Inventor (TCAI) Bulk Loader utility allows administrators to automatically import large numbers of Inventor files into Teamcenter. However, when Inventor files are protected (encrypted), the Bulk Loader cannot recognize or process them directly.

By decrypting protected files during the loading process, HaloCAD for TCAI enables the Bulk Loader to scan and load these files into Teamcenter.

HaloCAD for TCAI uses the same underlying decryption mechanism as HaloCAD for Viewers, but it is specifically designed to support bulk loading operations in the TCAI environment.  
![TechReference_HaloCAD for TCAI.png](https://help.secude.com/__attachments/a_633192d319e9084b011b475eab48b5a675076c5fa9f9667b381e5b6fe28602e2/TechReference_HaloCAD%20for%20TCAI.png?cb=23775ea43d43cd8812d96d5b1490f7bc)

*HaloCAD for TCAI*

**Microsoft Purview Information Protection**

HaloCAD seamlessly integrates with Microsoft Purview Information Protection solution to protect your sensitive documents. Microsoft Purview Information Protection is an industry-standard document security solution that enables businesses to ensure only authorized users can open protected content while also regulating what they can do with it, such as print, edit, or save. Even if sensitive data is leaked accidentally or maliciously, unauthorized parties cannot view it in clear text, thus leaving it useless.  
**Microsoft documentation**

This manual assumes that you already have a complete Microsoft Purview Information Protection setup and are familiar with using the Microsoft Purview portal and related concepts. If you are new, you can refer to Microsoft's online documentation for setup and configuration.

## Prerequisites

The prerequisites and dependencies for installing and configuring the HaloCAD add-ons are summarized in this section.

### Register an Application in Microsoft Entra ID - **Public client/native**

|-------------------|-------------------------------------------------------------------------------------------------------------------------------------|
| **Applicable to** | 1. HaloCAD Add-on for CAD 2. HaloCAD Reader Add-on for CAD 3. HaloCAD for Viewers 4. HaloCAD for TCAI 5. HaloCAD for SOLIDWORKS PDM |

This section will guide you through registering an application, obtaining the Client ID and Directory ID, and assigning permissions to the application.  
**Microsoft documentation**

Registering an application in Microsoft Entra ID establishes a trust connection between your application and the identity provider, the Microsoft identity platform.

The information in the Microsoft documentation overrides any information published in this section. For a comprehensive description, refer to Microsoft documentation.

#### Create an Application

Follow the instructions below to register an application:

1. Log in to the [Microsoft Entra admin center](https://entra.microsoft.com/) using an account that has administrator privileges.

2. If you have access to multiple tenants, click the **Settings** icon in the top menu and select the tenant for which you want to register the application from the **Directories** + **subscriptions**menu.

3. You will be directed to the homepage.

   ![0_Intial Screen.png](https://help.secude.com/__attachments/a_2d33274c381bf5ce73100cbc95702e9fb598051ba7e26575955d93e9a1c454fd/0_Intial%20Screen.png?cb=7474bc6a49931803f8de1518c0a94eca)

   *Selecting Microsoft Entra ID*
4. Click **Identity** \> **Applications** \> **App registrations**on the left of the navigation pane.

5. On the **App registrations** page, click the **New registration** page or **Register an Application** button (this button appears only if no applications have already been created).

   ![1_New application registration.png](https://help.secude.com/__attachments/a_ca291e4cfdc6bbfd8fe41a3ce5159aba60889df5a73514bf51fd535478fecd6b/1_New%20application%20registration.png?cb=5ea4d32fc9fa86b48bc627cd26dbcd0e)

   *New application registration*
6. On the**Register an application** page, enter the registration details for your application.

   ![2_Public client application details.png](https://help.secude.com/__attachments/a_1f27428ca98afed1e6a9fad696f5bc8a8cc62472ebb5664294c49dd5166550fb/2_Public%20client%20application%20details.png?cb=14ea97df2b8462fe456b3cb6a27dac4f)

   *Application details*
7. In the **Name**field, enter an appropriate application name.

8. Under **Supported account types**, select which account you would like your application to support. For detailed information on these types, please see Microsoft documentation.

   1. To target only accounts that are internal to your organization, select **Accounts in this organizational directory only**.

   2. To target only business or educational customers, select **Accounts in any organizational directory**.

   3. To target the widest set of Microsoft identities and to enable multitenancy, select **Accounts in any organizational directory and personal Microsoft accounts**.

   4. To target the widest set of Microsoft identities, select **Personal Microsoft account only**.

   5. Under **Redirect URI** : Select **Public client/native (mobile \& desktop)** , and then type a valid redirect URI for your application. For example, `https://localhost`.

   6. When finished, click **Register**.

9. The home page of the new application is created and displayed.

   ![3_Application ID and Tenant ID.png](https://help.secude.com/__attachments/a_e2a75de6ced71fb999fa296a9a6a5413a9370dfff85011a01ba81227c0b35b6e/3_Application%20ID%20and%20Tenant%20ID.png?cb=2d09547b6b78d6efbbceb666e67608ee)

   *Application ID and Tenant ID*
10. Once registration is complete, the following values are shown on the portal. To copy and save the ID value in a text editor, hover your cursor over it and click the **Copy to clipboard**icon.

    1. **Application ID** -- also known as **Client ID**.

    2. **Directory ID** -- also known as **Tenant ID**.

**Save the authentication parameters**

Open a text editor (such as Notepad) and copy the values for the Application (client) ID, Directory (tenant) ID, and Redirect URI. Save these details for initializing the HaloCAD Add-on. Note that the Directory (tenant) ID is required only for single-tenant applications.

#### Add Required Permissions

To protect content using the MIP SDK, you need to provide the following API permission(s) for the created application ID.

1. In the sidebar of the new application page, select **API permissions** . The **API permissions** page for the new application registration will appear.

2. Click **Add a permission** button. The **Request API permissions** page will appear.

3. Under the **Select an API**setting, select APIs my organization uses. A list appears, containing the applications in your directory that expose APIs.

4. Type in the search box or scroll to find the required API that is mentioned in the table below, "Required Permissions".

5. For example, type **Microsoft Information Protection Sync Service**. You can see the API listed as shown in the figure below:

   ![4_API selection.png](https://help.secude.com/__attachments/a_51394e2e21e2abc5a8194b73d8c37aa4ec436cd6f1a3f3d099d137384bc8e9c6/4_API%20selection.png?cb=60328777c1eb9f0880eb1267645ecb5d)

   *Searching for permissions*
6. Now, click on the displayed API. You can see two permissions on the page − **Delegated permissions** and **Application permissions**.

7. Click the **Delegated permissions** button and then, under the **Permission**section, select the check box against "Read all unified policies a user has access to".

   ![5_Adding permission.png](https://help.secude.com/__attachments/a_64d3ec249e14533ed47d10d19a710ea14dcab6adc5791c0c82f6c7817f664369/5_Adding%20permission.png?cb=dbc6f87482218efd202793dde05cdce6)

   *Adding permission*
8. Click **Add permissions**. Repeat the steps outlined above to add the other required permissions listed in the table below.

9. You will return to the API permissions page, where the permissions have been saved and added to the table. Please note that administrator consent is not necessary for **Delegated permissions**.

   ![6_Required API Permissions.png](https://help.secude.com/__attachments/a_c5bf802cac7cfb8aa34dd660a525c3544d2bcd4cb37ad652ade56b3945efbcb8/6_Required%20API%20Permissions.png?cb=66ea7fcb1dd8aa1087252334a951ab69)

   *API Required permissions*
10. The following table lists the required permissions.

|                        **API / Permission name**                        |     **Display Name**      | **Type**  |                     **Description**                      |
|-------------------------------------------------------------------------|---------------------------|-----------|----------------------------------------------------------|
| Azure Rights Management Services (Microsoft Rights Management Services) | `User_impersonation`      | Delegated | Create and access protected content for users            |
| Microsoft Graph                                                         | `User.Read`               | Delegated | Sign in and read user profile (will be added by default) |
| Microsoft Information Protection Sync Service                           | `UnifiedPolicy.User.Read` | Delegated | Read all unified policies a user has access to.          |

*Required permissions*

### **Register an Application in Microsoft Entra ID - Web**

|-------------------|----------------------------------------------------------------------------------|
| **Applicable to** | 1. HaloCAD for Teamcenter 2. HaloCAD for Windchill 3. HaloCAD for Autodesk Vault |

Creating an application in Microsoft Entra ID is similar to the steps in the previous section. However, for HaloCAD for PLM, some variations apply.

1. Under **Redirect URI** , select **Web**.

2. Add the permissions listed in the following table.

3. Click **Grant admin consent for your** *\<company\>*.

4. When the confirmation dialog appears, select **Yes** to approve.

5. After the consent is granted, the **Status** column changes to **Granted**.

|                        **API / Permission Name**                        |      **Display Name**       |  **Type**   |                                                         **Description**                                                          |
|-------------------------------------------------------------------------|-----------------------------|-------------|----------------------------------------------------------------------------------------------------------------------------------|
| Microsoft Graph                                                         | `User.Read`                 | Delegated   | Sign in and read the user profile. This API permission is added by default, but it is not used by the HaloENGINE Tomcat Service. |
| Azure Rights Management Services (Microsoft Rights Management Services) | `Content.DelegatedWriter`   | Application | Create protected content on behalf of a user                                                                                     |
| Azure Rights Management Services (Microsoft Rights Management Services) | `Content.Writer`            | Application | Create protected content                                                                                                         |
| Microsoft Information Protection Sync Service                           | `UnifiedPolicy.Tenant.Read` | Application | Read all unified policies of the tenant                                                                                          |

*Required permissions #1*

#### **Additional Permission (Only for Decryption)**

The permissions mentioned above are adequate for applying the MPIP label to a file with the owner as SPN (Service Principal Name) ID or any user email ID. Additionally, the HaloENGINE Tomcat Service requires the following superuser privilege for the decryption function when the owner is not as SPN.  

|                        **API / Permission Name**                        |  **Display Name**   |  **Type**   |                        **Description**                         |
|-------------------------------------------------------------------------|---------------------|-------------|----------------------------------------------------------------|
| Azure Rights Management Services (Microsoft Rights Management Services) | `Content.SuperUser` | Application | Read all protected content for this tenant in the Azure portal |

*Required permissions #2*

#### Upload the Certificate in the Azure Portal

The HaloENGINE Tomcat Service relies on certificate-based authentication to access MPIP services. Therefore, you must enter your certificate information in the registered application before proceeding with the configuration.

Prerequisites:

1. **Certificate**:

   1. Ensure that you have a valid certificate containing the following key properties: `-KeyExportPolicy Exportable` and `-KeySpec Signature`.

   2. The certificate can also be self-signed. Note: As a best practice and for security reasons, use a self-signed certificate only in a test environment. It is not recommended for production environments.

2. **Local Computer** certificate store: The certificate required for MPIP authentication must be installed in the Local Computer certificate store, along with the Root CA and Intermediate CA certificates.

   1. If the certificate is CA-signed, install all related certificates in their respective stores (Root, Intermediate, and Personal).

   2. If the certificate is self-signed, install it in both the Trusted Root Certification Authorities and Personal stores of the Local Computer.

To upload the public key of the certificate, follow the steps below:

1. In the sidebar of the new application page, select **Certificate \& secrets**.

2. Under the **Certificate** section, click **Upload certificate** . The **Upload certificate**dialog appears as shown in the figure below:

   ![Upload certificate_1.png](https://help.secude.com/__attachments/a_4189abcbf165a397cfba3b432501cbfd05efa5aac26b6fd86d2df101d32e28ca/Upload%20certificate_1.png?cb=9b028533c34b642a22254eac5af1b8b2)

   *Upload certificate #1*
3. Click on the folder icon to select the certificate and click **Open** . For illustration purposes, the file `DESKTOP001.cer` is used.

4. Now, click **Add**. The certificate will get uploaded, and its thumbprint will be displayed on the page as shown in the figure below:

   ![Upload certificate_2.png](https://help.secude.com/__attachments/a_08e5d8846bed6ef36dd43d70f6d6acb8eda46464b493b806735d5ae376526ddc/Upload%20certificate_2.png?cb=0623c0f3126f69195dfa9f8b7d86687e)

   *Upload certificate #2*

The following table lists the Microsoft Entra ID application types that must be registered when using HaloCAD Add-on for CAD, HaloCAD for Viewer, HaloENGINE, or HaloCAD for PLM.  

|              **Component and Combination**               |           **Application Type**           |                                                                                                                 **Configuration Guideline**                                                                                                                  |
|----------------------------------------------------------|------------------------------------------|--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| HaloCAD Add-on for CAD and HaloCAD Reader Add-on for CAD | Public client/native (mobile \& desktop) | Create a new Microsoft Entra ID application in your tenant for the HaloCAD Add-on for CAD installation and use the same application details for the Reader Add-on. The Reader Add-on cannot open protected files if the tenant details do not match.         |
| HaloCAD for Viewer                                       | Public client/native (mobile \& desktop) | Create a new Microsoft Entra ID application in your tenant for HaloCAD for Viewer installation. Alternatively, if you already have an existing HaloCAD application, use the same app details and ensure that the client type is set to Public client/native. |
| HaloCAD for TCAI                                         | Public client/native (mobile \& desktop) | Create a new Microsoft Entra ID application in your tenant for HaloCAD for Viewer installation. Alternatively, if you already have an existing HaloCAD application, use the same app details and ensure that the client type is set to Public client/native. |
| HaloCAD for SOLIDWORKS PDM                               | Public client/native (mobile \& desktop) | Create a new Microsoft Entra ID application in your tenant for the HaloCAD for SOLIDWORKS PDM installation. When used in combination with HaloENGINE, ensure that the same Directory (Tenant) ID is used. Mismatched IDs will cause configuration errors.    |
| HaloENGINE                                               | Web                                      | Create a new Microsoft Entra ID application in your tenant for the HaloENGINE. For more details, please refer to the HaloENGINE Installation Manual.                                                                                                         |
| HaloCAD for PLM and HaloENGINE                           | Web                                      | Both use a Web-type application, so the same application details can be used during installation.                                                                                                                                                            |

*HaloCAD and Application Type*

### Create and Configure the Sensitivity Labels

|-------------------|----------------------------------------------------------------------------------------------------------------------------------|
| **Applicable to** | 1. HaloCAD Add-on for CAD 2. HaloCAD Reader for Add-on 3. HaloCAD for PLM/PDM (Teamcenter, Windchill, Vault, and SOLIDWORKS PDM) |

As an administrator, you can create, configure, and publish sensitivity labels for various levels of content sensitivity based on your organization's classification taxonomy. Use names or terms that are familiar to your users. Consider starting with label names like Personal, Public, General, Confidential, and Highly Confidential if you don't already have a taxonomy in place. For more details, please refer to Microsoft online documentation.

### Office 365 Subscription Details

|-------------------|---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| **Applicable to** | 1. HaloCAD Add-on for CAD 2. HaloCAD Reader Add-on for CAD 3. HaloCAD for Viewers 4. HaloCAD for TCAI 5. HaloCAD for PLM/PDM (Teamcenter, Windchill, Vault, and SOLIDWORKS PDM) |

1. Fully configured Microsoft Purview Information Protection.

2. An Azure subscription is required to use Azure RMS and the MPIP functionality.

3. A working Microsoft Entra ID service must be available.

4. Transport Layer Security (TLS) 1.2 or higher must be enabled to ensure the use of cryptographically secure protocols at all client workstations. Please refer to the section "[Enable Support for TLS 1.2 at the Client Workstation for Microsoft Entra ID](https://help.secude.com/halocad-add-on-for-autodesk-revit/2.4/technical-reference-manual.md#TLS)".

5. To avail the revoke access feature, the user should be assigned to the Microsoft Purview Information Protection Premium P1/P2 license. (Not required for the reader and viewer add-on)

6. Audit logging: Your Azure subscription must include Log Analytics on the same tenant as Microsoft Entra ID.

### **Recommended URLs, Addresses, and Ports for MPIP**

|-------------------|-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| **Applicable to** | 1. HaloCAD Add-on for CAD 2. HaloCAD Reader for Add-on 3. HaloCAD for Viewers 4. HaloCAD for TCAI 5. HaloCAD for PLM/PDM (Teamcenter, Windchill, Vault, and SOLIDWORKS PDM) |

MIP SDK doesn't support the use of authenticated proxies. So, make sure you set the Microsoft 365 endpoints to bypass the proxy. View a list of endpoints at "[Microsoft Online Documentation](https://docs.microsoft.com/en-us/microsoft-365/enterprise/urls-and-ip-address-ranges?view=o365-worldwide)". However, Microsoft recommends the following:  

|                                                                                                                                    **Addresses**                                                                                                                                     |                   **Ports**                    |
|--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|------------------------------------------------|
| `*.protection.outlook.com` `40.92.0.0/15`, `40.107.0.0/16`, `52.100.0.0/14`, `52.238.78.88/32`, `104.47.0.0/17`, `2a01:111:f403::/48`                                                                                                                                                | TCP 443                                        |
| `*.aadrm.com`, `*.azurerms.com`, `*.informationprotection.azure.com`, `ecn.dev.virtualearth.net`, `informationprotection.hosting.portal.azure.net`, `*.office.com` (add `substrate.office.com` if you don't want to add all sub-domains), `crl3.digicert.com`, `crl4.digicert.com` . | TCP 443, 80                                    |
| **For event logging** `*.events.data.microsoft.com`                                                                                                                                                                                                                                  | TCP 443                                        |
| **National Cloud**                                                                                                                                                                                                                                                                   | **Microsoft Entra ID authentication endpoint** |
| Microsoft Entra ID for the US Government                                                                                                                                                                                                                                             | `https://login.microsoftonline.us`             |
| Microsoft Entra ID (global service) For details on Microsoft Entra ID endpoints, please refer to "[++Microsoft Online Documentation++](https://docs.microsoft.com/en-us/azure/active-directory/develop/authentication-national-cloud#azure-ad-authentication-endpoints)".            | `https://login.microsoftonline.com`            |

*Recommended endpoints*

**Secude License Manager for HaloCAD**  

|-------------------|------------------------------------------------------------|
| **Applicable to** | 1. HaloCAD Add-on for CAD 2. HaloCAD Reader Add-on for CAD |

To communicate with Secude License Manager for HaloCAD, the following URL and port must be whitelisted in the customer's proxy:  

|                              **Address**                              | **Port** |
|-----------------------------------------------------------------------|----------|
| License API - [api.licensespring.com](https://api.licensespring.com/) | TCP 443  |

*Recommended license manager endpoint*

### Enable Support for TLS 1.2 at the Client Workstation for Microsoft Entra ID

|-------------------|---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| **Applicable to** | 1. HaloCAD Add-on for CAD 2. HaloCAD Reader Add-on for CAD 3. HaloCAD for Viewers 4. HaloCAD for TCAI 5. HaloCAD for PLM/PDM (Teamcenter, Windchill, Vault, and SOLIDWORKS PDM) |

To improve the security posture of the tenant and to remain in compliance with industry standards, Microsoft Entra ID stopped supporting the following Transport Layer Security (TLS) protocols and ciphers:

1. TLS 1.1

2. TLS 1.0

3. 3DES cipher suite (TLS_RSA_WITH_3DES_EDE_CBC_SHA)

In order for the HaloCAD for CAD add-on to be able to authenticate to Microsoft Entra ID, TLS 1.2 must be activated on the respective client workstation. Please see this [Microsoft article to enable TLS 1.2](https://learn.microsoft.com/en-us/troubleshoot/azure/active-directory/enable-support-tls-environment?tabs=azure-monitor).  
**Microsoft documentation**

The information in the Microsoft documentation overrides any information published in this section.

Secude is not liable for changes to the content of this section because it was extracted from the Microsoft article at the time when the HaloCAD manual was prepared. Do check the most recent updates in this regard from the Microsoft documentation.

In summary, the following steps must be performed:

1. Update the Windows Operating System

2. Update .NET Framework

3. Set the following registry settings:

| **S.No** |                              **Windows Registry**                              |                                    **Values**                                     |
|----------|--------------------------------------------------------------------------------|-----------------------------------------------------------------------------------|
| 1        | `[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\.NETFramework\v4.0.30319]` | `"SystemDefaultTlsVersions"=dword:00000001` `"SchUseStrongCrypto"=dword:00000001` |
| 2        | `[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\v4.0.30319]`             | `"SystemDefaultTlsVersions"=dword:00000001` `"SchUseStrongCrypto"=dword:00000001` |

*Registry entries*

## License Administration

|-------------------|------------------------------------------------------------|
| **Applicable to** | 1. HaloCAD Add-on for CAD 2. HaloCAD Reader Add-on for CAD |

HaloCAD uses a key-based license to control application features. Obtain the license key from Secude Support before installing HaloCAD.  
This document does not cover all the specifics of purchasing a license. Please contact Secude's representative for additional details.

The following methods are available to activate the license in HaloCAD.

1. **Tool-based automatic initialization and license activation** : This method generates an encrypted configuration file that contains the license key and Microsoft Entra ID application details. Using this file, the installer automatically completes the installation, application initialization, and license activation. For more information, refer to the "[Secure Installation](https://help.secude.com/halocad-add-on-for-autodesk-revit/2.4/technical-reference-manual.md#secure)" section.

2. **UI-based manual license activation** : This method provides a straightforward installation process without automatic license activation. After launching the CAD application, the administrator must manually activate the license by entering the license key in the HaloCAD license screen. For more information, refer to the "[UI-based Manual License Activation](https://help.secude.com/halocad-add-on-for-autodesk-revit/2.4/technical-reference-manual.md#ui)" section.

3. **License activation in silent mode:** This method uses an encrypted configuration file to automatically initialize the application and activate the license during installation. For more details, refer to the **Silent Mode** section of the HaloCAD Installation Manual provided with your purchased application.

4. **License activation via System Center Configuration Manager (SCCM)**: For organization-wide deployment and activation of the HaloCAD add-on, an encrypted configuration file containing the license key information and Microsoft Entra ID application details is used together with the installer. For additional information on SCCM, please refer to the HaloCAD Installation Manual.

The following is a high-level diagram that illustrates license activation.  
![TechReference_Activation methods.png](https://help.secude.com/__attachments/a_9d48989c37c649ffa7f221679282cbcd8907755dc0f7703f84d3b5be4b049069/TechReference_Activation%20methods.png?cb=4db4bb96e8c6129e4c18ec2252367813)

*License activation*

### **Secure Installation (Recommended)**

|-------------------|-------------------------------------------------------------------------------------------------------------------------------------|
| **Applicable to** | 1. HaloCAD Add-on for CAD 2. HaloCAD Reader Add-on for CAD 3. HaloCAD for Viewers 4. HaloCAD for TCAI 5. HaloCAD for SOLIDWORKS PDM |

As a best practice, application secrets should not be shared with end users, third parties, or trusted vendors. However, to avail of HaloCAD features (standard add-on and reader add-on), it is necessary to share such sensitive information for a successful installation.

To overcome this challenge, Secude offers an admin utility tool that can write and encrypt data, including Microsoft Entra ID application details (Application ID, Tenant ID, and Redirect URI), Cloud type details, and a license key in an encrypted configuration file. It uses the RSA algorithm for cryptography, allowing only the HaloCAD installer to access the configuration file with the private key during the initialization process, effectively masking the Initialization screen from the user.

An administrator can create an encrypted JSON file using this admin tool and share it with internal/external parties without disclosing the original tenant details.

**HaloCAD Admin Utility Tool**

The HaloCAD product package comprises an additional component---`hc.admintool.exe`.

**Prerequisites**: Before executing the admin tool, make sure you have the necessary information.

1. Microsoft Entra ID application details for initialization

2. Cloud type details

3. A license key

   Note: A license key is not required for HaloCAD for Viewers and HaloCAD for TCAI.

**How to Encrypt the Configuration File**

1. From the product package, move the **admintool** folder to your preferred location. For example, `C:\Users\superdocs\Desktop\admintool`.

2. Open the Command Prompt with elevated rights (Run as Administrator).

3. Navigate to the directory of the **admintool** folder and type `hc.admintool.exe` and press **Enter**.

   ![Admin tool Commands.png](https://help.secude.com/__attachments/a_f5ba41621d735a2712710eace4f1ffd6c6719cdf65c58e708f1e2a6349452341/Admin%20tool%20Commands.png?cb=1a46b89cd30b48fb1baa0e771e3e253f)

   *Admin tool with help command*
4. Enter the required details. For example,

   **Cloud type: Commercial** - `hc.admintool.exe v6ca776-c74e-437d-98ef-662ecb5751tt https://localhost 9c1cfc28-1ec6-44ea-bec6-e3492ef0cd16 B27N-CMTO-LWGH-AKEQ Commercial`

   **Cloud type: US_DoD** - `hc.admintool.exe v6ca776-c74e-437d-98ef-662ecb5751tt https://localhost 9c1cfc28-1ec6-44ea-bec6-e3492ef0cd16 B27N-CMTO-LWGH-AKEQ US_DoD`

   **Cloud type: Custom** - `hc.admintool.exe v6ca776-c74e-437d-98ef-662ecb5751tt https://localhost 9c1cfc28-1ec6-44ea-bec6-e3492ef0cd16 B27N-CMTO-LWGH-AKEQ Custom https://api.aadrm.com https://dataservice.protection.outlook.com`

5. The output window will now appear as follows:

   ![Custom_Admin tool output.png](https://help.secude.com/__attachments/a_84a85826383d6e8b3d8da99b340966abb96da4a6c30616a3ddc5b9cca560d619/Custom_Admin%20tool%20output.png?cb=d0c0fde036cd75475504c21aa54dac5b)

   *Admin tool displaying the output*
6. **HaloCAD add-on for Creo**: The following help commands are specific to the HaloCAD add-on for Creo.

   ![Creo admin tool.jpg](https://help.secude.com/__attachments/a_637e170c54411fe08a98a9cd0289470f9430fa2c91f811c0b802a5439f80688d/Creo%20admin%20tool.jpg?cb=0251084f955bb62a73353c12ecc6fa2b)

   *Admin tool with help command* *for Creo add-on*  
   ![Admin tool - output-Creo ECTR.png](https://help.secude.com/__attachments/a_1931d08c9c88c227849370e2b6f2530f1b4bf65a25a04aabb774f3c133b449f7/Admin%20tool%20-%20output-Creo%20ECTR.png?cb=53dc5c95b7a1f6b9461aaf266f14ce4f)

   *Admin tool displaying the output with ECTR integration (only for Creo add-on)*
7. **HaloCAD for SOLIDWORKS PDM**: The following help commands are specific to HaloCAD for SOLIDWORKS PDM.

   ![Admin tool output (SWPDM).png](https://help.secude.com/__attachments/a_7fd5e659440fee97379208545891fd4a16a3b81cba101a9b719befe30b75b0a0/Admin%20tool%20output%20(SWPDM).png?cb=5e986a9c43bd90f71bd8c85c932bc538)

   *Admin tool displaying the output for SOLIDWORKS PDM*
8. **HaloCAD for Viewers and TCAI**: The following help commands are specific to HaloCAD for Viewers and TCAI.

   ![Admin tool displaying the output for HaloCAD for Viewers and TCAI.png](https://help.secude.com/__attachments/a_cca85500728d2be202a92f892166821a5640d0b6a96e9c3071471ab4057d49fd/Admin%20tool%20displaying%20the%20output%20for%20HaloCAD%20for%20Viewers%20and%20TCAI.png?cb=7d27e5050516ef77de8ed96dcd909c75)

   *Admin tool displaying the output for Viewers and TCAI*

**Result**:

* The `hc.conf.json` file will be replaced by an encrypted file named `hc.conf.enc`.

* You can now share the configuration file with external users. With this file, users can install the HaloCAD add-on on their workstations seamlessly, without requiring any additional configuration details.

* Configuration files created with earlier releases are not supported. Always use the admin tool included in the installation package to generate a new configuration file.

**Next step**

1. Place the encrypted file `hc.conf.enc` in the same directory as the HaloCAD installer you have purchased.

2. To start the interactive installation, double-click the installer and follow the steps provided in the Installation Manual for your purchased add-on.

### UI-based Manual License Activation

|-------------------|--------------------------------------------------------|
| **Applicable to** | 1. HaloCAD Add-on for CAD 2. HaloCAD Reader for Add-on |

This section describes how to activate a license using the HaloCAD user interface. Note: If you encounter any issues while activating the license, please refer to the "Troubleshooting" chapter in the Operations Manual.

Prerequisite: Ensure that the HaloCAD installation is complete by following the instructions provided in the Installation Manual.

1. Open the CAD application for which the add-on was purchased.

2. HaloCAD programmatically sends a license validation request to Secude's License Manager, and the following warning message appears:

   ![HALOCAD License warning message.png](https://help.secude.com/__attachments/a_dcd56b43dcaf0f60e0e0dec8bef82a8f5b03a729502238af9e1d4335d6bf1f9c/HALOCAD%20License%20warning%20message.png?cb=3bff119b979098a8e9ccd558802b5da8)

   *HaloCAD license warning message*
3. Click **OK**.

4. Go to the **HaloCAD** tab and click **About** to see the status of your license. You will see **None**on the screen, indicating that the license has not yet been enabled.

   ![License status - None -About Screen.png](https://help.secude.com/__attachments/a_c9a89ca23b5ea63d8cf7ef2c162bf8390b0ae75b4a1fb4663f6d34a4de1a7594/License%20status%20-%20None%20-About%20Screen.png?cb=deb860ef70b4b568263d0c199eefdca3)

   *License Status: None*
5. Click **Activate**.

6. The *HaloCAD License Activation* screen will appear.

   ![HALOCAD Activation Screen.png](https://help.secude.com/__attachments/a_e3e14f724fa27ef4b217693a087ee27d7986bf8143e42d0f897b00b356a4f079/HALOCAD%20Activation%20Screen.png?cb=acd5c6bf499586a88f83eaa7cfbf6a15)

   *HaloCAD activation screen*
7. Enter the license key for the standard add-on for protection. Note: Ensure you enter the license key provided specifically for the reader add-on when using it. Interchanging license keys results in activation failure.

8. Click **Activate**.

**Result**:

* You will receive the following confirmation message:

  ![Activation success message.png](https://help.secude.com/__attachments/a_eca9ae783be6fd0eb312ebda0f776908bbcbdff48533d7b88af12b30e3c61a2c/Activation%20success%20message.png?cb=c479100ffb0eb6c50f18afba55116969)

  *Activation success message*
* Click **OK**.

* As a result, you will see **Active** on the screen, indicating that the license has been activated.

  ![License status.png](https://help.secude.com/__attachments/a_94b7d26d1ec804c9515e8aa6201a5d342b2fdfcbc4ca8b2be804a7c7ecde8212/License%20status.png?cb=cfa6e519985f240fe1df3f9523829bc0)

  *License Status: Active*

**Related tasks**:

* If you click the pencil icon (**Click to change label** ) to label the file, the Rights Management Service prompts you to sign in. Click **OK**, and then enter your credentials.

* After successful authentication, the labels can be retrieved from Microsoft Purview Information Protection, and the HaloCAD Ribbon is activated. For more details, please refer to the Operations Manual.

### **License Expiration**

|-------------------|------------------------------------------------------------|
| **Applicable to** | 1. HaloCAD Add-on for CAD 2. HaloCAD Reader Add-on for CAD |

HaloCAD licenses are valid only until the specified expiration date. After the license expires, launching the CAD application will display a warning message stating *"The license is invalid."* After clicking **OK** , another message will appear stating *"User has no valid license. Please contact your administrator."* To continue using the application, a new valid license must be obtained and activated.

Prerequisite: Before reactivating it, ensure that you have a new license key from Secude.

**Option 1** **- Using the Admin Tool (Automatic Activation)**

1. Run the admin tool with the new license key, as explained in the section "[How to Encrypt the Configuration File](https://help.secude.com/halocad-add-on-for-autodesk-revit/2.4/technical-reference-manual.md#admintool)".

2. Navigate to the configuration directory containing the old `hc.conf.enc` file and replace it with the one created in the previous step.

3. Restart the application.

**Result**:

* The HaloCAD license key is now automatically activated.

* You can start protecting CAD files.

**Option 2 - Using the About UI (Manual Activation)**

1. Open the CAD application.

2. Go to the **HaloCAD** tab and click **About**.

3. Click **Activate**.

4. Enter the new key that Secude has provided.

**Result**:

* The HaloCAD license key is now manually activated.

* You can start protecting CAD files.

## Appendix

**Third-Party Libraries**

Third-party software/code is included or bundled with Secude's products according to its appropriate license. Secude conducts testing to ensure that third-party products are compatible with and perform as intended with Secude applications.  

|-------------------|------------------------------------------------------------|
| **Applicable to** | 1. HaloCAD Add-on for CAD 2. HaloCAD Reader Add-on for CAD |

The third-party libraries and dependencies used by the HaloCAD Add-on for CAD are shown in the table below.  

|   **Library**    |          **Version**           |                                                             **Source Code**                                                              |                                       **License Link**                                       |
|------------------|--------------------------------|------------------------------------------------------------------------------------------------------------------------------------------|----------------------------------------------------------------------------------------------|
| Mhook            | 2.5.1                          | <https://github.com/apriorit/mhook>                                                                                                      | <https://github.com/apriorit/mhook#license>                                                  |
| Protobuf Library | 3.15.6                         | <https://github.com/protocolbuffers/protobuf>                                                                                            | <https://github.com/protocolbuffers/protobuf/blob/master/LICENSE>                            |
| OpenSSL          | 3.2                            | <https://github.com/openssl>                                                                                                             | <https://github.com/openssl/openssl/blob/master/LICENSE.txt>                                 |
| Rapidxml         | 1.13                           | [https://sourceforge.net/projects/rapidxml/files/latest/download](https://sourceforge.net/projects/rapidxml/files/latest/download%C2%A0) | <http://rapidxml.sourceforge.net/license.txt>                                                |
| JSON Parser      | 3.11.3                         | <https://github.com/nlohmann/json>                                                                                                       | <https://github.com/nlohmann/json/blob/develop/LICENSE.MIT>                                  |
| MSAL             | 4.72.1.0                       | <https://github.com/AzureAD/microsoft-authentication-library-for-dotnet>                                                                 | <https://github.com/AzureAD/microsoft-authentication-library-for-dotnet/blob/master/LICENSE> |
| ConfuserEx       | 1.0.0.0                        | <https://github.com/yck1509/ConfuserEx>                                                                                                  | <https://github.com/yck1509/ConfuserEx/blob/master/LICENSE>                                  |
| WTL              | 9.0.4140                       | <https://www.nuget.org/packages/wtl/9.0.4140>                                                                                            | <https://opensource.org/licenses/cpl1.0.txt>                                                 |
| MIP SDK          | 1.18.103 Creo and NX: 1.16.126 | <https://learn.microsoft.com/en-us/information-protection/develop/version-release-history>                                               | <https://docs.microsoft.com/en-us/information-protection/develop/>                           |
| Licensespring    | 7.40.0                         | -                                                                                                                                        | -                                                                                            |

*Third-party libraries*

The third-party libraries and dependencies used by HaloCAD for Viewers, HaloCAD for TCAI, HaloENGINE, HaloCAD for Teamcenter PLM, HaloCAD for Windchill PLM, HaloCAD for Autodesk Vault PLM, and HaloCAD for SOLIDWORKS PDM are listed in its Installation Manual.

---
version: "2.4"
language: "en"
---
# HaloCAD Add-on for Dassault Systemes SOLIDWORKS

## HaloCAD Add-on for Dassault Systemes SOLIDWORKS

This page provides a complete collection of HaloCAD Add-on for Dassault Systemes SOLIDWORKS documentation.

### Documentation

*

  #### [Technical Reference Manual](https://help.secude.com/halocad-add-on-for-dassault-systemes-solidworks/2.4/technical-reference-manual.md)

#### [Installation Manual](https://help.secude.com/halocad-add-on-for-dassault-systemes-solidworks/2.4/sw-installation-manual.md)

*

  #### [Operations Manual](https://help.secude.com/halocad-add-on-for-dassault-systemes-solidworks/2.4/sw-operations-manual.md)

*

  #### [Release Notes](https://help.secude.com/halocad-add-on-for-dassault-systemes-solidworks/2.4/sw-release-notes.md)

---
version: "2.4"
language: "en"
---
# Appendix

This section provides supplemental information.  
**Installer Version Requirement**

When uninstalling the HaloCAD add-on, use the installer for the currently installed version, whether you run it by double-clicking the installer or from the command line. Using a different installer version may result in errors.

## Uninstalling the HaloCAD Add-on for SOLIDWORKS

When you no longer use the add-on, you may uninstall the application. Uninstalling removes all files and registry settings that were added to your computer during the initial installation.

**Method #1**

1. Click **Start** menu \> go to **Control Panel** \> **Programs** \>**Programs and Features** \> **Uninstall a Program** \>select**HaloCAD Add-on for SOLIDWORKS** application from the list \> right-click and select **Uninstall** option or double-click on the installer `HaloCAD_SOLIDWORKS_Setup.exe` file.

2. Depending on your Windows security settings, you may get a security warning as "*Do you want to allow the following program to make changes to this computer* ?". If you get this security warning, click the "**Yes**" button to confirm that you want to uninstall the add-on.

3. The HaloCAD installer checks the current user session for any supported CAD applications running in the background and, if any are detected, displays the following message prompting you to close them before continuing with the uninstallation.

   ![Uninstall message #1.png](https://help.secude.com/__attachments/a_7db7caeac9f32fc974c9d9821e26f861389056f3255a8444b404209bf01b0241/Uninstall%20message%20%231.png?cb=a2aee89b5524621705edb6305d81c10c)

   *Uninstall message #1*
4. Click **OK** and close all HaloCAD-supported CAD applications.

5. Redo [Step 1](https://help.secude.com/halocad-add-on-for-dassault-systemes-solidworks/2.4/sw-appendix.md#Step1), and the following confirmation message appears.

   ![Uninstall message #2.png](https://help.secude.com/__attachments/a_f7b00c555065d48610412fd2b5e3388d47dcb3914cc966e612bc920ab8d3e95c/Uninstall%20message%20%232.png?cb=788a4becb55c7815be7e6be4d441c3be)

   *Uninstall Message #2*
6. Click **Yes** to confirm the uninstallation of HaloCAD from your computer.

7. When prompted with the following message, click **Yes** to delete the identity of the currently logged-in user from the ongoing session(`%AppData%\Roaming\Secude\HaloCAD\SOLIDWORKS`), or **No**to proceed with the uninstallation without removing the identity. This prompt does not appear if no HaloCAD session has been initiated.

   ![Uninstall message #3.png](https://help.secude.com/__attachments/a_b0feed3df81f6a7c4336984bbd5037cdd2d60f124c0c24a927181cf621f41825/Uninstall%20message%20%233.png?cb=b8f0840ed438745d2dace33c4203b9c8)

   *Uninstall message #3*
8. The HaloCAD add-on has been uninstalled successfully. Click **OK**to close the dialog box.

   ![Uninstall message #4.png](https://help.secude.com/__attachments/a_1f6476893d2a5262c0a97c1912dda4c273a35738a219a27217524c90a2f25969/Uninstall%20message%20%234.png?cb=386f411d99837aac0ebf06610abe8fad)

   *Uninstall message #4*

**Method #2**

The add-on can be removed using the command line, as illustrated in the sample below.

1. Open a command prompt.

2. Navigate to the add-on installer's directory.

   1. **Option 1** : uninstall without deleting the identity of the currently logged-in user`HaloCAD_SOLIDWORKS_Setup.exe -uninstall`

   2. **Option 2** : uninstall deleting the identity of the currently logged-in user `HaloCAD_SOLIDWORKS_Setup.exe -uninstall -clearcache <yes>`

3. The uninstalling process is complete.

## Uninstalling the HaloCAD Reader Add-on for SOLIDWORKS

Uninstalling reader add-on is also similar to that of the full version.

**Method #1**

1. Click **Start** menu \> go to **Control Panel** \> **Programs** \>**Programs and Features** \> **Uninstall a Program** \>select**HaloCAD Reader Add-on for SOLIDWORKS** application from the list \> right-click and select **Uninstall** optionor double-click on the installer `HaloCAD_Reader_SOLIDWORKS_Setup.exe` file.

2. The uninstallation process for the Reader version is similar to that of the Full version; refer to the above section and follow the on-screen instructions to complete the process.

**Method #2**

The add-on can be removed using the command line, as illustrated in the sample below.

1. Open a command prompt.

2. Navigate to the add-on installer's directory.

   1. **Option 1** : uninstall without deleting the identity of the currently logged-in user `HaloCAD_Reader_SOLIDWORKS_Setup.exe -uninstall`

   2. **Option 2** : uninstall deleting the identity of the currently logged-in user `HaloCAD_Reader_SOLIDWORKS_Setup.exe -uninstall -clearcache <yes>`

3. The uninstalling process is complete.

---
version: "2.4"
language: "en"
---
# Installation Manual

## About this Manual

This manual walks you through the process of installing and configuring the following HaloCAD add-ons:

1. HaloCAD Add-on for SOLIDWORKS

2. HaloCAD Reader Add-on for SOLIDWORKS

**Reference**

All technical manuals are included with the product package you have purchased.

Administrators should first read the Technical Reference Manual to understand the add-on's architecture, learn about the prerequisites, and activate a license key. They should also refer to the Release Notes to learn about the supported CAD applications before following the instructions in this document.

---
version: "2.4"
language: "en"
---
# Installing the HaloCAD Add-on for SOLIDWORKS

This chapter describes how to install and configure the HaloCAD Add-on for SOLIDWORKS. This manual just briefly explains steps 1-3, which cover the prerequisites, obtaining the licensing key, and creating an encrypted JSON file; for more information, please refer to the Technical Reference Manual.

## **Step 1: Fulfill the Prerequisites**

1. Refer to the Release Notes to learn about supported operating systems, file types, and CAD applications.

2. Before installing the add-on, make sure all prerequisites are fulfilled.

Please refer to the section "[Prerequisites](https://help.secude.com/halocad-add-on-for-dassault-systemes-solidworks/2.4/technical-reference-manual.md#pre)".

## **Step 2: Obtain the License Key**

Obtain the license key and choose whether to activate it automatically or manually.

Please refer to the section "[License Administration](https://help.secude.com/halocad-add-on-for-dassault-systemes-solidworks/2.4/technical-reference-manual.md#lic)".

## **Step 3: Create an Encrypted JSON File**

To ensure a secure installation, create an encrypted JSON file using this admin tool and share it without exposing the original tenant details. When the encrypted JSON file is ready, place it with the HaloCAD installer. By reading data from the `hc.conf.enc` file, the installer activates the license and bypasses the "[Initialization](https://help.secude.com/halocad-add-on-for-dassault-systemes-solidworks/2.4/sw-installing-the-halocad-add-on-for-solidworks.md#Initialization)" screen, which would otherwise ask for Microsoft Entra ID application details.

Please refer to the section "[Secure Installation (Recommended)](https://help.secude.com/halocad-add-on-for-dassault-systemes-solidworks/2.4/technical-reference-manual.md#secure)".

## **Step 4: Install the Add-on**

You can install the add-on in the following modes:

1. **Graphical Mode**

   Graphical mode installation is an interactive, graphical user interface-based method that is driven by a wizard.

2. **Silent Mode**

   Silent-mode installation is a non-interactive method of installing the add-on using command lines.

3. **Via System Center Configuration Manager**

   With System Center Configuration Manager (SCCM), the add-on is deployed on the targeted computers across your enterprise.

### **Graphical Mode**

**Before you begin**

The following prerequisites must be met:

1. A user who installs the HaloCAD Add-on must have administrator rights.

2. Ensure that all active and open CAD applications are closed. If not, HaloCAD prompts a warning message as "*Please close all the CAD applications to proceed with the installation of HaloCAD Add-on for SOLIDWORKS.*"

3. Ensure that the HaloCAD Reader Add-on for SOLIDWORKS is not installed on the same workstation. If it is already installed, HaloCAD prompts a warning message as "*No supported CAD applications are available in the system. (OR) Remove the Reader version of this product.*"

4. Ensure that your Microsoft Entra tenant details are ready when the installation UI requests them. As an alternative, you can use `hc.conf.enc` for a secure and automated installation.

**Installation Procedure**

Install the add-on using the GUI-based setup program provided in the installation package.

1. Double-click the installer `HaloCAD_SOLIDWORKS_Setup.exe` file.

2. Depending on your Windows security settings, a prompt may appear stating, *"Do you want to allow the following program to make changes to this computer?"* If this warning appears, click **Yes** to continue with the installation.

3. When the installer starts, the **Startup** dialog appears, followed by the **Welcome** dialog.

   ![Startup dialog.png](https://help.secude.com/__attachments/a_5e62f37dcdbe1a6e8717348f9b36ab06287c25a3c9bf1afdd7f3c40d80758b6b/Startup%20dialog.png?cb=9be083684a5675c7342b23032581b67e)

   *Startup dialog*  
   ![Welcome dialog.jpg](https://help.secude.com/__attachments/a_b2ac98df49b77d2f68fd06a0cdbd7f36107b880d649b919d4cd0898abcdf7120/Welcome%20dialog.jpg?cb=d33319476459e8f4071676a96af40b8c)

   *Welcome dialog*
4. Click **Next** to continue the installation. The installer UI includes a link to the product's online documentation. When you click **Online Help**, the installation help page opens in your browser.

5. The **End-User License Agreement (EULA)** dialog appears.

   ![End-User License Agreement dialog.jpg](https://help.secude.com/__attachments/a_37fd3d3a5668f3b53d027dadcdbb53ab8ce81b9c5e25e233274a2b0cea243d38/End-User%20License%20Agreement%20dialog.jpg?cb=1bb045903beaf2348fb2fae8e3162e8f)

   *End-User License Agreement dialog*
6. Read the End-User License Agreement. If you agree to the terms, select **I accept the terms in the License Agreement** and click **Next** to continue.

7. The CAD application version selection dialog appears.

   ![CAD application version selection dialog.jpg](https://help.secude.com/__attachments/a_bac612381f93b2a29459becbc49beba5cc55253da39d69a188d9273a9d0fe5b6/CAD%20application%20version%20selection%20dialog.jpg?cb=8016d5eab14edf8acd7752d16f7f2b10)

   *CAD application version selection dialog*
   1. Select the installed SOLIDWORKS application version in your system.

   2. To review or modify installation settings (if needed), click **Back**to return to the previous screens.

8. The installation begins, and the progress is displayed in the dialog.

   ![Installing.jpg](https://help.secude.com/__attachments/a_0bbfa6812ac03807c36fecb317e47baf25f8a9a784d963ae0bd36dd8f267225b/Installing.jpg?cb=8a9c8844ba5b437d4714f871893c0b3a)

   *Installation progress dialog*
9. When the installation is complete, a message appears confirming that the add-on has been successfully installed.

   ![Installation completed dialog.jpg](https://help.secude.com/__attachments/a_940d511f929b7cb64eb017147ed7a8a22ad5c5bb01e6f05aa5a07d0a9f5107a7/Installation%20completed%20dialog.jpg?cb=fd9c36906b2a117bae5b55bbc9d1c652)

   *Installation completed dialog*
10. Click **Next** to proceed.

11. The initialization dialog appears. To prevent connectivity issues, ensure that the correct Microsoft Entra ID application details are entered on the screen. Note**:** If the `hc.conf.enc` file is included with the installer, this initialization screen is skipped and only the completion dialog is shown. The initialization screen appears only when the `hc.conf.enc` file is not present in the installer folder.

    ![Initialization dialog.jpg](/__attachments/a_c2331dac40da42c67c9bd3e792be5e5d3607f229519d0b2912cdb8d6e7b0a931/Initialization%20dialog.jpg?cb=1c1adc0ffc17cba5f31be996aba41530)

    *Initialization dialog*
    1. **Application ID** : Enter the unique identifier of your registered application. For example, `v6ca776-c74e-437d-98ef-662ecb5751tt`

    2. **Redirect URI** : Enter the URI, which was provided when registering the native application in the Azure portal. For example, `https://localhost`

    3. **Tenant ID:** If the registered application is **Single tenant** , you need to enter the globally unique identifier of your tenant if not, you can leave it empty. For example, `9c1cfc28-1ec6-44ea-bec6-e3492ef0cd16`

    4. **Cloud Type** : **Commercial** is selected by default. Based on your Azure subscription and configuration, select the required cloud type from the list: Commercial, Custom, Germany, US_DoD, US_GCC, US_GCC_High, US_Sec, US_Nat, or China_01. If you select **Custom** , enter the appropriate URLs in the **Protection Cloud URL** (for example, `https://api.aadrm.com`) and **Policy Cloud URL** (for example, `https://dataservice.protection.outlook.com`) fields.

    5. **Enable Federal Information Processing Standards (FIPS):** Enable this option to use encryption algorithms that comply with FIPS standards. When enabled, MPIP uses only FIPS-compliant encryption algorithms, and when disabled, it uses standard encryption algorithms. If this option was not enabled during installation, it can later be enabled through a registry entry. For more details, please refer to the section "[Step 5: Modify Registry Settings](/halocad-add-on-for-dassault-systemes-solidworks/2.4/sw-installing-the-halocad-add-on-for-solidworks.md#HRS)".

    6. Click **Next**.

12. Once the initialization is complete, a success message appears as shown below.

    ![Initialization completed dialog.jpg](/__attachments/a_17806d8b258fe5f1cd4f0daab9e335b87a4f499db7a93b83a899b7c12f9458d5/Initialization%20completed%20dialog.jpg?cb=963d1b41ff0f302515281641e81902a8)

    *Initialization completed dialog*
13. Click **Close** to close the installation wizard.

**Post-installation checks**:

1. To view the add-on, open the **SOLIDWORKS** application, and you will notice the **HaloCAD** tab added to the menu bar.

2. **Masking Personally Identifiable Information (PII)** :By default, the HaloCAD Add-on masks Personally Identifiable Information (PII) in logs, such as email names, file paths, and IP addresses in the MIP SDK logs. In HaloCAD logs, information such as the label name, label ID, engine ID, policy ID, and watermark text is masked with asterisks. To view PII in clear text, create the following registry entry in Path: `Computer\HKEY_CURRENT_USER\SOFTWARE\Secude\HaloCAD Add-on for SOLIDWORKS`

   **Name** : `mipallowpii`, **Type** : `REG_SZ`, **Value** : `true`

   The log files are located at the following paths:
   * **MIP SDK log** : `%AppData%\Roaming\Secude\HaloCAD\SOLIDWORKS\mip\logs\mip_sdk.miplog`

   * **HaloCAD log** : `%AppData%\Roaming\Secude\HaloCAD\SOLIDWORKS\halocad.log`

3. If your network infrastructure includes a proxy server that provides access to external websites. Then, to connect to the Secude License Manager URL, you need to manually add the Proxy settings in the add-on. To do so, create a registry entry in the root directory, `HKEY_LOCAL_MACHINE\SOFTWARE\Secude\HaloCAD Add-on for SOLIDWORKS`

   **Name** : `proxyuri`, **Type** : `REG_SZ`, **Value** : The format is, `<URL>:<PORT>`. For example, `http://10.41.0.130:808`

### **Silent Mode**

Besides graphical mode, the add-on can be installed in silent mode, which does not require user involvement or display a user interface. It is a convenient way to streamline installation using the command at once.

1. Open the Command Prompt with elevated rights (Run as Administrator).

2. Navigate to the add-on installer directory.

3. To know the list of options available in silent mode, follow the steps given below:

   **Type** `HaloCAD_SOLIDWORKS_Setup.exe -help`

   **Press** `Enter`

   **Output**

   **...**

   `HaloCAD_SOLIDWORKS_Setup.exe -install -application < SOLIDWORKS 2024 | SOLIDWORKS 2025 | SOLIDWORKS 2026 > -applicationid <azure_application_id> -redirecturi <azure_redirect_url> -tenantid <azure_tenant_id for Single-tenant app|null for Multi-tenant app> [-cloudtype <Commercial|Custom|Germany|US_DoD|US_GCC|US_GCC_High|US_Sec|US_Nat|China> -protectioncloudurl <protection cloud url> -policycloudurl <policy cloud url>] -enablefipsmode <true|false>`

   `[Default Parameters: cloudtype - Commercial and enablefipsmode - false]`

   `HaloCAD_SOLIDWORKS_Setup.exe -uninstall`

   `To delete HaloCAD cache through Silent Mode Uninstallation`

   `HaloCAD_SOLIDWORKS_Setup.exe -uninstall -clearcache <yes>`

   `For Silent Mode Installation if ENC file already exists in the same location`

   `HaloCAD_SOLIDWORKS_Setup.exe -install -application < SOLIDWORKS 2024 | SOLIDWORKS 2025 | SOLIDWORKS 2026 > -enablefipsmode <true|false> `

4. The following command illustrates how to install the add-on using the Azure application details.

   `HaloCAD_SOLIDWORKS_Setup.exe -install -application "SOLIDWORKS 2025" -applicationid v6ca776-c74e-437d-98ef-662ecb5751tt -redirecturi https://localhost -tenantid 9c1cfc28-1ec6-44ea-bec6-e3492ef0cd16 -cloudtype Custom -protectioncloudurl https://api.aadrm.com -policycloudurl https://dataservice.protection.outlook.com -enablefipsmode true`

5. The example below shows how to install the add-on using the `hc.conf.enc` file located in the same installation location.

   `HaloCAD_SOLIDWORKS_Setup.exe -install -application "SOLIDWORKS 2025" enablefipsmode true`

6. Press `Enter`.

7. The installation is complete.

### **Via System Center Configuration Manager**

Microsoft System Center Configuration Manager (SCCM) is an administrative tool that allows organizations to deploy operating systems and applications to Windows users efficiently and cost-effectively across their environment.

Using SCCM, the HaloCAD add-on can be deployed silently and automatically to specific target computers throughout the enterprise.

**Before You Begin**

1. Ensure that you have reviewed the prerequisites described in the **Graphical Mode** section.

2. We recommend adhering to best practices when creating a deployment procedure.

3. For guidance on preparing your environment, refer to the official Microsoft online documentation.

**Deployment Using SCCM**

This guide assumes that an SCCM environment is already configured. After setup, you can use the silent mode commands described in the **Silent Mode** section to deploy the add-on.

## **Step 5: Modify Registry Settings**

Prerequisite: To modify the add-on registry entries, first launch the CAD application and sign in to Microsoft Purview Information Protection to ensure that an active HaloCAD session is established.

Note: Only the registry entries listed in the table below should be modified.

The HaloCAD registry entries are grouped into two sections: **HKEY_CURRENT_USER** and **HKEY_LOCAL_MACHINE**. Depending on your requirements, you can modify the following settings:

1. `HKEY_CURRENT_USER\SOFTWARE\Secude\HaloCAD Add-on for SOLIDWORKS`. Once you have logged into the HaloCAD Session, open Registry Editor, navigate to this path, and modify the desired registry key. For example, to change the log level, double-click **loglevel** , change the "Value data" using the values listed in the table below, and then click **OK**.

   1. loginterval

   2. loglevel

   3. logsize

2. `HKEY_LOCAL_MACHINE\SOFTWARE\Secude\HaloCAD Add-on for SOLIDWORKS`: enable_fips (This entry does not require an active HaloCAD session.)

   |  **Name**   | **Default Value** | **Type**  |                                                                                                                                                                                                                                                                                          **Description**                                                                                                                                                                                                                                                                                           |
   |-------------|-------------------|-----------|----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
   | loginterval | `30`              | REG_SZ    | It automatically removes log files that are older than the default retention period. By default, log files older than 30 days are deleted.                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
   | loglevel    | `0X00000003 (3)`  | REG_DWORD | Log level information is logged in the `halocad.log` file. * Error---0. Logs error events that prevent program execution. * Record---1. Records all the details about the behavior of the application. * Warning---2. Logs unexpected exceptions that indicate potential problems. * Information---3. A standard log level that highlights the progress of the application. * Verbose---4. Debug events are logged. * Verbose 1---5. Debug 1 events are logged. * Verbose 2---6. Debug 2 events are logged. * Verbose 3---7. Debug 3 events are value. * Verbose 4---8. Debug 4 events are logged. |
   | logsize     | `1024`            | REG_SZ    | The `halocad.log` file is created at the start of a HaloCAD session and is stored in the default parent location directory. To have control over log file size, HaloCAD allows you to configure backup/archive the current log file with a timestamp when it exceeds the default size of `1024 MB,` and creates a new one. Format: `halocad<ddmmyy_hhmmss>.log`                                                                                                                                                                                                                                    |
   | enable_fips | `false`           | REG_SZ    | Enable or Disable FIPS Mode 1. true: MPIP uses only FIPS-compliant encryption algorithms. 2. false: MPIP uses standard encryption algorithms.                                                                                                                                                                                                                                                                                                                                                                                                                                                      |

   *Configuration in the HaloCAD Registry*

   **What to do next**
   1. If the encrypted configuration file was placed with the installer:

      1. You can launch the CAD application and start using the HaloCAD features immediately.

      2. The license is activated silently in the background.

      3. For details on protecting CAD files, refer to the Operations Manual.

   2. If the encrypted configuration file was not placed with the installer:

      1. You must activate the license manually.

      2. Follow the instructions in the "UI-based Manual License Activation" section of the Technical Reference Manual.

**HaloCAD Add-on with PLM**

1. If you have installed HaloCAD as a standalone add-on in your environment, you can create a file and protect it with a suitable label. For more information, please refer to the Operations Manual.

2. If you have the HaloCAD add-on installed in a suitable PLM environment, it will intercept the file download and automatically protect it with a suitable label. For more information, please refer to the HaloCAD for PLM Operations Manual.

   To integrate with SAP ECTR, you need to install the following components:
   1. HaloENGINE Service

   2. HaloENGINE

   3. HaloCORE Client for NetWeaver

   4. HaloCORE for DMS

   5. HaloCAD KPro

   To integrate with Keytech, you need to install the following components:
   1. HaloENGINE Service

   2. HaloENGINE

   3. HaloCAD for Keytech

   To integrate with SOLIDWORKS PDM, you need to install the following components:
   1. HaloENGINE Service

   2. HaloENGINE

   3. HaloCAD for SOLIDWORKS PDM

---
version: "2.4"
language: "en"
---
# Installing the HaloCAD Reader Add-on for SOLIDWORKS

This chapter describes how to install and configure the HaloCAD Reader Add-on for SOLIDWORKS.

**Before you begin**

1. A user who installs the HaloCAD Reader Add-on must have administrator rights.

2. Ensure that all active and open CAD applications are closed. If not, HaloCAD prompts a warning message as "*Please close all the CAD applications to proceed with the installation of HaloCAD Reader Add-on for SOLIDWORKS*."

3. Ensure that the HaloCAD Add-on for SOLIDWORKS (full version) is not installed on the same workstation. If it is already installed, HaloCAD prompts a warning message as "*No supported CAD applications are available in the system. (OR) Remove the full version of this product.*"

4. Ensure your Microsoft Entra tenant information is ready to enter when the setup process prompts for a manual installation. Alternatively, for a safe and automatic installation, use `hc.conf.enc`. In both cases, the tenant information must be the same as that used in the full version installation. Refer to the sections "License Activation" and "Secure Installation" in the Technical Reference Manual for further information on the various methods for activating a license key and automatic initialization and activation of a license.

**Installation Procedure**

Install the application by using the GUI-based setup program that is provided in the installation package.

1. To begin the interactive installation, double-click the installer `HaloCAD_Reader_SOLIDWORKS_Setup.exe` file. For the installation procedure, follow the installation wizard or refer to the full version.

2. The reader add-on can be installed and configured in the same manner as the full add-on. The command line to execute the silent installation is `HaloCAD_Reader_SOLIDWORKS_Setup.exe -help` and follow the commands.

3. **Post-installation checks**:

   1. To view the add-on, open the **AutoCAD Application** \> **HaloCAD** tab.

   2. Similar to the full version, the Reader add-on also masks personally identifiable information (PII) in logs. To view PII in clear text, create the following registry entry in Path: `Computer\HKEY_CURRENT_USER\SOFTWARE\Secude\HaloCAD Reader Add-on for SOLIDWORKS`

      **Name** : `mipallowpii`, **Type** : `REG_SZ`, **Value** : `true`

      The log files are located at the following paths:
      * **MIP SDK log** : `%AppData%\Roaming\Secude\HaloCAD\SOLIDWORKS\mip\logs\mip_sdk.miplog`

      * **HaloCAD log** : `%AppData%\Roaming\Secude\HaloCAD\SOLIDWORKS\halocad.log`

      * For more details, please refer to the section "[Step 5: Modify Registry Settings](/halocad-add-on-for-dassault-systemes-solidworks/2.4/sw-installing-the-halocad-add-on-for-solidworks.md#HRS)".

   3. If your network infrastructure includes a proxy server that provides access to external websites. Then, to connect to the Secude License Manager URL, you need to manually add the Proxy settings in the add-on. To do so, create a registry entry in the root directory, `HKEY_LOCAL_MACHINE\SOFTWARE\Secude\HaloCAD Reader Add-on for SOLIDWORKS`

      **Name** : `proxyuri`, **Type** : `REG_SZ`, **Value** : The format is, `<URL>:<PORT>`. For example, `http://10.41.0.130:808`

**What to do next**

1. If the encrypted configuration file was placed with the installer:

   1. You can launch the CAD application and begin using the reader add-on right away to view the protected file.

   2. The license is activated silently in the background.

   3. For details, refer to the Operations Manual.

2. If the encrypted configuration file was not placed with the installer:

   1. You must activate the license manually.

   2. Follow the instructions in the "UI-based Manual License Activation" section of the Technical Reference Manual.

---
version: "2.4"
language: "en"
---
# Operations Manual

Recording for internal use. This content will not be shipped into word EXPORT, visible only in Confluence.

**VERSION HISTORY**  

|  **Build number**   |                                                                                                                                                                                                                                                                 **Document changes**                                                                                                                                                                                                                                                                  |
|---------------------|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1.0 \> V1           | Initial Version                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| 1.0                 | 1. Change Rights check box added in status screen 2. Added section "HALOCAD Reader Add-on for SOLIDWORKS" 3. Added section "How to View a Protected File in HALOCAD Reader?" 4. Added Example 6: Removing Protection from Dependent Files                                                                                                                                                                                                                                                                                                             |
| 1.1                 | 1. Added "Could not Connect to Azure RMS" under Troubleshooting section 2. Added section Example 7: Custom Permission Label, Example 8: Remove protection from a file, Example 9: Remove protection from a file \& Example 10: Revoke a file 3. Added troubleshooting section "Label not found in the policy", Could not Connect to Azure RMS -- Case 1 \& Could not Connect to Azure RMS -- Case 2 4. How does it works - updated in Full and Reader mode, HALOCAD tab UI added 5. Permissions tables added, New section "License Enforcement" added |
| 1.2                 | 1. General FAQs added. 2. Tenant name changed from "halocore to halocad"                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| 1.3                 | 1. Tenant name changed from "halocad to halosecude" 2. Added support for Default label 3. Support for License Spring integration 4. Troubleshooting "HALOCAD Activation Fails, Incorrect License Key Error Message, Why am I getting license expiration notifications? and Other License Related Error messages" added. 5. Name changed to HaloCAD \& Secude                                                                                                                                                                                          |
| 2.0 (April GA 2024) | 1. Example 7: Other Use Case Scenarios - Least permission                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| 2.1 (Oct GA 2024)   | 1. Added Documentation Feedback section 2. Support Metadata update for MPIP Label only - Labeling a File Without Protection 3. Replaced "Microsoft purview compliance portal" with "Microsoft Purview portal". 4. Updated (message pop-up appears in unprotected file) and interchanged case 2 and case 3 in Example 7: Other Use Case Scenarios - Least permission 5. Added Example 8: Label with Content Marking 6. Watermark support is provided for MPIP Label only.                                                                              |
| 2.2 (April GA 2025) | 1. Troubleshooting - Added "Date header is not valid or set in past." under Other License Related Error Messages. 2. Expiry access date updated in *HaloCAD Custom permissions, Validity of the file, and User with custom permission.*                                                                                                                                                                                                                                                                                                               |
| 2.3 (Oct GA 2025)   | 1. Example 1 image 2. The warning message for reader mode is updated                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| 2.4 (April GA 2026) | 1. Year 2026 \> 2028 added. 2. How does it work, Full and Reader add-on image is updated 3. A note is added "HCADRVT-165". Note: By design, saving is restricted once a protected file is opened in a session to prevent protected content from being copied to an unprotected file. HaloCAD shows a restriction message. In a fresh session, unprotected files can be created and saved without any restrictions. 4. Change in heading name**"Technical support"** is added instead of **Customer Support and Feedback**.                            |

**Table of Contents**  
* 1 [About this Manual](https://help.secude.com/halocad-add-on-for-dassault-systemes-solidworks/2.4/sw-operations-manual.md#id-(2.4)(SW)OperationsManual-AboutthisManual)
* 2 [General FAQs](https://help.secude.com/halocad-add-on-for-dassault-systemes-solidworks/2.4/sw-operations-manual.md#id-(2.4)(SW)OperationsManual-GeneralFAQs)
* 3 [How does it work?](https://help.secude.com/halocad-add-on-for-dassault-systemes-solidworks/2.4/sw-operations-manual.md#id-(2.4)(SW)OperationsManual-Howdoesitwork?)
  * 3.1 [License Enforcement](https://help.secude.com/halocad-add-on-for-dassault-systemes-solidworks/2.4/sw-operations-manual.md#id-(2.4)(SW)OperationsManual-LicenseEnforcement)
  * 3.2 [Applying Protection using HaloCAD Add-on](https://help.secude.com/halocad-add-on-for-dassault-systemes-solidworks/2.4/sw-operations-manual.md#id-(2.4)(SW)OperationsManual-ApplyingProtectionusingHaloCADAdd-on)
  * 3.3 [Viewing a Protected File Via the HaloCAD Reader Add-on](https://help.secude.com/halocad-add-on-for-dassault-systemes-solidworks/2.4/sw-operations-manual.md#id-(2.4)(SW)OperationsManual-ViewingaProtectedFileViatheHaloCADReaderAdd-on)
* 4 [Get Started with HaloCAD](https://help.secude.com/halocad-add-on-for-dassault-systemes-solidworks/2.4/sw-operations-manual.md#id-(2.4)(SW)OperationsManual-GetStartedwithHaloCAD)
  * 4.1 [Permission Levels and Usage Rights](https://help.secude.com/halocad-add-on-for-dassault-systemes-solidworks/2.4/sw-operations-manual.md#id-(2.4)(SW)OperationsManual-PermissionLevelsandUsageRights)
    * 4.1.1 [Basic Permissions](/halocad-add-on-for-dassault-systemes-solidworks/2.4/sw-operations-manual.md#id-(2.4)(SW)OperationsManual-BasicPermissions)
    * 4.1.2 [Custom Permissions](/halocad-add-on-for-dassault-systemes-solidworks/2.4/sw-operations-manual.md#id-(2.4)(SW)OperationsManual-CustomPermissions)
  * 4.2 [HaloCAD Screen Introduction](https://help.secude.com/halocad-add-on-for-dassault-systemes-solidworks/2.4/sw-operations-manual.md#id-(2.4)(SW)OperationsManual-HaloCADScreenIntroduction)
  * 4.3 [How to Protect a CAD File?](https://help.secude.com/halocad-add-on-for-dassault-systemes-solidworks/2.4/sw-operations-manual.md#id-(2.4)(SW)OperationsManual-HowtoProtectaCADFile?)
    * 4.3.1 [Cancel, Remove, Relabel, and More](/halocad-add-on-for-dassault-systemes-solidworks/2.4/sw-operations-manual.md#id-(2.4)(SW)OperationsManual-Cancel,Remove,Relabel,andMore)
    * 4.3.2 [Log out an Active User](/halocad-add-on-for-dassault-systemes-solidworks/2.4/sw-operations-manual.md#id-(2.4)(SW)OperationsManual-LogoutanActiveUser)
  * 4.4 [How to Export a Protected CAD File to a PDF File?](https://help.secude.com/halocad-add-on-for-dassault-systemes-solidworks/2.4/sw-operations-manual.md#id-(2.4)(SW)OperationsManual-HowtoExportaProtectedCADFiletoaPDFFile?)
  * 4.5 [How to View a Protected File in HaloCAD Reader?](https://help.secude.com/halocad-add-on-for-dassault-systemes-solidworks/2.4/sw-operations-manual.md#id-(2.4)(SW)OperationsManual-HowtoViewaProtectedFileinHaloCADReader?)
* 5 [Common Scenarios](https://help.secude.com/halocad-add-on-for-dassault-systemes-solidworks/2.4/sw-operations-manual.md#id-(2.4)(SW)OperationsManual-CommonScenarios)
  * 5.1 [Concept: Sensitivity Labels](https://help.secude.com/halocad-add-on-for-dassault-systemes-solidworks/2.4/sw-operations-manual.md#id-(2.4)(SW)OperationsManual-Concept:SensitivityLabels)
  * 5.2 [How to Open a Protected CAD File?](https://help.secude.com/halocad-add-on-for-dassault-systemes-solidworks/2.4/sw-operations-manual.md#id-(2.4)(SW)OperationsManual-HowtoOpenaProtectedCADFile?)
    * 5.2.1 [Example 1: Label with Read-only Access](/halocad-add-on-for-dassault-systemes-solidworks/2.4/sw-operations-manual.md#id-(2.4)(SW)OperationsManual-Example1:LabelwithRead-onlyAccess)
    * 5.2.2 [Example 2: Label with Full Control Access](/halocad-add-on-for-dassault-systemes-solidworks/2.4/sw-operations-manual.md#id-(2.4)(SW)OperationsManual-Example2:LabelwithFullControlAccess)
    * 5.2.3 [Example 3: Unauthorized User Access](/halocad-add-on-for-dassault-systemes-solidworks/2.4/sw-operations-manual.md#id-(2.4)(SW)OperationsManual-Example3:UnauthorizedUserAccessEX3)
    * 5.2.4 [Example 4: Labeling Dependent (Protected and Unprotected) Files](/halocad-add-on-for-dassault-systemes-solidworks/2.4/sw-operations-manual.md#id-(2.4)(SW)OperationsManual-Example4:LabelingDependent(ProtectedandUnprotected)Files)
    * 5.2.5 [Example 5: Labeling Dependent (Unprotected) Files](/halocad-add-on-for-dassault-systemes-solidworks/2.4/sw-operations-manual.md#id-(2.4)(SW)OperationsManual-Example5:LabelingDependent(Unprotected)Files)
    * 5.2.6 [Example 6: Removing Protection from Assembly and Part Files](/halocad-add-on-for-dassault-systemes-solidworks/2.4/sw-operations-manual.md#id-(2.4)(SW)OperationsManual-Example6:RemovingProtectionfromAssemblyandPartFiles)
    * 5.2.7 [Example 7: Other Use Case Scenarios](/halocad-add-on-for-dassault-systemes-solidworks/2.4/sw-operations-manual.md#id-(2.4)(SW)OperationsManual-Example7:OtherUseCaseScenarios)
      * 5.2.7.1 [Importing a file with a restricted/least permission label](/halocad-add-on-for-dassault-systemes-solidworks/2.4/sw-operations-manual.md#id-(2.4)(SW)OperationsManual-Importingafilewitharestricted/leastpermissionlabel)
      * 5.2.7.2 [Labeling a File Without Protection](/halocad-add-on-for-dassault-systemes-solidworks/2.4/sw-operations-manual.md#id-(2.4)(SW)OperationsManual-LabelingaFileWithoutProtection)
    * 5.2.8 [Example 8: Label with Content Marking](/halocad-add-on-for-dassault-systemes-solidworks/2.4/sw-operations-manual.md#id-(2.4)(SW)OperationsManual-Example8:LabelwithContentMarking)
    * 5.2.9 [Example 9: Custom Permissions Label](/halocad-add-on-for-dassault-systemes-solidworks/2.4/sw-operations-manual.md#id-(2.4)(SW)OperationsManual-Example9:CustomPermissionsLabelCPL)
      * 5.2.9.1 [Protection using Custom Permissions (User-defined Permissions) from Microsoft Purview Portal](/halocad-add-on-for-dassault-systemes-solidworks/2.4/sw-operations-manual.md#id-(2.4)(SW)OperationsManual-ProtectionusingCustomPermissions(User-definedPermissions)fromMicrosoftPurviewPortal)
      * 5.2.9.2 [Protection using Custom Permissions (User-defined Permissions) via HaloCAD Add-on](/halocad-add-on-for-dassault-systemes-solidworks/2.4/sw-operations-manual.md#id-(2.4)(SW)OperationsManual-ProtectionusingCustomPermissions(User-definedPermissions)viaHaloCADAdd-on)
    * 5.2.10 [Example 10: Set an Expiration Date for File Access](/halocad-add-on-for-dassault-systemes-solidworks/2.4/sw-operations-manual.md#id-(2.4)(SW)OperationsManual-Example10:SetanExpirationDateforFileAccess)
      * 5.2.10.1 [Why is File Expiration Necessary?](/halocad-add-on-for-dassault-systemes-solidworks/2.4/sw-operations-manual.md#id-(2.4)(SW)OperationsManual-WhyisFileExpirationNecessary?)
      * 5.2.10.2 [What Happens When a File Expires?](/halocad-add-on-for-dassault-systemes-solidworks/2.4/sw-operations-manual.md#id-(2.4)(SW)OperationsManual-WhatHappensWhenaFileExpires?)
      * 5.2.10.3 [How to Open an Expired File](/halocad-add-on-for-dassault-systemes-solidworks/2.4/sw-operations-manual.md#id-(2.4)(SW)OperationsManual-HowtoOpenanExpiredFile)
    * 5.2.11 [Example 11: Revoke a File](/halocad-add-on-for-dassault-systemes-solidworks/2.4/sw-operations-manual.md#id-(2.4)(SW)OperationsManual-Example11:RevokeaFilerevoke)
      * 5.2.11.1 [Why Should a User Revoke a File?](/halocad-add-on-for-dassault-systemes-solidworks/2.4/sw-operations-manual.md#id-(2.4)(SW)OperationsManual-WhyShouldaUserRevokeaFile?)
      * 5.2.11.2 [How to Revoke a File?](/halocad-add-on-for-dassault-systemes-solidworks/2.4/sw-operations-manual.md#id-(2.4)(SW)OperationsManual-HowtoRevokeaFile?)
      * 5.2.11.3 [What Happens if a User Attempts to Open the Revoked File?](/halocad-add-on-for-dassault-systemes-solidworks/2.4/sw-operations-manual.md#id-(2.4)(SW)OperationsManual-WhatHappensifaUserAttemptstoOpentheRevokedFile?)
      * 5.2.11.4 [What Happens if a User Changes the Label?](/halocad-add-on-for-dassault-systemes-solidworks/2.4/sw-operations-manual.md#id-(2.4)(SW)OperationsManual-WhatHappensifaUserChangestheLabel?)
      * 5.2.11.5 [How to Open the Revoked File?](/halocad-add-on-for-dassault-systemes-solidworks/2.4/sw-operations-manual.md#id-(2.4)(SW)OperationsManual-HowtoOpentheRevokedFile?)
* 6 [Troubleshooting](https://help.secude.com/halocad-add-on-for-dassault-systemes-solidworks/2.4/sw-operations-manual.md#id-(2.4)(SW)OperationsManual-Troubleshooting)
  * 6.1 [Cannot Sign in to Microsoft Sign-In Assistant](https://help.secude.com/halocad-add-on-for-dassault-systemes-solidworks/2.4/sw-operations-manual.md#id-(2.4)(SW)OperationsManual-CannotSignintoMicrosoftSign-InAssistant)
  * 6.2 [Labels are not Getting Downloaded in the HaloCAD Session](https://help.secude.com/halocad-add-on-for-dassault-systemes-solidworks/2.4/sw-operations-manual.md#id-(2.4)(SW)OperationsManual-LabelsarenotGettingDownloadedintheHaloCADSession)
  * 6.3 [Label not Found in the Policy](https://help.secude.com/halocad-add-on-for-dassault-systemes-solidworks/2.4/sw-operations-manual.md#id-(2.4)(SW)OperationsManual-LabelnotFoundinthePolicy)
  * 6.4 [Double Key Encryption Label could not be Applied](https://help.secude.com/halocad-add-on-for-dassault-systemes-solidworks/2.4/sw-operations-manual.md#id-(2.4)(SW)OperationsManual-DoubleKeyEncryptionLabelcouldnotbeApplied)
  * 6.5 [Could not Connect to MPIP -- Case 1](#id-(2.4)(SW)OperationsManual-CouldnotConnecttoMPIP–Case1)
  * 6.6 [Could not Connect to MPIP -- Case 2](#id-(2.4)(SW)OperationsManual-CouldnotConnecttoMPIP–Case2)
  * 6.7 [HaloCAD Activation Fails](https://help.secude.com/halocad-add-on-for-dassault-systemes-solidworks/2.4/sw-operations-manual.md#id-(2.4)(SW)OperationsManual-HaloCADActivationFails)
  * 6.8 [Incorrect License Key Error Message](https://help.secude.com/halocad-add-on-for-dassault-systemes-solidworks/2.4/sw-operations-manual.md#id-(2.4)(SW)OperationsManual-IncorrectLicenseKeyErrorMessage)
  * 6.9 [Why Am I Getting License Expiration Notifications?](https://help.secude.com/halocad-add-on-for-dassault-systemes-solidworks/2.4/sw-operations-manual.md#id-(2.4)(SW)OperationsManual-WhyAmIGettingLicenseExpirationNotifications?)
  * 6.10 [Other License-Related Error Messages](https://help.secude.com/halocad-add-on-for-dassault-systemes-solidworks/2.4/sw-operations-manual.md#id-(2.4)(SW)OperationsManual-OtherLicense-RelatedErrorMessages)
* 7 [Technical Support](https://help.secude.com/halocad-add-on-for-dassault-systemes-solidworks/2.4/sw-operations-manual.md#id-(2.4)(SW)OperationsManual-TechnicalSupport)

## About this Manual

This manual provides comprehensive guidelines and step-by-step instructions for working with **HaloCAD solutions (Label** and **Protect)** . For information on deployment and configuration, refer to the **Installation Manual** included in the product package.

## General FAQs

This section answers the most frequently asked questions (FAQs). For additional inquiries, please contact your sales representative or the support team.

1. **What does HaloCAD provide for an organization?**

   HaloCAD solution protects engineering CAD files and enforces security across their entire lifecycle.

2. **How many variants does HaloCAD have?**

   HaloCAD is available in three variants:

   1. HaloCAD Add-on for CAD applications -- a standalone add-on

   2. HaloCAD for PLM

   3. HaloCAD Reader Add-on for CAD applications

3. **What is the difference between the HaloCAD Add-on for CAD and the HaloCAD for PLM?**

   HaloCAD Add-on for CAD is a standalone solution for organizations that do not store CAD files in PLM. It enforces protection through user engagement.

   HaloCAD for PLM integrates with the respective PLM application and includes the capabilities of HaloCAD PROTECT and HaloCAD MONITOR. The MPIP label is applied automatically, based on the rules defined in the Classification Engine, without requiring user intervention.
4. **What distinguishes the HaloCAD Reader add-on from the HaloCAD Standalone (full add-on)?**

   HaloCAD Standalone Add-on (Full Version) protects CAD files using Microsoft Purview Information Protection solution. This version is licensed.

   HaloCAD Reader Add-on allows viewing of files protected by the HaloCAD Standalone Add-on. This version is free of charge.
5. **What languages are supported by the HaloCAD add-on?**

   Currently, the HaloCAD add-on only supports English.

6. **Does the HaloCAD Add-on support all native CAD file types?**

   Yes, the HaloCAD Add-on supports all CAD native file types.

7. **What happens if an unauthorized person tries to open a HaloCAD-protected CAD file?**

   The process begins with user authentication, which verifies the user's identity. If authentication fails, an error message is displayed, and access is denied.

8. **Who decides what labels should be used for various CAD drawings and how they are managed in the background?**

   An administrator manages labels (user rights) in the Microsoft Purview portal, while engineers can create profiles, classification schemas, and action rules based on the sensitivity of their data.

9. **What if I don't want a certain file to be protected?**

   If you do not want the file to be protected, you can apply the **"No Protection"** label, which does not include any policy settings.

10. **Can I create my own labels?**

    Yes, HaloCAD allows users to create custom permission labels.

## How does it work?

This chapter provides a high-level explanation of the underlying processes and interactions between the system components to help you understand how HaloCAD protects sensitive data.

### License Enforcement

After installation, HaloCAD programmatically sends a license validation request to Secude's License Manager when a user attempts to start a session for the first time by opening the CAD application. Based on the administrator's installation method, one of the following scenarios applies:

**Case 1:**

If the license is activated automatically during the installation process, the user can continue using all HaloCAD features without interruption.

**Case 2:**

If the license has not been activated, the user will receive an error message and will be unable to access HaloCAD features. For information on license activation, refer to the **License Activation** section of the Technical Reference Manual.

### Applying Protection using HaloCAD Add-on

At a high level, HaloCAD workflow involves the following steps:  
![Common_Full_How does it work.png](https://help.secude.com/__attachments/a_82d261dd9ef1975563ee654b25daf103ffcf54583a102f0b1d9b5043b067fb58/Common_Full_How%20does%20it%20work.png?cb=50711313c7ce5ba3f2660fd6bb68bbeb)

*HaloCAD protection*

1. To create new CAD files, the user launches the CAD application and logs into the HaloCAD session for the first time.

2. HaloCAD connects to the Microsoft Entra tenant. In this manual, `halosecude.onmicrosoft.com` is used as an example tenant.

   1. Microsoft Entra ID prompts the user for authentication.

   2. After successful authentication, Microsoft Purview Information Protection (MPIP) labels are downloaded for the logged-in user (`john@halosecude.onmicrosoft.com`).

3. File protection: The user (John) selects and applies two different labels to two separate files.

4. HaloCAD enforces document protection based on the selected label. When a sensitivity label is applied, it is stored in the document metadata, and the corresponding protection settings are enforced to secure the content.

5. **File-Sharing** : Assume that `john@halosecude.onmicrosoft.com` shares the files with multiple users. **Users A** ,**B** ,and **C** receive **File 1** , while **User D** receives **File 2**.

6. Content consumption: Users A, B, C, and D attempt to access the protected files. Microsoft Entra ID authenticates each user, and the file opens upon successful authentication. Access permissions such as **View, Edit, Print, Copy, Export,** and **Change** are granted based on the applied label. Different permission levels may be assigned to individual users or user groups.

   Note: The user who initializes HaloCAD is considered the author and is granted full access rights to the document. For more information on labels, refer to the Microsoft documentation.

   1. File 1 - Full access is granted to `User A@halosecude.onmicrosoft.com`.

   2. File 1 - Read-only (view-only) access is granted to `User B@halosecude.onmicrosoft.com`.

   3. File 1 - `User C@halosecude.onmicrosoft.com` is denied access and cannot open the file.

   4. File 2 - Access was previously granted to `User D@halosecude.onmicrosoft.com` but has been revoked due to risky or suspicious activity.

**Logged-in user (HaloCAD session)**

In this document, the term "logged-in user" refers to the individual or user account that launches the CAD application and signs in to Microsoft Entra ID through the Microsoft Sign-In application. This may differ from the operating system user currently signed in. Collectively, this is referred to as the "HaloCAD session."

### Viewing a Protected File Via the HaloCAD Reader Add-on

At a high level, HaloCAD workflow involves the following steps:  
![Common_Reader How does it work.png](https://help.secude.com/__attachments/a_252b46e6eb442004894b9cb9776f5669b90edf0ab1e2d698ede44f484ffc8433/Common_Reader%20How%20does%20it%20work.png?cb=dd0cedef1a51cb05fe460946f52fff25)

*HaloCAD Reader Add-on*

1. The user selects two files that are protected by HaloCAD.

2. When the user logs in to the HaloCAD session for the first time, a connection to Microsoft Purview Information Protection is required. Microsoft Entra ID authenticates the user.

3. HaloCAD indicates that the files can be opened only in read-only mode. In this scenario, the user is authorized to open File 1.

4. File 2 does not open because the user does not have the required permissions.

By design, saving is restricted once a protected file is opened in a session to prevent protected content from being copied to an unprotected file. HaloCAD shows a restriction message. In a fresh session, unprotected files can be created and saved without any restrictions.

## Get Started with HaloCAD

This section describes how to protect a file, open a protected file, export a protected file as a PDF, and use the HaloCAD Reader add-on.

### Permission Levels and Usage Rights

#### **Basic Permissions**

The following table lists the basic permissions and the usage rights that they contain:  

| **S.No** |    **Permission Level**     |                                                       **Usage Rights (Allowed Recipient Actions)**                                                        |
|----------|-----------------------------|-----------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1        | View                        | Open and read the data (also known as "Read-only"). It includes Zoom and view from different angles (for CAD file types).                                 |
| 2        | Edit                        | Edit the file and save it                                                                                                                                 |
| 3        | Copy                        | Extract data (including screen captures) from the file into the same or another file.                                                                     |
| 4        | Print                       | Print the content                                                                                                                                         |
| 5        | Export                      | Save the content to a different filename (Save As). Also includes "Export to PDF".                                                                        |
| 6        | Change Rights               | Changing the label that is applied to a file includes removing protection and saving it as an unprotected file.                                           |
| 7        | Owner (Full Control rights) | Grants all rights to the file and all available actions can be performed. Also includes the following permissions: 1. Remove protection 2. Relabel a file |

*Basic Permissions*  
**Author (creator) of a file**

The author of a file has all the rights and actions mentioned in the above table. Also includes the following permissions:

1. Open file after the expiry date

2. Revoke access

#### **Custom Permissions**

The following table lists the custom permissions and the usage rights that they contain:  

| **S.No** | **Permission Level** |                                              **Usage Rights (Allowed Recipient Actions)**                                              |
|----------|----------------------|----------------------------------------------------------------------------------------------------------------------------------------|
| 1        | Viewer               | Open and read the data (also known as "Read-only"). It includes Zoom and view from different angles.                                   |
| 2        | Reviewer             | Viewer's allowed permissions plus: 1. Edit 2. Save the file                                                                            |
| 3        | Co-Author            | Reviewer's allowed permissions plus: 1. Print 2. Extract data (including screen captures) from the file into the same or another file. |
| 4        | Co-Owner             | Co-Author's allowed permissions plus: 1. Export 2. Change Rights                                                                       |
| 5        | Only for me          | Grants all rights to the file and all available actions can be performed only by the author of the file.                               |

*Custom Permissions*

### HaloCAD Screen Introduction

After installing the HaloCAD add-on, the HaloCAD tab appears in the CAD application, as shown in the figure below:  
![HaloCAD Start up.png](https://help.secude.com/__attachments/a_c54f915e9973417711dfaa19372aad592849258977f4d5cd0e130b85653b82f7/HaloCAD%20Start%20up.png?cb=847eb305499940c373fd3cec3fd0e7e3)

*HaloCAD in SOLIDWORKS*

The following table provides a brief description of each HaloCAD menu element.  

| **S.No** |                                                                         **Icon**                                                                          |                                                                                                                                                                                                                                                                                                                                            **Description**                                                                                                                                                                                                                                                                                                                                             |
|----------|-----------------------------------------------------------------------------------------------------------------------------------------------------------|--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1        | ![stauts.png](https://help.secude.com/__attachments/a_befcdef673868606bbccf3632a431052b9f655b5b078125cee7c163b475ec2a4/stauts.png?cb=ce9418192203a4b0d6c6149b5cbf59df)           | The **Status**icon displays the status of the file. ![Status screen.png](https://help.secude.com/__attachments/a_4408c78c5c1ee4d01505d8c52f711c54cd5e4f46b8b98c956c15cc300682ac4f/Status%20screen.png?cb=4280689fd2282bb58b1e6234a9a6f4c0) 1. **Connected as**: Name of the logged-in user 2. **Owner**: Author of the document 3. **Sensitivity**: Name of the label applied 4. **Permissions**: Rights on the file 5. **Expire access**: Displays the details of how long a user can access the labeled file 6. **Revoke Access** button**:**Revokes access granted for a protected document 7. **Reset**button: Logs off a user from the current active session. The button will be disabled unless the user logs in again |
| 2        | ![About.png](https://help.secude.com/__attachments/a_dfa4045adef96ebe7cd75fd076d4ef9dc0c929b3a6e2ff02cd2b69b5f185539d/About.png?cb=6934a8b3072095a7cee61e8692716638)             | The **About**icon displays the application version and license information. For details on license activation, refer to the "License Activation" section of the Technical Reference Manual. ![About Screen.png](https://help.secude.com/__attachments/a_2b6fe26e9222fd5aa4b355ead5f4c7b1bab2eb273036f30e27bf26c26106794b/About%20Screen.png?cb=f93a2242801dc7fc12a3bbeb14864c5d)                                                                                                                                                                                                                                                                                                                                              |
| 3        | ![Label icon.png](https://help.secude.com/__attachments/a_a402dfaa414a6a62e207625a4974c41ae3583e8712e2cca14ba561f3fb949ed2/Label%20icon.png?cb=482a28372c1b817ac112503dfbcbac24) | The **Sensitivity** icon enables and disables the**HaloCAD**ribbon. ![HaloCAD Ribbon.png](https://help.secude.com/__attachments/a_28f960a65b7cd1a336de3601101478a0905c875ed319c5d23f092249069306a5/HaloCAD%20Ribbon.png?cb=30e3f4a45e4e6dca73d68e7dc9249ef1) **Pencil icon - Click to change label**: 1. Downloads the available labels. 2. Allows changing an applied label.                                                                                                                                                                                                                                                                                                                                                 |
| 3        | ![Label icon.png](https://help.secude.com/__attachments/a_a402dfaa414a6a62e207625a4974c41ae3583e8712e2cca14ba561f3fb949ed2/Label%20icon.png?cb=482a28372c1b817ac112503dfbcbac24) | ![Sensitivity bar after connecting.png](https://help.secude.com/__attachments/a_064ac971f59282cb87ba500dd82580c1f5a142526957bd69a21982e36de47782/Sensitivity%20bar%20after%20connecting.png?cb=696412c111dca425a5fbc6fd9cb701cd) 1. **Green check mark - Click to set label**icon - applies the selected label or removes the existing label. 2. **Red cross mark - Click to cancel**icon - cancels the selected label. 3. **Sensitivity** labellist - displays the labels.                                                                                                                                                                                                                                                   |

*Overview of screen elements*

### How to Protect a CAD File?

**Prerequisites**

* To protect organizational data by using sensitivity labels, configure protection settings for each label in the **Microsoft Purview portal**.

* To set a default label for documents, configure the following setting in the **Microsoft Purview portal** : Go to **Label policies** \> **Settings** \> **Documents** \> **Default settings for documents** \> **Apply a default label to documents**, and then select a label from the list.

To protect a CAD file, perform the following steps:

1. Open the SOLIDWORKS application, and then open an existing file or create a new file.

2. For new or unprotected files, the **Sensitivity** status displays **Not set** if no default label is configured in the policy. If a default label is configured, the configured default label is displayed. In this example, no default label is set.

3. On first login, HaloCAD prompts for **Microsoft Sign-In Assistant** authentication.

   ![Microsoft Sign-In Assistant invoking message.png](https://help.secude.com/__attachments/a_d1667a9ff5a3272fd0720bde647faae4a20368152216e11af6f11dcd500a8f5a/Microsoft%20Sign-In%20Assistant%20invoking%20message.png?cb=fd82dff43a5c815a26c6e0fcdee4640d)

   *Microsoft Sign-In Assistant invoking message*
4. Enter your credentials.

   ![Microsoft Sign in1.png](https://help.secude.com/__attachments/a_2f6a0d22ba5ece217f53438aff635b9feec38745259f137ec396bbe653c95650/Microsoft%20Sign%20in1.png?cb=845c779a5767c8dbe16cf63605fed31d)

   *Authentication sign-in prompt*
5. After authentication, HaloCAD connects to Microsoft Entra ID and caches the user credentials.

6. Go to the **HaloCAD** tab and click **Sensitivity**.

7. To apply the label to the active document, click the pencil icon (**Click to change label**).

8. A notification appears indicating that labels are being downloaded from Microsoft Purview Information Protection.

   ![Please wait message.png](https://help.secude.com/__attachments/a_3e768b465c6d22cb30c36cf059b44ff50e44af3735c95cf70ad5ff1f2c8a541e/Please%20wait%20message.png?cb=ae09df516b7c88d682cf9eebca0161d9)

   *Fetching the labels*
9. From the **Sensitivity** list, select a label, and then click the green check mark (**Click to set label**) to confirm the selection.

   ![Downloaded labels SW.png](https://help.secude.com/__attachments/a_a9e7eac26fa07b659640fa7527f274f183223583398c84be782d5d643a5b14d9/Downloaded%20labels%20SW.png?cb=36ea86c4947b5b122d705bf99ba03f08)

   *Downloaded labels for the signed-in user*
10. For a new file, specify a file name and save it.

11. For an existing file, an additional save action is not required. When the label is applied by clicking the **Click to set label** (check mark) icon, the file is saved automatically.

**Result**

* The selected label is applied to the active document.

* The selected label is displayed on the HaloCAD ribbon, along with the color configured in the Microsoft Purview portal.

* To clear the credential cache, click **Reset** in the **Status**UI.

![After label selection_SW.png](https://help.secude.com/__attachments/a_5fc588059f27adabdf84fc8e69fdb280deaabe11300e18f7f40a72a2a35909ef/After%20label%20selection_SW.png?cb=ec9be8e0e3c03fc71f0ff15537b2dbf7)

*File with applied label*

#### **Cancel, Remove, Relabel, and More**

1. **Canceling Label Selection** : If you have selected an incorrect label, you can cancel it by clicking the red cross icon (**Click to Cancel**). This will remove only the selected label that has not yet been applied to the file.

2. **Removing Protection** : To remove an existing label and keep the file unprotected, select the **No Protection** label from the list. Note: Whenever you change a label, click the green check mark icon (**Click to set label**) to apply the updated label. The file will be saved, and the label will be applied to the active document.

3. **Relabeling** : If you want to apply a different label or modify protection settings (Custom Permissions) after a label has already been applied, first click the pencil icon (**Click to change label** ) and then select a new label from the list. For more details, refer to "[Example 9: Custom Permissions Label](https://help.secude.com/halocad-add-on-for-dassault-systemes-solidworks/2.4/sw-operations-manual.md#CPL)".

4. **Revoke Access** - If an author does not want a user to access the shared file for security reasons, you can prohibit it by clicking **Revoke Access** in the **Status** UI. Please refer to the section "[Example 11: Revoke a File](https://help.secude.com/halocad-add-on-for-dassault-systemes-solidworks/2.4/sw-operations-manual.md#revoke)".

#### Log out an Active User

This section describes how to log out the currently active user from HaloCAD. Logging out ends the active session and allows another user to log in.

1. Go to the **HaloCAD** tab \> click **Status** \> click **Reset**.

2. When the following message appears, click **Yes**.

   ![Reset Clear cached credentials #1_2.png](https://help.secude.com/__attachments/a_3340c6d6baffacec7347f745617bf2cc10882a6e7b83f3b9e282b43946638467/Reset%20Clear%20cached%20credentials%20%231_2.png?cb=883a859681b430cb98051260ecafa62b)

   *Clear cached credentials #1*
3. When the next message appears, click **OK**.

   ![Reset Clear cached credentials #2_2.png](https://help.secude.com/__attachments/a_9659641b1c5ce3a054c29878eda40e9cf9daa9ea8fc476cb7d07db59fb6102e8/Reset%20Clear%20cached%20credentials%20%232_2.png?cb=23441a9334f41a354fcf13df9ea57418)

   *Clear cached credentials #2*
4. Restart the application.

**Result**

* After relaunching the application, users can log in to a new HaloCAD session using their credentials.

* If you do not relaunch the CAD application, HaloCAD displays the following message: *"For HaloCAD to work properly you should relaunch the application now".*

* Click **OK**, and then relaunch the application.

**Next step**

1. **Log in after reset:** After restarting the application, when you open a protected file or click the pencil icon (**Click to change label** ), HaloCAD prompts you to use the Microsoft Sign-In Assistant. Click **OK**, and then sign in with your credentials.

   ![Microsoft Sign-In Assistant invoking message.png](https://help.secude.com/__attachments/a_29a60d784c74fa5e5a4d051d287e4507887174702d435b2265017657b709c6b4/Microsoft%20Sign-In%20Assistant%20invoking%20message_2.png?cb=1f27eeff142b5b05e48f95f0e760e276)

   *Microsoft Sign-In Assistant invoking message*
2. For more information about HaloCAD functionality, see **Common scenarios**.

### How to Export a Protected CAD File to a PDF File?

To convert / export / save a protected file as PDF:

1. Go to **File** \> **Save As**.

2. From the **Save As type** list, select Adobe Portable Document Format (`*.pdf`).

3. Click **Save** on the **Save As** dialog.

**Result**: An exported PDF file is saved with protection.

The protected file may need to be viewed after being exported. To open a protected file, follow the instructions below:

**Prerequisite**: Ensure that the latest version of Acrobat Reader DC or Acrobat DC is installed.

1. Double-click the protected file or open the **Adobe** application, go to the **File** menu \> **Open** \> browse, and select the file.

2. Microsoft Sign-in prompts you to provide your credentials.

3. Enter the credentials and click **Sign in**.

   ![Opening a PDF file using MIP plug-in.png](https://help.secude.com/__attachments/a_485b4987cdc291ba17c5c11c8e8d452dee011ee72a913587c0563e368fa0b4a4/Opening%20a%20PDF%20file%20using%20MIP%20plug-in.png?cb=a809931c9881a9792aed85dec12846e7)

   *Protected PDF File*
4. To the question "*Do you want to stay signed in?* ", answer **Yes**.

**Result**:

* Upon successful authentication, the protected file is opened.

* If authentication fails, access to the file is blocked.

**Next step**

To see the actual permissions that are applied to the file, do one of the following:

* Click on the lock icon \> **Permission Details** \> **Document Properties** screen \> click **Show Details**.

* Click **File** \> **Properties** \> click **Security** tab \> **Document Properties** screen \> click **Show Details**.

### How to View a Protected File in HaloCAD Reader?

The reader add-on is intended for customers who do not have the full HaloCAD solution installed. Secude provides this viewer program to enable end users to view HaloCAD-protected files without having to install the standard (full) version of the HaloCAD solution on their desktops.  
**Reader add-on vs HaloCAD Standard add-on**

Both add-ons use the Microsoft Purview Information Protection security solution. However, the reader add-on cannot function as a HaloCAD Standard add-on; it is limited to opening and reading CAD files that are protected by the Standard/Full add-on.

Prerequisite: Make sure that the HaloCAD Reader Add-on for SOLIDWORKS is installed.

1. Double-click the protected file.

2. HaloCAD will prompt you about the Microsoft Sign-In Assistant before allowing you to access the file.

3. Click **OK.** Enter the credentials and click **Sign in**. (However, you do not require this validation if your cached account information is available.)

**Result**:

* A read-only version of the file opens with the following message.

  ![Reader add-on message.png](https://help.secude.com/__attachments/a_209b017ce4b6bc8cb0cdb8bb2634e29fc2d39148f7c181f6e041b094d242a717/Reader%20add-on%20message.png?cb=66a5d7c362261e416a505c0538f7ab7b)

  *HaloCAD reader message*
* Click **OK** on the HaloCAD reader message. Because the file opens in read-only mode, the pencil icon (**Click to change label**) in the Sensitivity ribbon is disabled. Within the application, some tabs are disabled while others remain enabled, and clicking an enabled menu displays a HaloCAD warning message.

  ![Disabled ICON.png](https://help.secude.com/__attachments/a_aa3bd1e5978570ad6e32a3d3a3819aaf5b36203c007819ee80cbe291b917046e/Disabled%20ICON.png?cb=412c5f81bc32912fc53398a2496efeb4)

  *Disabled Click to change label icon*

**Next step**

The reader add-on gives you the following options, similar to the standard add-on:

* To view the file's permissions, click the **Status**icon.

* To log out an active user from a HaloCAD session, click the **Reset**icon.

## Common Scenarios

This section presents common scenarios for illustrative purposes and provides general guidelines.

### Concept: Sensitivity Labels

MPIP labels can be customized to meet the requirements of each organization. These labels are defined and managed directly in the Microsoft Purview portal, and the HaloCAD Add-on retrieves them for user selection. When a sensitivity label is applied, the associated permission levels are automatically enforced on the document; any rights that are not explicitly granted are not assigned to the user. For example, a label applied to a CAD file with view-only permission allows users to view the content without any additional rights.

1. Let's say, for example, that you set up a label with the "Viewer" permission. In this case, the user will be able to view MPIP-protected content, but the following actions and menus will be disabled:

   1. Pencil icon - **Click to change label** in the HaloCAD Sensitivity ribbon.

   2. All tabs, panels, and buttons in the CAD application.

   3. Edit, Copy, Print, Export, Change Rights, and Revoke options in the **Status** UI. Refer to [Example 1](https://help.secude.com/halocad-add-on-for-dassault-systemes-solidworks/2.4/sw-operations-manual.md#EX1).

2. In contrast to the previous point, if you configure a label with 'Co-Owner' permission, the user will have full access to the file, including the ability to view, edit content, print, copy, and export the file, as well as change rights (labels). Refer to [Example 2](https://help.secude.com/halocad-add-on-for-dassault-systemes-solidworks/2.4/sw-operations-manual.md#EX2).

3. For more details on labels, please refer to Microsoft Documentation.

### How to Open a Protected CAD File?

Follow the procedure below to view the protected file:

1. Click the protected file to open it.

2. When a labeled file is opened for the first time, a connection to the Microsoft Entra tenant is requested via the Microsoft Sign-In Assistant.

3. Click **OK**when prompted that the Microsoft Sign-In Assistant will be invoked and user credentials will be cached.

4. Follow the on-screen instructions to complete the authentication process.

5. After successful authentication, the file opens.

6. Access results for the same document may vary based on the applied policy settings. Please refer to the following examples.

#### Example 1: Label with Read-only Access

1. The MPIP label **HCAD Confidential** is applied to the following file. This label allows the logged-in (connected) user to view the file while restricting all other operations. To view the applied label and your file permissions, click the **HaloCAD** tab and then select **Status**.

   ![User with restricted access #1 Solidworks.png](https://help.secude.com/__attachments/a_47c684a3dee8cfd3974e0c4c9dd42eaafff12457e0e739b06e92c329e05eee23/User%20with%20restricted%20access%20%231%20Solidworks.png?cb=722f51a647a1ed648ebb3dcddc28af58)

   *User with restricted access #1*
2. In case you click the restricted menus/options, you will receive the following HaloCAD pop-up.

   ![User with restricted access #2 SW.png](https://help.secude.com/__attachments/a_128e6181c08f2d122daf7a1572dd72a9083efeed9c9b004d4702a848ccb00521/User%20with%20restricted%20access%20%232%20SW.png?cb=0399e42f8744ae0ab90023e3d18ba2e4)

   *User with restricted access #2*
3. Click **OK**.

**Behavior When Attempting to Copy, Save, or Capture Screen Data**

One of the most common ways confidential information is compromised is by copying it (Ctrl + C) or capturing it using tools such as Print Screen or the Snipping Tool and then transmitting it elsewhere. To prevent this, when a label without the **Copy** usage right is applied, the entire content is blanked out during copy or screen-capture attempts.  
![PrintEX1.png](https://help.secude.com/__attachments/a_f4af23da343c1760204df02f89d1f42b8e666009d5e9f1e8bc84eb21b5119d5a/PrintEX1.png?cb=4df2a9968992505a3ae56eca71bbd839)

*HaloCAD prevents copying data*

**Behavior When Attempting to Relabel with Read-Only Permissions**

With "Read-only / View" rights, you are only allowed to view the content; the pencil icon - **Click to change label** on the HaloCAD Sensitivity ribbon is disabled. As a result, the imposed protection cannot be relabeled or removed.  
![Disabled pencil icon.png](https://help.secude.com/__attachments/a_fbc7d6469043faa1fae307651e993b174d8d59e32ad0e17d546674fb1860bb4a/Disabled%20pencil%20icon.png?cb=8c1488bd46ac63377486bdcba573e2c4)

*Disabled tabs, buttons, and icons*

#### Example 2: Label with Full Control Access

The file shown below is labeled **HCAD Confidential** , which grants the user full access, therefore, all menus are enabled in the file. To view the applied label and your file permissions, click the **HaloCAD** tab and then select **Status** .  
![User with full access #3 Solidworks.png](https://help.secude.com/__attachments/a_e01466aad3ad8b9002e5350325472e3fb423e81b64c227fe6a7cbda1b46c5832/User%20with%20full%20access%20%233%20Solidworks.png?cb=5a78c44286d410ee5b0a1d10ca801480)

*User with full access*

**What Happens if You Try to Relabel with Co-Owner Permission?**

With "Co-Owner" rights, you have complete control over the content and can relabel or remove the protection as needed by clicking the pencil icon - **Click to change label**on the HaloCAD Sensitivity ribbon.

#### Example 3: Unauthorized User Access

An unauthorized user who double-clicks on a protected CAD file receives the warning shown below. Note: An unauthorized user is anyone who is not listed in the allowed user list configured within the Microsoft Purview Information Protection sensitivity label.  
![Example 3 (SOLIDWORKS) read-only Warning.png](https://help.secude.com/__attachments/a_67e3e22c857f4677500b57d312754a972b3b541f1fcbfc6c692b81dc001e1758/Example%203%20(SOLIDWORKS)%20read-only%20Warning.png?cb=9bbfceccdd69589c1ba9a4316510dd5b)

*Unauthorized user opening a protected file*

#### Example 4: Labeling Dependent (Protected and Unprotected) Files

Assume there are dependent parts or sub-assembly files that are protected and unprotected in a Parent Assembly file. When you apply a label to the Parent Assembly file, you must confirm the following action to take effect:  
![Example 4 - mutiple child files.png](https://help.secude.com/__attachments/a_3b8bd472745c1bcec3007fd0949cf20576a963bcd7249a1231860ba6c3a1becd/Example%204%20-%20mutiple%20child%20files.png?cb=9a1207f87e6e10d9d926d93da3423f23)

*Labeling the unprotected and protected child files*

If **Yes**:

* All associated unprotected child files receive the Assembly file's label.

* Already protected child files are relabeled with the Assembly file's label.

* If a child file does not have Owner or Co-owner rights, the Parent label cannot be imposed on the file.

If **No**:

* Only unprotected files receive protection.

* Existing protected child files remain unchanged.

#### Example 5: Labeling Dependent (Unprotected) Files

Assume that a Parent Assembly file contains dependent parts or sub-assembly files that are unprotected, while the Parent Assembly file may be protected or unprotected. When you relabel the Parent Assembly file, the following message appears. Click **OK** to protect both the Parent Assembly file and the dependent files with the same label.  
![Example 5 Assembly with unprotected files.png](https://help.secude.com/__attachments/a_c0a6dc74e491a70d439e04308a50c97a93ac3c645725976010acccc1e88bd5aa/Example%205%20Assembly%20with%20unprotected%20files.png?cb=2eabb124313428927081ad842247cdda)

*Labeling unprotected child files*

#### Example 6: Removing Protection from Assembly and Part Files

Assume that a protected Parent Assembly file contains part or sub-assembly files. To keep the file unprotected, remove the existing label and apply the **--No Protection--** label to the Parent Assembly file. The following message appears:  
![Example 6 Removing Protection from dependent file.png](https://help.secude.com/__attachments/a_b676b928cb48475838102ce9e5ac1b61abc8da913a87743553ca024bebff2852/Example%206%20Removing%20Protection%20from%20dependent%20file.png?cb=2d85dd1339a336e5f45c6ba4363c4dbd)

*Removing protection from dependent files*

You must confirm the following action to take effect:

If **Yes**:

* All associated protected child file labels are removed, and the files are unprotected.

* If a child file does not have Owner or Co-owner rights, protection cannot be removed from the file.

If **No**:

* Only the Parent Assembly file label is removed, and the file is unprotected.

* The labels on the existing protected child files remain unchanged.

#### Example 7: Other Use Case Scenarios

##### **Importing a file with a restricted/least permission label**

A restricted/least permission label refers to a label with the lowest permission, such as view-only access rights. A full permission label has full access rights, such as Edit, Export, Change Rights, and so on.

1. **Case 1** - When you import a dependent part or sub-assembly file protected with a "restricted permission" label into a parent assembly file protected with a "full permission" label, the following HaloCAD pop-up message appears as *"Please confirm applying least permission label from import file? Yes - Current file will be updated with import file label "XXXXXXX". No - Import operation will be cancelled."*

   1. If **Yes** ,then the imported dependent part file's label will be applied to the parent assembly file. For example, the **HCAD Public** label with view rights will be applied.

   2. If **No** ,then the import will be blocked and the parent assembly file will remain unchanged.

2. **Case 2** - When you import a dependent part or sub-assembly file protected with a "full permission" or "restricted permission" label into a parent assembly file that is unprotected, the HaloCAD pop-up message appears as described in Case 1 above. The response (Yes or No) process will also follow the same procedure as in Case 1.

3. **Case 3** - When you import a dependent part or sub-assembly file protected with a "full permission" label into a parent assembly file protected with a "restricted permission" label, the import is allowed and no label changes occur in the parent assembly file.

In addition, when an assembly file is opened, all linked part or sub-assembly files are checked to determine the least restrictive permission among them. If any part or sub-assembly file has the lowest permission level, the parent assembly file adopts that restriction. For example, if a part file is set to 'view-only', the assembly file is also enforced to 'view-only' upon opening.

##### **Labeling a File Without Protection**

Compared to a standard MPIP label, a **label-only MPIP label** adds metadata to a file without applying protection. In this context, *label-only* refers solely to metadata classification. The key difference between a standard **MPIP label** and a **label-only MPIP label** is that the standard label includes encryption and protection options, whereas the label-only variant does not. As a result, a **label-only MPIP label** can be applied to files that do not require protection but still need to be labeled for classification purposes.

**Prerequisite** : Make sure the **Control access** check box under **Choose protection settings for the types of items you selected** page is unchecked while defining the label-only in the Microsoft Purview portal.

**Other key points**

1. When a label-only MPIP label is applied to a file, the suffix (**Label Only** ) is appended to the label name. For example, if the label name defined in the portal is **HCAD Metadata** , it appears as **HCAD Metadata (Label Only)** after being applied to the file.

   ![Label only metadata.png](https://help.secude.com/__attachments/a_008c02c14db1ae868e3875010cde369be69e49a3f1ba0adc1b1edab60cc8fc4f/Label%20only%20metadata.png?cb=6d5bdb8f3c3c6ddaae90c3ff763b9263)

   *MPIP label-only*
2. **Full rights**: A file with this label allows a user to have full rights on it.

3. **Notifications**: Similar to a standard MPIP label, the user will receive notifications when label-only is applied to a top-level parent file.

4. **With the HaloCAD Add-on**: The label details will be displayed in the Status UI, just like a standard MPIP label.

5. **Without the HaloCAD Add-on**: A file with a label-only MPIP label will behave like any other unprotected CAD file.

6. **Properties**: To see label details, follow the instructions below:

   1. Go to **File** \> **Properties**.

   2. Click on the **Custom** tab to view the author name, label ID, and label name.

   3. Furthermore, if watermarking is configured in this label, the **Custom**tab displays additional information such as the font color, font name, font size, layout, and text.

#### Example 8: Label with Content Marking

Applying a watermark indicates what type of content it is and how it should be handled, and its presence in a file serves as a constant reminder to the user that the file contains sensitive information. The file below is labeled **HCAD Secret** and bears the watermark **Secret**.  
![Watermark.png](https://help.secude.com/__attachments/a_2f9b06e71f1da90b0f41d0b38ac3e4118aeaa04aa21d72941e96889557afd122/Watermark.png?cb=20099faba232a0c0585a5282afefa22c)

*Content with watermark*

#### Example 9: Custom Permissions Label

**Difference Between Sensitivity Labels and Custom Permissions**

**Sensitivity Labels**

Sensitivity Labels are defined and managed by an organization's administrator in the Microsoft Purview portal. Each label includes a predefined set of permissions and is also referred to as administrator-defined permissions.

**Custom Permissions**

Custom Permissions are user-selectable permission sets available in the HaloCAD application UI. These permissions are defined by users and are also referred to as user-defined permissions.

##### **Protection using Custom Permissions (User-defined Permissions) from Microsoft Purview Portal**

**Prerequisite** : Make sure the custom permissions label in the portal is set to **Let users assign permissions when they apply the label**.  
![Custom permissions and other labels.png](https://help.secude.com/__attachments/a_001781215eea4721775591d6b6390e23d872aa4627f64602dd31135f785bca58/Custom%20permissions%20and%20other%20labels.png?cb=79b3128a59e46f39243148c26ea83813)

*Custom permissions and other labels*

Follow the procedure to apply the custom permissions label:

1. Open the SOLIDWORKS application, select a template, and then create objects.

2. Click the **Click to change label** icon.

3. When HaloCAD downloads the labels, custom permission labels (from the Microsoft Purview portal and user-defined labels) are listed in the Sensitivity ribbon.

4. For illustration, the custom permission label from Microsoft Purview is named **Custom Permissions (Portal)**.

5. Select the **Custom Permissions (Portal)** label from the list and click the green check mark (**Click to set label icon**).

6. The HaloCAD screen appears, as shown below.

   ![HaloCAD Custom permissions.png](https://help.secude.com/__attachments/a_c58b469aa2ec790439dbe4fb71b0a3a799fcaa5bd1d34c311171a434fe8d38ba/HaloCAD%20Custom%20permissions.png?cb=a7defa3e0a5bd8bac710fe5e2162e14a)

   *Custom permissions*
7. From the **Select Permission** list, choose the level of access you want users to have when protecting the file: (Viewer - View Only / Reviewer - View, Edit / Co-Author - View, Edit, Copy, Print / Co-Owner - All Permissions / Only for me).

8. In **Enter Users, Groups, or Organizations**, specify who should have access to the file. Enter individual email addresses, group email addresses, or an organization domain, separated by commas, spaces, or semicolons.

9. In the **Expire Access** field, specify how long the labeled file can be accessed. Select **Never**for unlimited access, suitable for less sensitive content. For highly sensitive content, select an expiry date so that recipients (other than the owner) cannot access the file after that date.

10. Click the **Clear date selection** option to clear the previous date selection.

11. Click **Apply** to confirm the protection settings.

**Result:** The label is applied to the file.

**What happens when a user opens a custom permissions--labeled file?**

Based on the user's permissions, the file can be accessed accordingly. Note: The author of the document always has full rights to the file and can access it at any time, regardless of any custom permissions or expiry date configured in the label. The following example shows a label with custom permissions.  
![User with custom permission.png](https://help.secude.com/__attachments/a_f46bb694eaf6cc0c071a86d06e75251ac5006d5f1c0c720cf04140397448832d/User%20with%20custom%20permission.png?cb=9cda67d2002849a7fcab56e653bdc328)

*User with custom permission*

##### **Protection using Custom Permissions (User-defined Permissions) via HaloCAD Add-on**

In comparison to the previous section, the HaloCAD add-on also supports a **Custom Permissions** label. However, this label is defined at the application level within HaloCAD and is not obtained from the Microsoft Purview portal. The process for applying this label is the same as described in the previous section.

#### Example 10: Set an Expiration Date for File Access

**Prerequisites:**

1. Ensure that the expiration date is configured in the Microsoft Purview portal when using a static MPIP label.

2. Ensure that the expiration date is configured in the Custom Permissions label when using it via the Microsoft Purview portal or the HaloCAD add-on.

##### Why is File Expiration Necessary?

When files are shared with external vendors, access may continue even after a contract ends, creating security risks. To prevent this, set an expiration date on the file. This is a recommended practice when working with vendors or contractors. For example, if a file is shared with an expiration date of 31/12/2028, business partners will not be able to open it after that date. Each time the file is opened, HaloCAD displays the file's validity.  
![Validity of the file.png](https://help.secude.com/__attachments/a_00d4528c8fc26429ec80c1433a30e289f61ae354b05dad82fc5604cc9d656728/Validity%20of%20the%20file.png?cb=c0490b7d9d9b3be46dad4d4a8162da1f)

*Validity of the file*

##### **What Happens When a File Expires?**

When a user opens a file that has reached its expiration date in their current time zone, the labeled file cannot be opened. HaloCAD will prompt a message "*You do not have sufficient permissions to view this document."* This behavior is like unauthorized file access, as described in the section "[Example 3: Unauthorized User Access](https://help.secude.com/halocad-add-on-for-dassault-systemes-solidworks/2.4/sw-operations-manual.md#EX3)".

##### **How to Open an Expired File**

Recipients cannot open an expired file. Only the file author can access it. If a recipient needs continued access, they must contact the author to obtain a new copy of the file with an updated expiration date.

#### Example 11: Revoke a File

Prerequisite: Ensure that the user who wants to revoke a file has the required license, as specified in the Release Notes under the Requirements section.

Revoke Feature: MPIP provides a revoke feature that prevents any new access attempts to a protected file, restricting access to all users except the author. Note that revoking access removes permissions for all users associated with that label.

##### Why Should a User Revoke a File?

A user may revoke access to a sensitive file if it was sent by mistake, accessed from a suspicious location, leaked, or if a recipient no longer requires access. In these scenarios, the author can immediately prevent further access by revoking the file. Note: Revoking does not delete the shared file, but users will no longer be able to open it. The **Revoke Access** button is available on the HaloCAD status screen.

##### **How to Revoke a File?**

1. To revoke a file, go to the **HaloCAD** tab \> click **Status** \> click the **Revoke** **Access**. The following message will appear:

   ![Revoke access message #1.png](https://help.secude.com/__attachments/a_3935a3ecdef704bf11cb09e94d5b0661970208e66773d30aaf2d63cd21403caf/Revoke%20access%20message%20%231.png?cb=365addd000b9d1b5642445854726d45b)

   *Revoke access message #1*
2. Click **Yes** to confirm revoking access and continue with [step 3](https://help.secude.com/halocad-add-on-for-dassault-systemes-solidworks/2.4/sw-operations-manual.md#revokestep3). If you do not have the required license, it is not possible to revoke a file. In this instance, HaloCAD will show the alert as follows:

   ![Access denied revoking a file.png](https://help.secude.com/__attachments/a_f306019bd1f00395579d9ecb3c2fac07cd3dd29b3d3a22acbb137ffc026f7e89/Access%20denied%20revoking%20a%20file.png?cb=cd46f6aa154b6bbca7e0a3c49f985813)

   *Access denied when revoking a file*
3. The following message will appear:

   ![Revoke access message #2.png](https://help.secude.com/__attachments/a_fd5e36246f7d560fac85d4227dc2d65a240426669ad0cdae46fabed157dd3ffa/Revoke%20access%20message%20%232.png?cb=da510811dee08e09c9ad44d22e813571)

   *Revoke access message #2*
4. Click **OK**and save the file.

**Result:**

* Access to the file is revoked.

* Users who previously had access to the document can no longer open it.

##### **What Happens if a User Attempts to Open the Revoked File?**

Once the file is revoked, the user cannot open it, although the user has accessed it before. HaloCAD shows a generic message as "*You do not have sufficient permissions to view this document."* This behavior is like unauthorized file access, as described in the section "[Example 3: Unauthorized User Access](https://help.secude.com/halocad-add-on-for-dassault-systemes-solidworks/2.4/sw-operations-manual.md#EX3)".  
**MIP SDK**

A revoked file can be accessed by the same user if it was previously opened by the same user in the same HaloCAD session. This is due to the actual behavior of the MIP SDK if you have defined the sensitivity label with the two options **Allow offline access** and **Users have offline access to the content for this many days,** the configured offline access allows users to continue to access the revoked file until the offline policy period ends.

##### **What Happens if a User Changes the Label?**

Assume User A shares a sensitive file with User B.

**Case 1:** If User B makes copies of the original document, revoking file access by User A will also revoke all copies, since the label remains unchanged.

**Case 2:** If User A has not revoked access and User B (with full rights) changes the label, revoking file access will not apply to that modified copy. However, the original document will still be revoked.

##### **How to Open the Revoked File?**

A recipient cannot open a revoked file. Only the file author can access it. If a recipient needs access, they must contact the author to obtain a new copy of the file.

## **Troubleshooting**

This chapter will help you overcome the most common problems with the HaloCAD solution.

### **Cannot Sign in to Microsoft Sign-In Assistant**

**Symptoms**

The user login fails with the following error message.  
![Error Message.png](https://help.secude.com/__attachments/a_e062bce6040e45d96c298c60c3affacddf074b7d9985d61f3a4b4a64631e055e/Error%20Message.png?cb=6d9b3e79084c244dd66b83c93336a910)

*Microsoft Sign-in error message*

**Background**

The above error occurs when a user logs in to a HaloCAD session using Microsoft Sign-In Assistant.

**Probable Cause**

As the Redirect URL specified in the request does not match the URL configured for the registered application, Microsoft Sign-in fails.

**Corrective Action**

1. **Case 1:** An incorrect Redirect URI was entered during the HaloCAD installation.

   1. Reinstall the HaloCAD Add-on using the correct **Redirect URI**.

   2. Launch the CAD application, click the pencil icon (**Click to change label**), and sign in using the Microsoft Sign-In Assistant.

2. **Case 2** : Redirect URIs use an improper scheme (such as `http://contoso.com`)

   1. Log in to the Microsoft Azure portal.

   2. On the home page, click the **Show Portal Menu** icon, then select **Microsoft Entra ID**.

   3. Under the **Manage** section on your tenant's **Overview** page, choose **App registrations**.

   4. Click **All Applications**, and enter your application name in the search bar.

   5. From the list, select your application.

   6. Click the **Redirect URIs** link or select **Authentication** from the **Manage**section on the application overview page.

   7. Verify that the reply URL begins with https://. If it does not, update it to https and save the changes.

      ![Incorrect Redirect URIs.png](/__attachments/a_a29c1ee42d47ad7d1334745b830d982e1a22fc5027d0423b80a91aa78f6d0868/Incorrect%20Redirect%20URIs.png?cb=e53194da9917a03c5e13fc8432d01cf9)

      *Incorrect Redirect URIs*
   8. Now, sign in using the Microsoft Sign-In Assistant.

3. **Case 3**: Tenant ID provided for multi-tenant application

   1. Reinstall the HaloCAD Add-on without entering the **Tenant ID**.

   2. Open the CAD application, click the pencil icon (**Click to change label**), and sign in using the Microsoft Sign-In Assistant.

### **Labels are not Getting Downloaded in the HaloCAD Session**

**Symptoms**

The user could not download labels.

**Background**

The user logs in successfully in the HaloCAD session, but cannot download labels.

**Probable Cause**

Improper label configuration in the Microsoft Purview portal.

**Corrective Action**

1. Log in to the Microsoft Purview portal as a global administrator.

2. Ensure that the labels are configured to apply protection.

3. Verify that the user has the required policy to use the label.

4. For more details, refer to the Microsoft documentation.

### **Label not Found in the Policy**

**Symptoms**

HaloCAD prompts the following message:  
![Label not found.png](https://help.secude.com/__attachments/a_5d4d8d0d6950f0c0a2789d6df741c7627d82647732a831ee3bc17134148e411e/Label%20not%20found.png?cb=42657b787053faa9668d2f34dee1ac87)

*Label not found error message*

**Background**

The above message is shown when you apply a label to a file and save it.

**Probable Cause**

Improper label configuration.

**Corrective Action**

Request your Microsoft Purview portal administrator to review the label and publish label policies.

### **Double Key Encryption Label could not be Applied**

**Symptoms**

HaloCAD prompts the following message:  
![Label could not be applied.png](https://help.secude.com/__attachments/a_f2e758e94f208d1e40b975c82357c466fa9700e23e902596b8b6b8c4a2805cb3/Label%20could%20not%20be%20applied.png?cb=a4d057352d6127ca811d925833449e95)

*DKE label error message*

**Background**

The above message is shown when you apply a Double Key Encryption (DKE) label to a file and save it.

**Probable Cause**

This issue occurs if the DKE service is stopped or unavailable.

**Corrective Action**

Make sure that the DKE service on the client's computer is active and accessible online.

### **Could not Connect to MPIP -- Case 1**

**Symptoms**

HaloCAD prompts the following message:  
![1_Azure RMS connection fails - wrong values.png](https://help.secude.com/__attachments/a_3baf0ee870b6297941b796e54ed9b290cdab36197b86c3af76cb4c6c67a78709/1_Azure%20RMS%20connection%20fails%20-%20wrong%20values.png?cb=082ddb7cd5d607e89817b925614b8284)

*MPIP connection warning message #1*

**Background**

The above error occurs when a user logs in to the HaloCAD session via Microsoft Sign-In Assistant.

**Probable Cause**

This issue occurs if one or more of the following conditions are true:

1. **Case 1** : You have entered the incorrect **Application (client) ID** , **Directory (tenant) ID** , and **Redirect URI**.

2. **Case 2**: You have closed the Microsoft Sign-In Assistant dialog unknowingly.

**Corrective Action**

1. **Case 1** : Make sure the correct values of **Application (client) ID** , **Directory (tenant) ID** , and **Redirect URI** are entered during the initialization.

2. **Case 2**: Relaunch the application and enter user credentials in the Microsoft Sign-In Assistant dialog.

### **Could not Connect to MPIP -- Case 2**

**Symptoms**

HaloCAD prompts the following message:  
![2_Azure RMS connection fails- Network issue.png](https://help.secude.com/__attachments/a_164d1ea8e2e7a46d20402a73246df178c79822cd4ec297f03064b0b702185fef/2_Azure%20RMS%20connection%20fails-%20Network%20issue.png?cb=55d7256dc1db86eb2959362ef8f9b728)

*MPIP connection warning message #2*

**Background**

The above error occurs when a user logs in to the HaloCAD session via Microsoft Sign-In Assistant.

**Probable Cause**

The most likely cause of this issue is that your network is preventing you from connecting to Microsoft Purview Information Protection.

**Corrective Action**

1. Review yourfirewalls or network infrastructure to establish a connection with Azure.

2. Check if your proxy limits the URL.

### **HaloCAD Activation Fails**

**Symptoms**

HaloCAD prompts the following message:  
![Exceeded maximum activation.png](https://help.secude.com/__attachments/a_28a4f73284ceee4690a3b1dce1ba057c7818bec3e5bcced984e66c86d848a397/Exceeded%20maximum%20activation.png?cb=df5eb60ae6e98694e03d722487b3100f)

*HaloCAD Activation warning message*

**Background**

The above message is shown when you try to activate HaloCAD on a system.

**Probable Cause**

After a successful license activation, the license status changes to **Active** , and the **Total activations** count in Secude's License Server Manager increases by one. The total activation count increments with each activation.

For example, if you purchased ten HaloCAD licenses, you can activate HaloCAD up to ten systems. After the tenth activation, attempting to activate HaloCAD on another system will fail, and the License Server Manager will display an error indicating that the maximum number of activations has been reached.

**Corrective Action**

1. **Action 1:** Uninstall one or more HaloCAD add-ons that were previously activated on a CAD system, and then activate the license on the required CAD system.

2. **(Or) Action 2:** Purchase an additional HaloCAD license.

3. After completing the action, activate the license.

### **Incorrect License Key Error Message**

**Symptoms**

HaloCAD prompts the following message:  
![Incorrect license activation message.png](https://help.secude.com/__attachments/a_ad9f4a84c5220e4468687bce464b3f4fc94381af4c7b025fc2315ab35d59b3df/Incorrect%20license%20activation%20message.png?cb=cb267dc0092fe4945e1fb661682fcde4)

*Incorrect license activation message*

**Background**

The above message is shown when you try to activate HaloCAD on a system.

**Probable Cause**

There are various possible reasons, including a license key associated with another HaloCAD, an incorrect key, or an invalid key.

**Corrective Action**

Make sure to enter the correct licensing key, unique to this add-on, before activating it.

### **Why Am I Getting License Expiration Notifications?**

**Symptoms**

HaloCAD prompts the following message:  
![Prior message for expiration..png](https://help.secude.com/__attachments/a_0bdbecf7770951b79acc7c38d70c88eb934af268f62d011739887bef4d48fe52/Prior%20message%20for%20expiration..png?cb=c97540b1f90a870ddaebd37429107c0b)

*HaloCAD notification*

**Background**

The above notification occurs once a day when a user logs into the HaloCAD session.

**Probable Cause**

When you run the CAD application and see a HaloCAD expiration alert, it means action is required to continue using the add-on.

Each license has an end date defined at the time of issue. When the license is within 30 days of expiry, the License Manager triggers daily notifications in HaloCAD. For example, if the license expires on September 30, 2028, notifications will begin appearing once per day starting September 1, 2028.

**Corrective Action**

1. Purchase a new HaloCAD license or renew the existing license.

2. Activate the license.

### **Other License-Related Error Messages**

|                 **HaloCAD License Error Messages**                  |                                     **Root Cause**                                     |                                                **Correction Action**                                                |
|---------------------------------------------------------------------|----------------------------------------------------------------------------------------|---------------------------------------------------------------------------------------------------------------------|
| The license validity period has expired                             | When your license had just expired.                                                    | Please contact Secude's representative to receive a new license.                                                    |
| The license is not enabled.                                         | When you try to activate a license key that is already disabled on the License portal. | Please contact Secude's representative to enable the license.                                                       |
| This device is blacklisted.                                         | When your device is blocked in the license portal for a specific reason.               | Please contact Secude's representative to enable the device.                                                        |
| This license cannot be activated before the start date: yyyy-mm-dd. | When attempting to activate a license before its start date.                           | Please make sure the license is activated on the start date.                                                        |
| Date header is not valid or set in past.                            | When the date or time on the machine is incorrect.                                     | Please make sure that the machine installed with the HaloCAD add-on is synchronized with the current date and time. |

*License-related error messages*

## Technical Support

Before contacting Technical Support, ensure that you have the following information available. Providing this information helps the support team investigate and resolve your issue more efficiently.

* Full contact details

* Product build version

* Date, time, and description of the error (include screenshots, if possible)

* Details of any third-party software used with the product

* Any additional information required to reproduce the issue

**Contact Technical Support**

Secude provides technical support through email [++support@secude.com++](mailto:support@secude.com). When contacting Technical Support by email, include your company details, a detailed description of the issue, and the relevant log files (if available). A support representative will respond to your inquiry.

**Additional Resources**

Visit the Secude website [++https://secude.com++](https://secude.com/) to learn about upcoming events, press releases, and to download white papers.

**Documentation Feedback**

Secude values your feedback and continuously strives to improve product documentation. To provide feedback, send an email to: [++documentation@secude.com++](mailto:documentation@secude.com)

Include the following details in your feedback:

* Product name and version

* Documentation topic

* Description of the suggestion or error

The technical documentation team reviews all feedback and incorporates relevant updates in future documentation releases.

---
version: "2.4"
language: "en"
---
# Release Notes

## Introduction

The release notes provide brief and high-level descriptions of the new features of HaloCAD. Before installing HaloCAD, it is recommended to read the release notes to understand any current limitations or bugs that may apply to this version of the software.

## Product Description

HaloCAD acts as the guardian of your CAD files by automatically protecting them with Microsoft Purview Information Protection (MPIP) labels whenever they leave your secure IT perimeter. As a plug-in for CAD applications, HaloCAD offers access to MPIP-protected files, including label handling and privilege enforcement. CAD users will not notice any differences in the handling of CAD files because protection takes place in the background. By seamlessly attaching MPIP labels to the CAD files while they are being created, it provides end-to-end security for those files.

## System Requirements

The following system requirements table specifies the minimum and recommended technical specifications, such as software and network resources, necessary to run the product.  

|       **Components**        |                                                                                                                                                                                                                          **Details**                                                                                                                                                                                                                           |
|-----------------------------|----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| Supported Operating Systems | Windows 11 or above with updates installed.                                                                                                                                                                                                                                                                                                                                                                                                                    |
| Supported file types        | 1. File types supported for Save and Open: `.sldprt`, `.sldasm`, `.slddrw`, `.step`, `.stp`, `.iges`, `.igs`, `.3mf`, `.dwg`, `.dxf`, `.x_t`, `.stl`, `.vda`, `.sat` 2. File types supported for Export: `.3dxml`,`.sat`, `.amf`, `.ai`, `.psd`,`.pdf`, `.eprt`, `.sldftp`, `.hcg`, `.hsf`, `.ifc`,`.pdf`, `.jpg`, `.sldlfp`, `.xaml`, `.prtdot`, `.ply`, `.png`, `.prt`, `.tif`, `.asm`, `.easm`, `.smj`, `.wrl`, `.edrw`, `.drwpot`, `.gltf`, `.glb`, `.ifc` |
| Supporting application      | To view the encrypted PDF files, install the latest version of Acrobat Reader DC / Acrobat DC.                                                                                                                                                                                                                                                                                                                                                                 |

*Requirements*

**Supported CAD applications for HaloCAD Add-ons**  

|    **CAD applications**     | **HaloCAD Add-on version** |
|-----------------------------|----------------------------|
| SOLIDWORKS 2024, 2025, 2026 | 2.4                        |
| SOLIDWORKS 2023, 2024, 2025 | 2.3                        |
| SOLIDWORKS 2022, 2023, 2024 | 2.1, 2.2                   |

*CAD applications and the HaloCAD Add-on version*

## Prerequisites

Before installing the add-on, ensure that the following prerequisites are met:

1. An application is registered with Microsoft Entra ID.

2. An active Office 365 subscription is available.

3. Access to the recommended URLs is enabled.

4. TLS 1.2 or later is enabled on all client workstations to ensure secure communication.

For more information, refer to the **Technical Reference Manual**.

## Code Quality and Security

Secude focuses on software quality and security. This is accomplished by adhering to and exceeding best practices in development, testing, and quality control. Secude has chosen SonarQube as the first building block for building and implementing a robust continuous code quality assurance (QA). SonarQube is a platform for static code analysis for continuous inspection of code quality. It performs automatic reviews of code to detect bugs, code smells, unit test coverage, and security issues in 29 programming languages.

SonarQube is utilized throughout the development process at Secude, and only the highest marks are accepted for a product to be released. It helps to regulate code quality from the beginning of development, find and repair issues promptly, and improve overall software stability.

Each build report can be found under its relevant version heading in this release notes.

**Reliability Rating**

1. A = 0 Bugs

2. B = at least 1 Minor Bug

3. C = at least 1 Major Bug

4. D = at least 1 Critical Bug

5. E = at least 1 Blocker Bug

**Security Rating**

1. A = 0 Vulnerabilities

2. B = at least 1 Minor Vulnerability

3. C = at least 1 Major Vulnerability

4. D = at least 1 Critical Vulnerability

5. E = at least 1 Blocker Vulnerability

**Security Review Rating**

The Security Review Rating is a letter grade based on the percentage of Reviewed (Fixed or Safe) Security Hotspots.

1. A = \>= 80%

2. B = \>= 70% and \<80%

3. C = \>= 50% and \<70%

4. D = \>= 30% and \<50%

5. E = \< 30%

**Maintainability Rating**

A=0-0.05, B=0.06-0.1, C=0.11-0.20, D=0.21-0.5, E=0.51-1

The Maintainability Rating scale can be alternatively stated by saying that if the outstanding remediation cost is:

1. \<=5% of the time that has already gone into the application, the rating is A

2. Between 6 to 10%, the rating is a B

3. Between 11 to 20%, the rating is a C

4. Between 21 to 50%, the rating is a D

5. Anything over 50% is an E

## Build 2.4

This chapter provides an overview of the updates and quality insights included in this release. It covers the fixed issues, improvements, limitations, new features, and known issues, along with a summary of SonarQube's key parameters to highlight code quality metrics and analysis results.

### New Features

There are no new features to highlight in this release.

### Improvements

This section lists the improvements in the current release.

1. Improved token-sharing encryption and FIPS compatibility by ensuring proper OpenSSL FIPS context initialization and preventing failures in child processes during configuration decryption. HCADSW-560

2. Added support to display online documentation directly from the installer UI for both the standard and Reader add-on installers. When the **Online Help** button is clicked, the online documentation now opens in the user's default browser. HCADSW-571

3. Added default values for silent command-line parameters.

4. Added support for SOLIDWORKS 2026. HCADACD-574

5. In previous releases, asterisks were used in MIP SDK logs to mask Personally Identifiable Information (PII), such as email names and IP addresses. This feature is now extended to HaloCAD logs to also mask information such as label name, label ID, engine ID, policy ID, and watermark text.

### Fixed Issues

This section provides a list of the fixed issues in the current release.

1. Fixed an issue where a Microsoft pop-up is displayed when opening a protected IGES or STEP file, even when the user cache is already available. HCADSW-570

2. Fixed an issue where the SOLIDWORKS application hangs when importing a protected large Assembly STEP file. HCADSW-578, HCADSW-579

### Known Issues

This section describes the known issues with the current release.

1. It is possible to export the protected file using the **Motion Study 1** option without export rights. HCADSW-162

2. It is possible to modify the design using the **Assembly** features \> **Hole Series** option in the view-only rights-protected file and save it as an unprotected file. HCADSW-204

3. It is possible to modify the Bill of Materials **Part number and Description** in a protected drawing file with view-only rights. HCADSW-205

4. Without copy permission, it is possible to take a screenshot of a protected file in the **Task Preview** window. HCADSW-216

5. Protected files can be modified with view rights, and the connected user will be updated as the owner of the file in the HaloCAD status window when the file is opened at a network location. HCADSW-264

6. If the HaloCAD Tomcat service is stopped when opening a Keytech file, the SOLIDWORKS application crashes, and the file opens as unprotected. HCADSW-328

7. HaloCAD Add-on for SOLIDWORKS cannot be uninstalled via the control panel intermittently, as the HaloCAD uninstall dialog does not appear. HCADSW-371

8. The SOLIDWORKS application will crash if a protected part file is opened from the **Welcome-SOLIDWORKS** screen \> click **Open** . HCADSW-501

9. SOLIDWORKS PDM: When opening a protected file from the SOLIDWORKS PDM VAULT folder, the **Save As** window will appear, and the protected file will be saved in the folder. HCADSW-511

10. Intermittently, an error may occur and prevent a protected large STEP file from opening. HCADSW-586

### Unsupported Versions

Support for SOLIDWORKS 2023 has been removed in this release.

## Quality Gate Report

Please see the table below for a list of SonarQube's key parameters for this version. Refer to the "[Code Quality and Security](https://help.secude.com/halocad-add-on-for-dassault-systemes-solidworks/2.4/sw-release-notes.md#code)" section for more information on rating definitions.  

|         **Metric**         | **Value** |
|----------------------------|-----------|
| Coverage                   | 82.9%     |
| Maintainability Rating     | A         |
| Reliability Rating         | A         |
| Security Hotspots Reviewed | A         |
| Security Rating            | A         |

*Quality Gate report*

---
version: "2.4"
language: "en"
---
# Technical Reference Manual

## Introduction

Companies across industries, such as automotive, aviation, and high tech, create and manage their intellectual property (IP) based on drawings. These drawings are created digitally using computer-aided design (CAD) applications and are shared with users outside the organization owing to business considerations. It's essential to understand the potential risks associated with sharing business information. Comprehensive security measures are essential to reducing risks and safeguarding sensitive data. HaloCAD, a purpose-built data protection solution, is designed to help organizations achieve this objective effectively.

### How does HaloCAD protect your Data?

HaloCAD effortlessly integrates Microsoft Purview Information Protection (MPIP), formerly known as Microsoft Information Protection (MIP), the leading technology for Enterprise Digital Rights Management (EDRM). It acts as a shield for your CAD files by automatically labeling them with MPIP and manages data assets across your environment. HaloCAD modules can be used either in standalone mode or in combination with HaloCAD for PLM, which automatically protects file downloads, decrypts files during upload, and returns them to the PLM vault.  
![HaloCAD's high-level architecture.png](https://help.secude.com/__attachments/a_9c49fd7a94b909d74cf3547914e8d7b8ef8279319c0219671f14ae4de814ecd6/HaloCAD's%20high-level%20architecture.png?cb=9a10e8622ee0fddb28499b27d61f4613)

*HaloCAD Add-on for CAD applications*

### About this Manual

This manual provides administrators with the information required to successfully deploy HaloCAD components. It explains how to set up the HaloCAD environment, describes the overall architecture, lists the prerequisites and system requirements for each component, and offers step-by-step guidance for installation and configuration. The manual covers the HaloCAD Add-on for CAD, the HaloCAD Reader Add-on for CAD, HaloCAD for Viewers, HaloCAD for TCAI, and HaloCAD for PLM and PDM, along with detailed explanations to ensure smooth implementation and usage.

The term **HaloCAD Add-on for CAD** is a generic reference to the supported CAD applications, namely AutoCAD, Inventor, Revit, Creo, Solid Edge, NX, SOLIDWORKS, and DraftSight. Throughout this manual, any reference to this term denotes these supported CAD applications. Additionally, the HaloCAD Add-on for CAD includes a corresponding reader add-on for each of the above-listed applications, which is collectively referred to by the generic term **HaloCAD Reader Add-on for CAD**.

The term **HaloCAD for PLM** is a general reference to the supported PLM applications, namely Teamcenter, Windchill, and Autodesk Vault. Wherever this term appears in the manual, it denotes these supported PLM systems. Similarly, references to **HaloCAD for PDM** correspond to SOLIDWORKS PDM.  
This is the primary document that administrators should read before installing the HaloCAD components. After completing this, proceed with the installation and operations manuals.

### Features

1. **Business infrastructure**: HaloCAD connects effortlessly with existing infrastructure, making it simple to use and manage.

2. **CAD:**HaloCAD add-on seamlessly extends MPIP security to CAD files.

3. **Usage rights**: Applies label-based protection using Microsoft Purview Information Protection (MPIP) and user-defined custom permissions.

4. **Data security**: Sensitive information is protected persistently regardless of where it is moved, including mobile and cloud platforms.

5. **Data Access and Usage**: Policy enforcement for managing sensitive file access and usage.

   1. Policies specify who has access to sensitive files and what actions they can do with them.

   2. Furthermore, it specifies how data may be used, such as restrictions on viewing, editing, copying, printing, exporting, relabeling, or modifying the rights. Watermarks can be applied to documents that contain sensitive information.

6. **Seamless integration with PLM**: Automatically protects file downloads, decrypts files during upload, and returns them to the PLM vault.

## Quick Start Installation Summary - Standalone HaloCAD Add-on

The image below illustrates the high-level process of setting up the HaloCAD Add-on for CAD.  
![TechReference_Quick start - standalone .png](https://help.secude.com/__attachments/a_93c4798c470b59425b5ac57058b31621bb4b3911989ac3ae3d2b5fa50199a056/TechReference_Quick%20start%20-%20standalone%20.png?cb=f5ead24b2b28007828631bad33621938)

*Quick start installation steps for HaloCAD Standalone Add-on*  
![TechReference_Quick Start Reader Add-on.png](https://help.secude.com/__attachments/a_1499a0e0d0c94824ab128d162779228e94f2a85ece9d4b1f5b6e196acda3e35a/TechReference_Quick%20Start%20Reader%20Add-on.png?cb=e990f5d975398e57f2c86678eac3c685)

*Quick start installation steps for HaloCAD Reader Add-on*

**Reference Manuals**

The table below describes where to obtain information in the HaloCAD documentation set.  

|                                                                                **For information on**                                                                                |                   **Name of the Reference**                    |
|--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|----------------------------------------------------------------|
| 1. Prerequisites, architecture, and supported license activation methods 2. Secure installation using an encrypted JSON configuration file 3. Actions to take when a license expires | Please refer to the current manual.                            |
| HaloCAD Installation Options -- UI, Silent, and SCCM                                                                                                                                 | Refer to the Installation Manual for the add-on you purchased. |
| HaloCAD features, operations, and troubleshooting, if you face any issues                                                                                                            | Refer to the Operations Manual for the add-on you purchased.   |
| Overview of new features, resolved issues, known issues, and supported file types                                                                                                    | Refer to the Release Notes for the add-on you purchased.       |

*HaloCAD standalone add-on reference documentation*

## Quick Start Installation Summary - Integrated with PLM/PDM

The image below illustrates the high-level process of setting up the **HaloCAD Add-on for CAD** with **HaloCAD for PLM/PDM** environment.  
![TechReference_Quick start_PLM-PDM.png](https://help.secude.com/__attachments/a_f35c3f3e9828066ac2b272e243af683c24c983bc740156e1b1851239f18ee2d2/TechReference_Quick%20start_PLM-PDM.png?cb=f1f21476c16f52782f2d7c44f25661e8)

*Quick start installation steps for HaloCAD for PLM/PDM*

**Reference Manuals**

The table below describes where to obtain information in the HaloCAD documentation set.  

|                        **For information on**                         |                          **Name of the Reference**                          |
|-----------------------------------------------------------------------|-----------------------------------------------------------------------------|
| Step 1 -- Registering an Application in Entra ID.                     | Please refer to the current manual.                                         |
| Step 2 -- How to install HaloCAD Add-on for CAD.                      | Refer to the Installation Manual for the add-on you purchased.              |
| Step 3 -- How to install HaloENGINE.                                  | `HaloENGINE_Manual_Installation_EN_Online.pdf`                              |
| Step 4 -- How to install HaloCAD for PLM/PDM.                         | Refer to the Installation Manual for the HaloCAD for PLM/PDM you purchased. |
| Step 5 and Step 6 -- Workflow illustrating protection and decryption. | Refer to the Operations Manual for the HaloCAD for PLM/PDM you purchased.   |

*HaloCAD for PLM/PDM reference documentation*  
**About the Term "HaloENGINE Tomcat Service"**

The HaloENGINE Tomcat Service is a common component used in both the HaloENGINE and HaloCAD products. Since it was initially developed for HaloENGINE and later adopted across HaloCAD, all Tomcat instances in Secude appear under the name "HaloENGINE Tomcat Service."

## Quick Start Installation Summary - HaloCAD for Viewers

The image below illustrates the high-level process of setting up HaloCAD for Viewers.  
![TechReference_Quicl Start - Viewers.png](https://help.secude.com/__attachments/a_89d69f3d1985444d1fef20aabb2d7b81be9dca7e4ca55a094fc78d37fc326c3d/TechReference_Quicl%20Start%20-%20Viewers.png?cb=8eae1af140d7e0e42c619971fa5a0bf6)

*Quick start installation steps for HaloCAD for Viewers*

For HaloCAD for TCAI, follow the same Quick Start installation steps described for HaloCAD for Viewers. Refer to the HaloCAD for TCAI documentation set for additional information.

**Reference Manuals**

The table below describes where to obtain information in the HaloCAD documentation set.  

|                                                                                **For information on**                                                                                |                  **Name of the Reference**                  |
|--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|-------------------------------------------------------------|
| 1. Prerequisites, architecture, and supported license activation methods 2. Secure installation using an encrypted JSON configuration file 3. Actions to take when a license expires | Please refer to the current manual.                         |
| Installation Options -- UI, Silent, and SCCM                                                                                                                                         | `HaloCAD_Viewers_Manual_InstallationAndUsage_EN_Online.pdf` |
| Overview of new features, resolved issues, known issues, and supported file types                                                                                                    | `HaloCAD_Viewers_ReleaseNotes_EN_Online.pdf`                |

*HaloCAD* *for Viewers reference documentation*

## HaloCAD Architecture

The architecture is designed to provide secure and efficient management of CAD and PLM data through three core components: HaloCAD Add-on for CAD, HaloCAD for PLM, and the HaloENGINE.

### HaloCAD Add-on for CAD

A standalone solution that contains the HaloCAD PROTECT feature. It enables access to protected files, enforces associated privileges, and allows controlled modification of MPIP labels via direct interaction with the user.

HaloCAD Add-on for CAD leverages the Microsoft Purview Information Protection solution to provide persistent document security. During the process of creating a new CAD file, the user downloads MPIP labels using valid credentials, selects a suitable label, and applies it to the file. In the standalone add-on, no automation is available, as setting labels is done manually. Protected files can only be opened and modified by authorized users, and thus, protection remains even when multiple users access the file. The user's rights are governed by pre-established policies. The following figure shows the HaloCAD Add-on for CAD as a standalone add-on.  
![TechReference_Fullmode.png](https://help.secude.com/__attachments/a_13af6708c53ca3f91f3ddab8c826fedea913b815ea5bbe86a374250f1052aacb/TechReference_Fullmode.png?cb=5de7b834c5831259fd3ce9a53184fccc)

*HaloCAD as a standalone add-on*

Note: When HaloCAD (standalone add-on) is integrated with HaloCAD for PLM, files are automatically protected based on predefined rules before the end user can access them.

### HaloCAD Reader Add-on for CAD

Secude offers a standalone reader add-on for CAD applications that lets you view MPIP-protected files containing sensitive data. It enforces 'read-only' privileges to all users and thus even authorized users cannot sneak sensitive information out by copying it or taking a screenshot. Additionally, it does not support the setting or modification of labels. Note: When a HaloCAD MPIP-protected file is shared with partners/suppliers, they don't need to install the HaloCAD Add-on for CAD on their machines; instead, just this simple reader add-on is sufficient. The following figure shows the HaloCAD Reader Add-on for CAD.  
![TechReference_Readermode.png](https://help.secude.com/__attachments/a_08558b722d19524df605bf4f9f2fabef20208bb4797aab8e52beff518828573b/TechReference_Readermode.png?cb=6f97dfb6cc11eb8a240f43c05257c24a)

*HaloCAD Reader Add-on for CAD*

### **HaloCAD for PLM**

**HaloCAD for PLM (HaloCAD for Teamcenter, HaloCAD for Windchill, and HaloCAD for Autodesk Vault)**

This solution integrates seamlessly with the PLM application, including the features of HaloCAD PROTECT and HaloCAD MONITOR, while utilizing Microsoft Purview Information Protection (MPIP), formerly Microsoft Information Protection (MIP), to provide Enterprise Digital Rights Management (EDRM) capabilities.

HaloCAD for PLM operates continuously in the background, monitoring file uploads and downloads. It connects to Microsoft Purview Information Protection to download sensitivity labels and handle file encryption and decryption.

During a file upload, it checks whether the file is already encrypted and, if so, automatically decrypts it before allowing it to be checked into the PLM Vault. Similarly, whenever a file is downloaded, HaloCAD for PLM automatically enforces protection in accordance with defined action rules, ensuring that all file operations adhere to security rules and keep data safe. It operates independently during the file check-in or upload process. However, during file check-out or download, it depends on the rules defined in the Classification Engine (HaloENGINE).  
![TechReference_HaloCAD for PLM.png](https://help.secude.com/__attachments/a_ab1ead5bd62967505522dde2c90173a2d9fcbdc628deec6cb5eb17e0df86d36b/TechReference_HaloCAD%20for%20PLM.png?cb=0d6e3f609ae3d060a06c2d2cb11caf40)

*HaloCAD for PLM*  
**Separate Installation Requirement**

Ensure that HaloENGINE and HaloCAD for PLM are installed and configured separately on Windows servers.

**HaloENGINE**---A Java-based classification engine that implements the business logic of the architecture. It integrates with Microsoft Purview Information Protection to download sensitivity labels and make them available for configuration. HaloENGINE uses metadata to classify and organize data, and it also enforces classification schemas and action rules. All file downloads must comply with the rules defined in this engine, making it the central component of the architecture.

During file download, HaloENGINE receives relevant metadata from HaloCAD for PLM, determines the appropriate action based on the configured rules, and forwards the label and action information to HaloCAD for PLM for file processing (encryption).

**HaloCAD for PDM (HaloCAD for SOLIDWORKS PDM)**

This solution integrates HaloCAD PROTECT and MONITOR capabilities with the respective PDM application. It connects to Microsoft Purview Information Protection to download sensitivity labels and handle file encryption and decryption.

SOLIDWORKS PDM folders are actively monitored to ensure file security and compliance. When files are cut or copied from a SOLIDWORKS PDM folder to a non-SOLIDWORKS PDM folder, they are automatically intercepted and protected before reaching the destination. Conversely, when previously encrypted SOLIDWORKS application files or PDF files are copied or moved into a SOLIDWORKS PDM folder, they are seamlessly decrypted and saved for use within the environment.

**HaloENGINE**---A Java-based classification engine that implements the business logic of the architecture. As described in HaloCAD for PLM, it provides similar functionality when integrated with PDM.

All file copy/move must comply with the rules defined in this engine, making it the central component of the architecture.  
![TechReference_HaloCAD for PDM.png](https://help.secude.com/__attachments/a_477123dbd1ab4e89ee6bc702bf4dfa71c5d9b62352ec2d43be3eaef705f9234b/TechReference_HaloCAD%20for%20PDM.png?cb=18b66a80ae43cda05837e7c3713efbc8)

*HaloCAD for PDM*

For comprehensive details, please refer to the respective manuals as per your PLM environment:

1. If your environment is integrated with Windchill PLM, refer to the HaloCAD for Windchill Installation Manual.

2. If your environment is integrated with Teamcenter PLM, refer to the HaloCAD for Teamcenter Installation Manual.

3. If your environment is integrated with Autodesk Vault PLM, refer to the HaloCAD for Autodesk Vault Installation Manual.

4. If your environment is integrated with SOLIDWORKS PDM, refer to the HaloCAD for SOLIDWORKS PDM Installation Manual.

### HaloCAD for Viewers

HaloCAD for Viewers is a lightweight application designed to view HaloCAD-protected files in other CAD-Viewer applications with "View only" access to all users who have access to it. This application is useful for suppliers or partners who need to access HaloCAD-protected models or drawings in their environment. The high-level architecture of HaloCAD for Viewers is illustrated in the following figure.  
![TechReference_Arch of Viewers.png](https://help.secude.com/__attachments/a_7893f1e6474cd5f7fb73098ac79df0645814972150fa3a278241e665f40baee5/TechReference_Arch%20of%20Viewers.png?cb=4adc86590e461620ae6eb174a6cf3542)

*HaloCAD for Viewers*

### HaloCAD for TCAI

HaloCAD for TCAI is a lightweight application that uses Microsoft Purview Information Protection functionality to decrypt HaloCAD-protected CAD files during bulk loading operations in Teamcenter integration with Autodesk Inventor. This enables protected Inventor files to be scanned and processed by the TCAI Bulk Loader.

The Teamcenter Integration for Autodesk Inventor (TCAI) Bulk Loader utility allows administrators to automatically import large numbers of Inventor files into Teamcenter. However, when Inventor files are protected (encrypted), the Bulk Loader cannot recognize or process them directly.

By decrypting protected files during the loading process, HaloCAD for TCAI enables the Bulk Loader to scan and load these files into Teamcenter.

HaloCAD for TCAI uses the same underlying decryption mechanism as HaloCAD for Viewers, but it is specifically designed to support bulk loading operations in the TCAI environment.  
![TechReference_HaloCAD for TCAI.png](https://help.secude.com/__attachments/a_1f84cade68e9feaa1f68868f1f886ec43a2abb125a9dc5df8be086f766298a95/TechReference_HaloCAD%20for%20TCAI.png?cb=23775ea43d43cd8812d96d5b1490f7bc)

*HaloCAD for TCAI*

**Microsoft Purview Information Protection**

HaloCAD seamlessly integrates with Microsoft Purview Information Protection solution to protect your sensitive documents. Microsoft Purview Information Protection is an industry-standard document security solution that enables businesses to ensure only authorized users can open protected content while also regulating what they can do with it, such as print, edit, or save. Even if sensitive data is leaked accidentally or maliciously, unauthorized parties cannot view it in clear text, thus leaving it useless.  
**Microsoft documentation**

This manual assumes that you already have a complete Microsoft Purview Information Protection setup and are familiar with using the Microsoft Purview portal and related concepts. If you are new, you can refer to Microsoft's online documentation for setup and configuration.

## Prerequisites

The prerequisites and dependencies for installing and configuring the HaloCAD add-ons are summarized in this section.

### Register an Application in Microsoft Entra ID - **Public client/native**

|-------------------|-------------------------------------------------------------------------------------------------------------------------------------|
| **Applicable to** | 1. HaloCAD Add-on for CAD 2. HaloCAD Reader Add-on for CAD 3. HaloCAD for Viewers 4. HaloCAD for TCAI 5. HaloCAD for SOLIDWORKS PDM |

This section will guide you through registering an application, obtaining the Client ID and Directory ID, and assigning permissions to the application.  
**Microsoft documentation**

Registering an application in Microsoft Entra ID establishes a trust connection between your application and the identity provider, the Microsoft identity platform.

The information in the Microsoft documentation overrides any information published in this section. For a comprehensive description, refer to Microsoft documentation.

#### Create an Application

Follow the instructions below to register an application:

1. Log in to the [Microsoft Entra admin center](https://entra.microsoft.com/) using an account that has administrator privileges.

2. If you have access to multiple tenants, click the **Settings** icon in the top menu and select the tenant for which you want to register the application from the **Directories** + **subscriptions**menu.

3. You will be directed to the homepage.

   ![0_Intial Screen.png](https://help.secude.com/__attachments/a_a6d6eabb80d1776d6ab26ac11e5560533b95aed0636311dcf4cdf57e993646dc/0_Intial%20Screen.png?cb=7474bc6a49931803f8de1518c0a94eca)

   *Selecting Microsoft Entra ID*
4. Click **Identity** \> **Applications** \> **App registrations**on the left of the navigation pane.

5. On the **App registrations** page, click the **New registration** page or **Register an Application** button (this button appears only if no applications have already been created).

   ![1_New application registration.png](https://help.secude.com/__attachments/a_25deb57a57f8ed59f37c58128135024f331cb88fd7005c04e2c25e7103a63e76/1_New%20application%20registration.png?cb=5ea4d32fc9fa86b48bc627cd26dbcd0e)

   *New application registration*
6. On the**Register an application** page, enter the registration details for your application.

   ![2_Public client application details.png](https://help.secude.com/__attachments/a_d628b4f481b4ac52de5c04e28b25a6099f7d3319b176e4bef3bbe58b57e4daf1/2_Public%20client%20application%20details.png?cb=14ea97df2b8462fe456b3cb6a27dac4f)

   *Application details*
7. In the **Name**field, enter an appropriate application name.

8. Under **Supported account types**, select which account you would like your application to support. For detailed information on these types, please see Microsoft documentation.

   1. To target only accounts that are internal to your organization, select **Accounts in this organizational directory only**.

   2. To target only business or educational customers, select **Accounts in any organizational directory**.

   3. To target the widest set of Microsoft identities and to enable multitenancy, select **Accounts in any organizational directory and personal Microsoft accounts**.

   4. To target the widest set of Microsoft identities, select **Personal Microsoft account only**.

   5. Under **Redirect URI** : Select **Public client/native (mobile \& desktop)** , and then type a valid redirect URI for your application. For example, `https://localhost`.

   6. When finished, click **Register**.

9. The home page of the new application is created and displayed.

   ![3_Application ID and Tenant ID.png](https://help.secude.com/__attachments/a_687c22c2021b1df2ef31c0f7e3a60bc668ceae8e6a1a0a403cc0e9fcbc04889c/3_Application%20ID%20and%20Tenant%20ID.png?cb=2d09547b6b78d6efbbceb666e67608ee)

   *Application ID and Tenant ID*
10. Once registration is complete, the following values are shown on the portal. To copy and save the ID value in a text editor, hover your cursor over it and click the **Copy to clipboard**icon.

    1. **Application ID** -- also known as **Client ID**.

    2. **Directory ID** -- also known as **Tenant ID**.

**Save the authentication parameters**

Open a text editor (such as Notepad) and copy the values for the Application (client) ID, Directory (tenant) ID, and Redirect URI. Save these details for initializing the HaloCAD Add-on. Note that the Directory (tenant) ID is required only for single-tenant applications.

#### Add Required Permissions

To protect content using the MIP SDK, you need to provide the following API permission(s) for the created application ID.

1. In the sidebar of the new application page, select **API permissions** . The **API permissions** page for the new application registration will appear.

2. Click **Add a permission** button. The **Request API permissions** page will appear.

3. Under the **Select an API**setting, select APIs my organization uses. A list appears, containing the applications in your directory that expose APIs.

4. Type in the search box or scroll to find the required API that is mentioned in the table below, "Required Permissions".

5. For example, type **Microsoft Information Protection Sync Service**. You can see the API listed as shown in the figure below:

   ![4_API selection.png](https://help.secude.com/__attachments/a_db25148553adc8db48e8be391d88ebf57ca7b18add7a0f418c7b8a4d596d110d/4_API%20selection.png?cb=60328777c1eb9f0880eb1267645ecb5d)

   *Searching for permissions*
6. Now, click on the displayed API. You can see two permissions on the page − **Delegated permissions** and **Application permissions**.

7. Click the **Delegated permissions** button and then, under the **Permission**section, select the check box against "Read all unified policies a user has access to".

   ![5_Adding permission.png](https://help.secude.com/__attachments/a_f6a34d85a0f558ad5e10bafdaff9502c6085900f92ed80df166f30cbbc4a34b4/5_Adding%20permission.png?cb=dbc6f87482218efd202793dde05cdce6)

   *Adding permission*
8. Click **Add permissions**. Repeat the steps outlined above to add the other required permissions listed in the table below.

9. You will return to the API permissions page, where the permissions have been saved and added to the table. Please note that administrator consent is not necessary for **Delegated permissions**.

   ![6_Required API Permissions.png](https://help.secude.com/__attachments/a_f8d82a1bdbc7e7c62bd564d1d55177b7a44bdae2a54b648d9709099b9219d214/6_Required%20API%20Permissions.png?cb=66ea7fcb1dd8aa1087252334a951ab69)

   *API Required permissions*
10. The following table lists the required permissions.

|                        **API / Permission name**                        |     **Display Name**      | **Type**  |                     **Description**                      |
|-------------------------------------------------------------------------|---------------------------|-----------|----------------------------------------------------------|
| Azure Rights Management Services (Microsoft Rights Management Services) | `User_impersonation`      | Delegated | Create and access protected content for users            |
| Microsoft Graph                                                         | `User.Read`               | Delegated | Sign in and read user profile (will be added by default) |
| Microsoft Information Protection Sync Service                           | `UnifiedPolicy.User.Read` | Delegated | Read all unified policies a user has access to.          |

*Required permissions*

### **Register an Application in Microsoft Entra ID - Web**

|-------------------|----------------------------------------------------------------------------------|
| **Applicable to** | 1. HaloCAD for Teamcenter 2. HaloCAD for Windchill 3. HaloCAD for Autodesk Vault |

Creating an application in Microsoft Entra ID is similar to the steps in the previous section. However, for HaloCAD for PLM, some variations apply.

1. Under **Redirect URI** , select **Web**.

2. Add the permissions listed in the following table.

3. Click **Grant admin consent for your** *\<company\>*.

4. When the confirmation dialog appears, select **Yes** to approve.

5. After the consent is granted, the **Status** column changes to **Granted**.

|                        **API / Permission Name**                        |      **Display Name**       |  **Type**   |                                                         **Description**                                                          |
|-------------------------------------------------------------------------|-----------------------------|-------------|----------------------------------------------------------------------------------------------------------------------------------|
| Microsoft Graph                                                         | `User.Read`                 | Delegated   | Sign in and read the user profile. This API permission is added by default, but it is not used by the HaloENGINE Tomcat Service. |
| Azure Rights Management Services (Microsoft Rights Management Services) | `Content.DelegatedWriter`   | Application | Create protected content on behalf of a user                                                                                     |
| Azure Rights Management Services (Microsoft Rights Management Services) | `Content.Writer`            | Application | Create protected content                                                                                                         |
| Microsoft Information Protection Sync Service                           | `UnifiedPolicy.Tenant.Read` | Application | Read all unified policies of the tenant                                                                                          |

*Required permissions #1*

#### **Additional Permission (Only for Decryption)**

The permissions mentioned above are adequate for applying the MPIP label to a file with the owner as SPN (Service Principal Name) ID or any user email ID. Additionally, the HaloENGINE Tomcat Service requires the following superuser privilege for the decryption function when the owner is not as SPN.  

|                        **API / Permission Name**                        |  **Display Name**   |  **Type**   |                        **Description**                         |
|-------------------------------------------------------------------------|---------------------|-------------|----------------------------------------------------------------|
| Azure Rights Management Services (Microsoft Rights Management Services) | `Content.SuperUser` | Application | Read all protected content for this tenant in the Azure portal |

*Required permissions #2*

#### Upload the Certificate in the Azure Portal

The HaloENGINE Tomcat Service relies on certificate-based authentication to access MPIP services. Therefore, you must enter your certificate information in the registered application before proceeding with the configuration.

Prerequisites:

1. **Certificate**:

   1. Ensure that you have a valid certificate containing the following key properties: `-KeyExportPolicy Exportable` and `-KeySpec Signature`.

   2. The certificate can also be self-signed. Note: As a best practice and for security reasons, use a self-signed certificate only in a test environment. It is not recommended for production environments.

2. **Local Computer** certificate store: The certificate required for MPIP authentication must be installed in the Local Computer certificate store, along with the Root CA and Intermediate CA certificates.

   1. If the certificate is CA-signed, install all related certificates in their respective stores (Root, Intermediate, and Personal).

   2. If the certificate is self-signed, install it in both the Trusted Root Certification Authorities and Personal stores of the Local Computer.

To upload the public key of the certificate, follow the steps below:

1. In the sidebar of the new application page, select **Certificate \& secrets**.

2. Under the **Certificate** section, click **Upload certificate** . The **Upload certificate**dialog appears as shown in the figure below:

   ![Upload certificate_1.png](https://help.secude.com/__attachments/a_7198c6b1b86af754daa652953b1f5c63f5f990538fa33865e512510bd2e03767/Upload%20certificate_1.png?cb=9b028533c34b642a22254eac5af1b8b2)

   *Upload certificate #1*
3. Click on the folder icon to select the certificate and click **Open** . For illustration purposes, the file `DESKTOP001.cer` is used.

4. Now, click **Add**. The certificate will get uploaded, and its thumbprint will be displayed on the page as shown in the figure below:

   ![Upload certificate_2.png](https://help.secude.com/__attachments/a_06ec68709284453c78ddc9c2e2941e7fb0c96fe59c2a3418b0f5f7551b9321fe/Upload%20certificate_2.png?cb=0623c0f3126f69195dfa9f8b7d86687e)

   *Upload certificate #2*

The following table lists the Microsoft Entra ID application types that must be registered when using HaloCAD Add-on for CAD, HaloCAD for Viewer, HaloENGINE, or HaloCAD for PLM.  

|              **Component and Combination**               |           **Application Type**           |                                                                                                                 **Configuration Guideline**                                                                                                                  |
|----------------------------------------------------------|------------------------------------------|--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| HaloCAD Add-on for CAD and HaloCAD Reader Add-on for CAD | Public client/native (mobile \& desktop) | Create a new Microsoft Entra ID application in your tenant for the HaloCAD Add-on for CAD installation and use the same application details for the Reader Add-on. The Reader Add-on cannot open protected files if the tenant details do not match.         |
| HaloCAD for Viewer                                       | Public client/native (mobile \& desktop) | Create a new Microsoft Entra ID application in your tenant for HaloCAD for Viewer installation. Alternatively, if you already have an existing HaloCAD application, use the same app details and ensure that the client type is set to Public client/native. |
| HaloCAD for TCAI                                         | Public client/native (mobile \& desktop) | Create a new Microsoft Entra ID application in your tenant for HaloCAD for Viewer installation. Alternatively, if you already have an existing HaloCAD application, use the same app details and ensure that the client type is set to Public client/native. |
| HaloCAD for SOLIDWORKS PDM                               | Public client/native (mobile \& desktop) | Create a new Microsoft Entra ID application in your tenant for the HaloCAD for SOLIDWORKS PDM installation. When used in combination with HaloENGINE, ensure that the same Directory (Tenant) ID is used. Mismatched IDs will cause configuration errors.    |
| HaloENGINE                                               | Web                                      | Create a new Microsoft Entra ID application in your tenant for the HaloENGINE. For more details, please refer to the HaloENGINE Installation Manual.                                                                                                         |
| HaloCAD for PLM and HaloENGINE                           | Web                                      | Both use a Web-type application, so the same application details can be used during installation.                                                                                                                                                            |

*HaloCAD and Application Type*

### Create and Configure the Sensitivity Labels

|-------------------|----------------------------------------------------------------------------------------------------------------------------------|
| **Applicable to** | 1. HaloCAD Add-on for CAD 2. HaloCAD Reader for Add-on 3. HaloCAD for PLM/PDM (Teamcenter, Windchill, Vault, and SOLIDWORKS PDM) |

As an administrator, you can create, configure, and publish sensitivity labels for various levels of content sensitivity based on your organization's classification taxonomy. Use names or terms that are familiar to your users. Consider starting with label names like Personal, Public, General, Confidential, and Highly Confidential if you don't already have a taxonomy in place. For more details, please refer to Microsoft online documentation.

### Office 365 Subscription Details

|-------------------|---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| **Applicable to** | 1. HaloCAD Add-on for CAD 2. HaloCAD Reader Add-on for CAD 3. HaloCAD for Viewers 4. HaloCAD for TCAI 5. HaloCAD for PLM/PDM (Teamcenter, Windchill, Vault, and SOLIDWORKS PDM) |

1. Fully configured Microsoft Purview Information Protection.

2. An Azure subscription is required to use Azure RMS and the MPIP functionality.

3. A working Microsoft Entra ID service must be available.

4. Transport Layer Security (TLS) 1.2 or higher must be enabled to ensure the use of cryptographically secure protocols at all client workstations. Please refer to the section "[Enable Support for TLS 1.2 at the Client Workstation for Microsoft Entra ID](https://help.secude.com/halocad-add-on-for-dassault-systemes-solidworks/2.4/technical-reference-manual.md#TLS)".

5. To avail the revoke access feature, the user should be assigned to the Microsoft Purview Information Protection Premium P1/P2 license. (Not required for the reader and viewer add-on)

6. Audit logging: Your Azure subscription must include Log Analytics on the same tenant as Microsoft Entra ID.

### **Recommended URLs, Addresses, and Ports for MPIP**

|-------------------|-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| **Applicable to** | 1. HaloCAD Add-on for CAD 2. HaloCAD Reader for Add-on 3. HaloCAD for Viewers 4. HaloCAD for TCAI 5. HaloCAD for PLM/PDM (Teamcenter, Windchill, Vault, and SOLIDWORKS PDM) |

MIP SDK doesn't support the use of authenticated proxies. So, make sure you set the Microsoft 365 endpoints to bypass the proxy. View a list of endpoints at "[Microsoft Online Documentation](https://docs.microsoft.com/en-us/microsoft-365/enterprise/urls-and-ip-address-ranges?view=o365-worldwide)". However, Microsoft recommends the following:  

|                                                                                                                                    **Addresses**                                                                                                                                     |                   **Ports**                    |
|--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|------------------------------------------------|
| `*.protection.outlook.com` `40.92.0.0/15`, `40.107.0.0/16`, `52.100.0.0/14`, `52.238.78.88/32`, `104.47.0.0/17`, `2a01:111:f403::/48`                                                                                                                                                | TCP 443                                        |
| `*.aadrm.com`, `*.azurerms.com`, `*.informationprotection.azure.com`, `ecn.dev.virtualearth.net`, `informationprotection.hosting.portal.azure.net`, `*.office.com` (add `substrate.office.com` if you don't want to add all sub-domains), `crl3.digicert.com`, `crl4.digicert.com` . | TCP 443, 80                                    |
| **For event logging** `*.events.data.microsoft.com`                                                                                                                                                                                                                                  | TCP 443                                        |
| **National Cloud**                                                                                                                                                                                                                                                                   | **Microsoft Entra ID authentication endpoint** |
| Microsoft Entra ID for the US Government                                                                                                                                                                                                                                             | `https://login.microsoftonline.us`             |
| Microsoft Entra ID (global service) For details on Microsoft Entra ID endpoints, please refer to "[++Microsoft Online Documentation++](https://docs.microsoft.com/en-us/azure/active-directory/develop/authentication-national-cloud#azure-ad-authentication-endpoints)".            | `https://login.microsoftonline.com`            |

*Recommended endpoints*

**Secude License Manager for HaloCAD**  

|-------------------|------------------------------------------------------------|
| **Applicable to** | 1. HaloCAD Add-on for CAD 2. HaloCAD Reader Add-on for CAD |

To communicate with Secude License Manager for HaloCAD, the following URL and port must be whitelisted in the customer's proxy:  

|                              **Address**                              | **Port** |
|-----------------------------------------------------------------------|----------|
| License API - [api.licensespring.com](https://api.licensespring.com/) | TCP 443  |

*Recommended license manager endpoint*

### Enable Support for TLS 1.2 at the Client Workstation for Microsoft Entra ID

|-------------------|---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| **Applicable to** | 1. HaloCAD Add-on for CAD 2. HaloCAD Reader Add-on for CAD 3. HaloCAD for Viewers 4. HaloCAD for TCAI 5. HaloCAD for PLM/PDM (Teamcenter, Windchill, Vault, and SOLIDWORKS PDM) |

To improve the security posture of the tenant and to remain in compliance with industry standards, Microsoft Entra ID stopped supporting the following Transport Layer Security (TLS) protocols and ciphers:

1. TLS 1.1

2. TLS 1.0

3. 3DES cipher suite (TLS_RSA_WITH_3DES_EDE_CBC_SHA)

In order for the HaloCAD for CAD add-on to be able to authenticate to Microsoft Entra ID, TLS 1.2 must be activated on the respective client workstation. Please see this [Microsoft article to enable TLS 1.2](https://learn.microsoft.com/en-us/troubleshoot/azure/active-directory/enable-support-tls-environment?tabs=azure-monitor).  
**Microsoft documentation**

The information in the Microsoft documentation overrides any information published in this section.

Secude is not liable for changes to the content of this section because it was extracted from the Microsoft article at the time when the HaloCAD manual was prepared. Do check the most recent updates in this regard from the Microsoft documentation.

In summary, the following steps must be performed:

1. Update the Windows Operating System

2. Update .NET Framework

3. Set the following registry settings:

| **S.No** |                              **Windows Registry**                              |                                    **Values**                                     |
|----------|--------------------------------------------------------------------------------|-----------------------------------------------------------------------------------|
| 1        | `[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\.NETFramework\v4.0.30319]` | `"SystemDefaultTlsVersions"=dword:00000001` `"SchUseStrongCrypto"=dword:00000001` |
| 2        | `[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\v4.0.30319]`             | `"SystemDefaultTlsVersions"=dword:00000001` `"SchUseStrongCrypto"=dword:00000001` |

*Registry entries*

## License Administration

|-------------------|------------------------------------------------------------|
| **Applicable to** | 1. HaloCAD Add-on for CAD 2. HaloCAD Reader Add-on for CAD |

HaloCAD uses a key-based license to control application features. Obtain the license key from Secude Support before installing HaloCAD.  
This document does not cover all the specifics of purchasing a license. Please contact Secude's representative for additional details.

The following methods are available to activate the license in HaloCAD.

1. **Tool-based automatic initialization and license activation** : This method generates an encrypted configuration file that contains the license key and Microsoft Entra ID application details. Using this file, the installer automatically completes the installation, application initialization, and license activation. For more information, refer to the "[Secure Installation](https://help.secude.com/halocad-add-on-for-dassault-systemes-solidworks/2.4/technical-reference-manual.md#secure)" section.

2. **UI-based manual license activation** : This method provides a straightforward installation process without automatic license activation. After launching the CAD application, the administrator must manually activate the license by entering the license key in the HaloCAD license screen. For more information, refer to the "[UI-based Manual License Activation](https://help.secude.com/halocad-add-on-for-dassault-systemes-solidworks/2.4/technical-reference-manual.md#ui)" section.

3. **License activation in silent mode:** This method uses an encrypted configuration file to automatically initialize the application and activate the license during installation. For more details, refer to the **Silent Mode** section of the HaloCAD Installation Manual provided with your purchased application.

4. **License activation via System Center Configuration Manager (SCCM)**: For organization-wide deployment and activation of the HaloCAD add-on, an encrypted configuration file containing the license key information and Microsoft Entra ID application details is used together with the installer. For additional information on SCCM, please refer to the HaloCAD Installation Manual.

The following is a high-level diagram that illustrates license activation.  
![TechReference_Activation methods.png](https://help.secude.com/__attachments/a_79464a96c1dcdd402edb82da637c7c9b38a2a66590f51d6cc4a7429179df3985/TechReference_Activation%20methods.png?cb=4db4bb96e8c6129e4c18ec2252367813)

*License activation*

### **Secure Installation (Recommended)**

|-------------------|-------------------------------------------------------------------------------------------------------------------------------------|
| **Applicable to** | 1. HaloCAD Add-on for CAD 2. HaloCAD Reader Add-on for CAD 3. HaloCAD for Viewers 4. HaloCAD for TCAI 5. HaloCAD for SOLIDWORKS PDM |

As a best practice, application secrets should not be shared with end users, third parties, or trusted vendors. However, to avail of HaloCAD features (standard add-on and reader add-on), it is necessary to share such sensitive information for a successful installation.

To overcome this challenge, Secude offers an admin utility tool that can write and encrypt data, including Microsoft Entra ID application details (Application ID, Tenant ID, and Redirect URI), Cloud type details, and a license key in an encrypted configuration file. It uses the RSA algorithm for cryptography, allowing only the HaloCAD installer to access the configuration file with the private key during the initialization process, effectively masking the Initialization screen from the user.

An administrator can create an encrypted JSON file using this admin tool and share it with internal/external parties without disclosing the original tenant details.

**HaloCAD Admin Utility Tool**

The HaloCAD product package comprises an additional component---`hc.admintool.exe`.

**Prerequisites**: Before executing the admin tool, make sure you have the necessary information.

1. Microsoft Entra ID application details for initialization

2. Cloud type details

3. A license key

   Note: A license key is not required for HaloCAD for Viewers and HaloCAD for TCAI.

**How to Encrypt the Configuration File**

1. From the product package, move the **admintool** folder to your preferred location. For example, `C:\Users\superdocs\Desktop\admintool`.

2. Open the Command Prompt with elevated rights (Run as Administrator).

3. Navigate to the directory of the **admintool** folder and type `hc.admintool.exe` and press **Enter**.

   ![Admin tool Commands.png](https://help.secude.com/__attachments/a_6ade269b2d8996f00dec97e0ab04e50080d186a3ce320e09fd619207cc93176f/Admin%20tool%20Commands.png?cb=1a46b89cd30b48fb1baa0e771e3e253f)

   *Admin tool with help command*
4. Enter the required details. For example,

   **Cloud type: Commercial** - `hc.admintool.exe v6ca776-c74e-437d-98ef-662ecb5751tt https://localhost 9c1cfc28-1ec6-44ea-bec6-e3492ef0cd16 B27N-CMTO-LWGH-AKEQ Commercial`

   **Cloud type: US_DoD** - `hc.admintool.exe v6ca776-c74e-437d-98ef-662ecb5751tt https://localhost 9c1cfc28-1ec6-44ea-bec6-e3492ef0cd16 B27N-CMTO-LWGH-AKEQ US_DoD`

   **Cloud type: Custom** - `hc.admintool.exe v6ca776-c74e-437d-98ef-662ecb5751tt https://localhost 9c1cfc28-1ec6-44ea-bec6-e3492ef0cd16 B27N-CMTO-LWGH-AKEQ Custom https://api.aadrm.com https://dataservice.protection.outlook.com`

5. The output window will now appear as follows:

   ![Custom_Admin tool output.png](https://help.secude.com/__attachments/a_ebd8c888da10fa215b7d561f3aac79b845245173108d028ff2e2147453689d5a/Custom_Admin%20tool%20output.png?cb=d0c0fde036cd75475504c21aa54dac5b)

   *Admin tool displaying the output*
6. **HaloCAD add-on for Creo**: The following help commands are specific to the HaloCAD add-on for Creo.

   ![Creo admin tool.jpg](https://help.secude.com/__attachments/a_4d07a0da32c25c3156f16bd5c4090b0c963814c08f1c00ba855bfc3626df1d67/Creo%20admin%20tool.jpg?cb=0251084f955bb62a73353c12ecc6fa2b)

   *Admin tool with help command* *for Creo add-on*  
   ![Admin tool - output-Creo ECTR.png](https://help.secude.com/__attachments/a_52b01d744f436152d0a36f8f70e461b52f69f7ed4ca37dcdbdc10c2229cabd28/Admin%20tool%20-%20output-Creo%20ECTR.png?cb=53dc5c95b7a1f6b9461aaf266f14ce4f)

   *Admin tool displaying the output with ECTR integration (only for Creo add-on)*
7. **HaloCAD for SOLIDWORKS PDM**: The following help commands are specific to HaloCAD for SOLIDWORKS PDM.

   ![Admin tool output (SWPDM).png](https://help.secude.com/__attachments/a_2a8d069ba7c37ac4e4d4a1439aa234dc73086ee7844d1cb73467f17383b76fcd/Admin%20tool%20output%20(SWPDM).png?cb=5e986a9c43bd90f71bd8c85c932bc538)

   *Admin tool displaying the output for SOLIDWORKS PDM*
8. **HaloCAD for Viewers and TCAI**: The following help commands are specific to HaloCAD for Viewers and TCAI.

   ![Admin tool displaying the output for HaloCAD for Viewers and TCAI.png](https://help.secude.com/__attachments/a_d773d7829a29f55f6a9d401432943f9d477dce14c2d742ba054098f5d96c1afd/Admin%20tool%20displaying%20the%20output%20for%20HaloCAD%20for%20Viewers%20and%20TCAI.png?cb=7d27e5050516ef77de8ed96dcd909c75)

   *Admin tool displaying the output for Viewers and TCAI*

**Result**:

* The `hc.conf.json` file will be replaced by an encrypted file named `hc.conf.enc`.

* You can now share the configuration file with external users. With this file, users can install the HaloCAD add-on on their workstations seamlessly, without requiring any additional configuration details.

* Configuration files created with earlier releases are not supported. Always use the admin tool included in the installation package to generate a new configuration file.

**Next step**

1. Place the encrypted file `hc.conf.enc` in the same directory as the HaloCAD installer you have purchased.

2. To start the interactive installation, double-click the installer and follow the steps provided in the Installation Manual for your purchased add-on.

### UI-based Manual License Activation

|-------------------|--------------------------------------------------------|
| **Applicable to** | 1. HaloCAD Add-on for CAD 2. HaloCAD Reader for Add-on |

This section describes how to activate a license using the HaloCAD user interface. Note: If you encounter any issues while activating the license, please refer to the "Troubleshooting" chapter in the Operations Manual.

Prerequisite: Ensure that the HaloCAD installation is complete by following the instructions provided in the Installation Manual.

1. Open the CAD application for which the add-on was purchased.

2. HaloCAD programmatically sends a license validation request to Secude's License Manager, and the following warning message appears:

   ![HALOCAD License warning message.png](https://help.secude.com/__attachments/a_0c39c8e3cddffd749eff555126b5b38fad88330f31b776da70231a3a97ff465a/HALOCAD%20License%20warning%20message.png?cb=3bff119b979098a8e9ccd558802b5da8)

   *HaloCAD license warning message*
3. Click **OK**.

4. Go to the **HaloCAD** tab and click **About** to see the status of your license. You will see **None**on the screen, indicating that the license has not yet been enabled.

   ![License status - None -About Screen.png](https://help.secude.com/__attachments/a_2bcf8fff0015e5696fb48e4ce890183c315e87229fd89bcd2d01d369ca61d301/License%20status%20-%20None%20-About%20Screen.png?cb=deb860ef70b4b568263d0c199eefdca3)

   *License Status: None*
5. Click **Activate**.

6. The *HaloCAD License Activation* screen will appear.

   ![HALOCAD Activation Screen.png](https://help.secude.com/__attachments/a_649fd79a1672e392579f60203e2cd0fe8599f7a20295fb6e5f2d1ef757e5b63f/HALOCAD%20Activation%20Screen.png?cb=acd5c6bf499586a88f83eaa7cfbf6a15)

   *HaloCAD activation screen*
7. Enter the license key for the standard add-on for protection. Note: Ensure you enter the license key provided specifically for the reader add-on when using it. Interchanging license keys results in activation failure.

8. Click **Activate**.

**Result**:

* You will receive the following confirmation message:

  ![Activation success message.png](https://help.secude.com/__attachments/a_8d77bbc4922fd91d447da22971ff0c8bf3a33c7ace61fe558eb024ca0082efeb/Activation%20success%20message.png?cb=c479100ffb0eb6c50f18afba55116969)

  *Activation success message*
* Click **OK**.

* As a result, you will see **Active** on the screen, indicating that the license has been activated.

  ![License status.png](https://help.secude.com/__attachments/a_74793ed8c1e60b12415dbfb164c9fb0931000d3c8550684e809fc057a1f2779f/License%20status.png?cb=cfa6e519985f240fe1df3f9523829bc0)

  *License Status: Active*

**Related tasks**:

* If you click the pencil icon (**Click to change label** ) to label the file, the Rights Management Service prompts you to sign in. Click **OK**, and then enter your credentials.

* After successful authentication, the labels can be retrieved from Microsoft Purview Information Protection, and the HaloCAD Ribbon is activated. For more details, please refer to the Operations Manual.

### **License Expiration**

|-------------------|------------------------------------------------------------|
| **Applicable to** | 1. HaloCAD Add-on for CAD 2. HaloCAD Reader Add-on for CAD |

HaloCAD licenses are valid only until the specified expiration date. After the license expires, launching the CAD application will display a warning message stating *"The license is invalid."* After clicking **OK** , another message will appear stating *"User has no valid license. Please contact your administrator."* To continue using the application, a new valid license must be obtained and activated.

Prerequisite: Before reactivating it, ensure that you have a new license key from Secude.

**Option 1** **- Using the Admin Tool (Automatic Activation)**

1. Run the admin tool with the new license key, as explained in the section "[How to Encrypt the Configuration File](https://help.secude.com/halocad-add-on-for-dassault-systemes-solidworks/2.4/technical-reference-manual.md#admintool)".

2. Navigate to the configuration directory containing the old `hc.conf.enc` file and replace it with the one created in the previous step.

3. Restart the application.

**Result**:

* The HaloCAD license key is now automatically activated.

* You can start protecting CAD files.

**Option 2 - Using the About UI (Manual Activation)**

1. Open the CAD application.

2. Go to the **HaloCAD** tab and click **About**.

3. Click **Activate**.

4. Enter the new key that Secude has provided.

**Result**:

* The HaloCAD license key is now manually activated.

* You can start protecting CAD files.

## Appendix

**Third-Party Libraries**

Third-party software/code is included or bundled with Secude's products according to its appropriate license. Secude conducts testing to ensure that third-party products are compatible with and perform as intended with Secude applications.  

|-------------------|------------------------------------------------------------|
| **Applicable to** | 1. HaloCAD Add-on for CAD 2. HaloCAD Reader Add-on for CAD |

The third-party libraries and dependencies used by the HaloCAD Add-on for CAD are shown in the table below.  

|   **Library**    |          **Version**           |                                                             **Source Code**                                                              |                                       **License Link**                                       |
|------------------|--------------------------------|------------------------------------------------------------------------------------------------------------------------------------------|----------------------------------------------------------------------------------------------|
| Mhook            | 2.5.1                          | <https://github.com/apriorit/mhook>                                                                                                      | <https://github.com/apriorit/mhook#license>                                                  |
| Protobuf Library | 3.15.6                         | <https://github.com/protocolbuffers/protobuf>                                                                                            | <https://github.com/protocolbuffers/protobuf/blob/master/LICENSE>                            |
| OpenSSL          | 3.2                            | <https://github.com/openssl>                                                                                                             | <https://github.com/openssl/openssl/blob/master/LICENSE.txt>                                 |
| Rapidxml         | 1.13                           | [https://sourceforge.net/projects/rapidxml/files/latest/download](https://sourceforge.net/projects/rapidxml/files/latest/download%C2%A0) | <http://rapidxml.sourceforge.net/license.txt>                                                |
| JSON Parser      | 3.11.3                         | <https://github.com/nlohmann/json>                                                                                                       | <https://github.com/nlohmann/json/blob/develop/LICENSE.MIT>                                  |
| MSAL             | 4.72.1.0                       | <https://github.com/AzureAD/microsoft-authentication-library-for-dotnet>                                                                 | <https://github.com/AzureAD/microsoft-authentication-library-for-dotnet/blob/master/LICENSE> |
| ConfuserEx       | 1.0.0.0                        | <https://github.com/yck1509/ConfuserEx>                                                                                                  | <https://github.com/yck1509/ConfuserEx/blob/master/LICENSE>                                  |
| WTL              | 9.0.4140                       | <https://www.nuget.org/packages/wtl/9.0.4140>                                                                                            | <https://opensource.org/licenses/cpl1.0.txt>                                                 |
| MIP SDK          | 1.18.103 Creo and NX: 1.16.126 | <https://learn.microsoft.com/en-us/information-protection/develop/version-release-history>                                               | <https://docs.microsoft.com/en-us/information-protection/develop/>                           |
| Licensespring    | 7.40.0                         | -                                                                                                                                        | -                                                                                            |

*Third-party libraries*

The third-party libraries and dependencies used by HaloCAD for Viewers, HaloCAD for TCAI, HaloENGINE, HaloCAD for Teamcenter PLM, HaloCAD for Windchill PLM, HaloCAD for Autodesk Vault PLM, and HaloCAD for SOLIDWORKS PDM are listed in its Installation Manual.

---
version: "2.8"
language: "en"
---
# HaloCAD for Siemens Teamcenter

## HaloCAD for Siemens Teamcenter

This page provides a complete collection of HaloCAD for Siemens Teamcenter documentation.

### Documentation

*

  #### [Technical Reference Manual](https://help.secude.com/halocad-for-siemens-teamcenter/2.8/technical-reference-manual.md)

#### [Installation Manual](https://help.secude.com/halocad-for-siemens-teamcenter/2.8/tc-installation-manual.md)

*

  #### [Operations Manual](https://help.secude.com/halocad-for-siemens-teamcenter/2.8/tc-operations-manual.md)

*

  #### [Release Notes](https://help.secude.com/halocad-for-siemens-teamcenter/2.8/tc-release-notes.md)

---
version: "2.8"
language: "en"
---
# Configuring the HaloCAD Proxy

This section explains how to configure HaloCAD and HaloENGINE parameters using both command-line and GUI methods, as well as Dataset and TCCS configurations.

## Configuration Using Tool (GUI)

Prerequisites: Ensure that HaloCAD for Teamcenter is installed before proceeding.

Follow these steps to configure the settings through the GUI:

**Step 1**. Run the HaloCAD Config tool.

1. Go to the default installation directory `C:\Program Files\Secude\HaloCADTeamcenter\config`.

2. To run, either double-click the `halocad-teamcenter-config-<version>.jar` file or open Command Prompt with administrative privileges and execute the following syntax.

   **Syntax** : `<pathtojar>java -jar halocad-teamcenter-config-<version>.jar`

   **For example** : `C:\Program Files\Secude\HaloCADTeamcenter\config>java -jar halocad-teamcenter-config-<version>.jar`

**Result** : The **HaloCAD for Teamcenter Config Tool** window is displayed.

**Step 2.**Enter the following information under the Teamcenter Configuration tab.  
![1_Tool_Teamcenter Confguration.png](https://help.secude.com/__attachments/a_57c753f6598f0c4aa5a6f3846108c78a1011671d13118e9b4e6954bc335db586/1_Tool_Teamcenter%20Confguration.png?cb=50d77aec07b744f4f21cf8be87bf7af3)

*Teamcenter Configuration* *tab*

1. **Proxy URL** : Enter the URL of the proxy (HaloCAD component) installation. For example, `http://tclu0310.secude.local:8080`

2. **Tomcat Path** : Click **Choose Path** to browse and select the **Tomcat** home directory path. For example, `C:\Program Files\Secude\Tomcat`

3. **Fail-Safe Mode**: The Fail-Safe Mode controls the system's behavior in case of inconsistencies that prevent the specified protection from being applied (conflicting configuration, server component unreachable, or returning an error message, etc.). You can define any one of the following:

   1. **Strict**: The file upload or download will be blocked whenever any error occurs.

   2. **Tolerant**(default): The file upload or download will be allowed, even when an error occurs.

4. **File Optimization**: Choose one of the following options for file optimization. By default, Single Label Optimization is set.

   1. **Single Label Optimization:**The top-level file label is considered and applied to all dependent files.

   2. **Multi-Label Optimization:**Each file type group label defined in the Classification Engine is considered and applied to the corresponding group during ASM optimization.

5. **AWC Micro Service** : To communicate with Teamcenter via **Microservices**, enable this option.

   **AWC 5.x with Microservice:**
   1. If you use Microservices for AWC, enable the option **AWC Micro Service** and provide the port number in **AWC Proxy Port**. Please use a different port number for the Proxy URL and AWC Proxy Port.

   2. For Example, if your Proxy URL is 8080, you may use a different port for the AWC Proxy Port, such as 8081.

   3. To access AWC, use `http://hostname:awcproxyport`. For example, `http://svlu0309:8081`

   **AWC 4.x without Microservice:**
   1. Here, to use AWC without Microservice, disable the option **AWC Micro Service**.

   2. To access AWC, use `http://hostname:proxyport/awc`. For example, `http://svlu0309:8080/awc`

6. **Log Level**: Select a log level of your choice.

   1. **INFO**: A standard log level that highlights the progress of the application.

   2. **ERROR**: Logs error events that prevent program execution.

   3. **DEBUG** : Logs detailed tracing messages. It should be used for information that may be required for diagnosing issues and troubleshooting. The log level is set to "DEBUG" by default. The log rollover period is configured to 24 hours, which means that every 24 hours, a new log file with the file format `haloproxy.<yyyy-MM-dd>.log` is generated.

7. **FMS Target URL** : Enter the URL of the Teamcenter Server where the file download needs to be protected. For more details, please refer to the section "[Appendix](https://help.secude.com/halocad-for-siemens-teamcenter/2.8/tc-appendix.md#app)". For example, `http://tclu0310.secude.local:4544`

8. **Other Target URL** : In case of multiple FSC configurations, enter other URLs as given in the following format `http://<fmstarget url_1>;http://<proxy url_1>,http://<fmstarget url_2>; http://<proxy url_1>`. For more details, please refer to the section "[Appendix](https://help.secude.com/halocad-for-siemens-teamcenter/2.8/tc-appendix.md#app)".

   Example, `http://tclu0317.secude.local:4544/;http://tclu0310.secude.local:8080, http://tclu0312.secude.local:4544;http://tclu0313.secude.local:8080`

   **AWC Target URL**: Enter AWC's URL.
   1. Without Microservice: `http://tclu0310.secude.local:80/awc`

   2. With Microservice: `http://tclu0310.secude.local:3000`

9. **Group** : Enter the name of the group. For example, `dba`.

10. **ServerHost** : Enter your Teamcenter URL. For example, `http://tclu0310.secude.local:80/tc` or `http://tclu0310.secude.local:7001/tc`.

11. **TC Username**: Enter the Teamcenter username. For example, teamcenter_admin.

12. **TC Password**: Enter the Teamcenter password.

13. Click **Apply** .A red tooltip message appears if any required values are missing. Enter the missing information and click **Apply** to continue.

**Result:**

* A progress bar indicates that the "*Restarting Tomcat Service"*.

* A confirmation message dialog box appears.

* Click **OK** to close the confirmation dialog box.

**Step 3.** Go to the **HaloENGINE Configuration** tab, and then enter the following information.  
![2_Tool_HaloENGINE configuration tab.png](https://help.secude.com/__attachments/a_b0a140919ea8d89837097d1cccdbe1e1242f7914f9144dc2f063f31ad9639bd9/2_Tool_HaloENGINE%20configuration%20tab.png?cb=803221587b65ab623752693a185ae94c)

*HaloENGINE Configuration*tab

**Primary HaloENGINE Configuration**

1. **Certificate Name** : Click **Choose File** to browse and select the client Keystore in JKS format, generated by the HaloENGINE Admin Portal (through which communication is established between the primary HaloENGINE and Teamcenter). For example, `Teamcenter01_ClientKey.jks`

2. **Password** : Enter the password of the selected client Keystore. For example, `ckpass`

3. **Host** : Enter the IP address/FQDN of HaloENGINE. For example, `10.41.14.169`

4. **Endpoint Port** : Enter the Endpoint Port where the service is accessed by this client application. For example, `8746`

5. **HaloENGINE Service File Mode**: Select the file transmission method.

   1. **FilePath** (default): File stored in a local temporary location for the encryption and decryption process. Here, file path information is used for transferring.

   2. **Stream**: File as a sequence of bytes.

6. **Customer ID** : Enter the Customer ID that has been assigned in the Admin Portal. For example, `halo_customer`.

7. **System ID** : System Unique ID must be the Teamcenter Server's hostname that is added as the FMS target in the proxy configuration. For example, `TEAMCENTER01`

8. **Secondary HaloENGINE** : If you want to set up a failover mechanism in your environment, select this check box. HaloCAD supports connection failover between two HaloENGINEs. For more information, please refer to the section "[Failover Mechanism for HaloENGINE in HaloCAD for PLM](https://help.secude.com/halocad-for-siemens-teamcenter/2.8/tc-appendix.md#fail)".

**Secondary HaloENGINE Configuration**

You can skip this step if you haven't chosen the Secondary HaloENGINE option. This step is only necessary if you want to use the failover mechanism.

Prerequisite: Ensure that the secondary HaloENGINE uses the same configuration profiles and rules as the primary HaloENGINE. Thus, when the primary HaloENGINE fails, the secondary HaloENGINE immediately takes over, assuring continuous operation.

1. **Certificate Name** : Click **Choose File** to browse and select the client Keystore in JKS format, generated by the HaloENGINE Admin Portal \[through which communication is established between HaloENGINE (secondary) and Teamcenter\]. For example, `Teamcenter02_ClientKey.jks`

2. **Password** : Enter the password of the selected client Keystore. For example, `Key$T#1234`

3. **HaloENGINE Host** : Enter the IP address/FQDN of HaloENGINE. For example, `10.91.0.190`

4. **HaloENGINE** **Endpoint Port** : Enter the endpoint port from which HaloENGINE can be accessed. For example, `8746`

5. Click **Apply** . A red tooltip message appears if any required values are missing. Enter the missing information and click **Apply** to continue.

**Result:**

* A progress bar indicates that the "*Restarting Tomcat Service"*.

* A confirmation message dialog box appears.

* Click **OK** to close the confirmation dialog box.

**Step 4.** Go to the **SOA Validation** tab and check the connection status.  
![3_Tool_SOA Configuration.png](https://help.secude.com/__attachments/a_5e69d61f32418b614e7ee7a453fd542bc6f18ae6b8e30c80c910ac1970d5a7d7/3_Tool_SOA%20Configuration.png?cb=047946c841a5ed4d0bb8fbcedca2e009)

*SOA Validation tab*

1. Press the **SOA Login Check** button to confirm the SOA credential configuration.

2. Click **Apply** . A red tooltip message appears for any missing values. Enter the required information and click **Apply** to continue.

**Result:**

* A progress bar indicates that "*Checking SOA Login connection status"* is in progress.

* If the connection is successful, a confirmation message dialog box appears. Click **OK** to close the dialog box.

* If the connection fails, an appropriate warning message appears. Follow the on-screen instructions and try again.

**Step 5** . Go to the **Others**tab, and then enter the following information.  
![4_Tool_Others tab.png](https://help.secude.com/__attachments/a_8c7b6c4982da4fa488528561bb4528dcc03239e57a6588321c420ac786a4d802/4_Tool_Others%20tab.png?cb=49d662181f0a42b6aefa5de550a566c7)

*Others tab*

1. **Custom Attribute**

   1. If you do not want to use custom attributes, click **Apply**, and then close the configuration tool window.

   2. If you want to use custom attributes, choose **Yes** in **Custom Attribute**, and then fill out the following information.

2. **New Attribute** : Enter the name of an attribute and then click **Add** . Enter the exact custom property name that was provided during the custom property configuration. For example, the **document** is a new attribute added to the list.

3. The attribute will be added to the **Attribute Name** list.

4. Click **Apply** . A red tooltip message appears for any missing values. Enter the required information and click **Apply** to continue.

**Result:**

* A confirmation message dialog box appears.

* Click **OK** to close the dialog box.

* To remove an attribute from the list, select the attribute, click **Remove** , and then click **Apply** to save the configuration.

### Dataset Configuration - DatasetFromIman

The following steps are to be carried out by a user with DBA privileges on the Teamcenter server. For illustration, the user account **Infodba** is used.

1. Click the **Query Builder** icon in the navigation pane.

2. Click on **Saved Queries**. A new query page will appear, and you need to enter the following details.

   1. Enter **DatasetFromIman** inthe **Name**text box.

   2. In **Search Type** , select **Dataset** from the list.

   3. In **Modifiable Query Types** , select **Local Query** from the list.

   4. Under the **Properties Selection** section, double-click on the property**ref_list** . The **Business Type Selection Dialog** will appear.

   5. You need to search for **ImanFile** and double-click on it. It will be added to the property.

   6. The property name will now appear as **ref_list \[File\]**.

   7. Under **ref_list \[File\]** , double-click on **file_name** .You can see the attributes being displayed in the **Search Criteria** section.

      ![DatasetFromIman - Query 1.png](https://help.secude.com/__attachments/a_28edef793dc8dc477dfe153eb45840b2c8cff738e5afa72f6e32b7a2523b73db/DatasetFromIman%20-%20Query%201.png?cb=7deed9ff5990b3850906e0ece8d349f7)

      *Adding a new query - DatasetFromIman*
3. Click **Create**.

   **Result**: The query is saved and added to the Query Builder list.

### TCCS Configuration

The following procedure explains how to change the File Management System (FMS) master file and FMS client cache (FCC) file in the Teamcenter client communication system (TCCS). We recommend that you make a backup of the current two XML files.

1. **Step 1**. Modify the FMS master file.

   1. Go to Siemens installed location `<Installed_Path>\Siemens\Teamcenter12\fsc\fmsmaster_FSC_<ComputerName>_Teamcenter.xml>.`

      **For example** ,`C:\Program Files\Siemens\Teamceter12\fsc\fmsmaster_FSC_tclu0310_Teamcenter.xml`

   2. Open the XML file with administrator privileges and add the following line after `<fscgroup id="mygroup"> tag` along with the port number as shown in the example below:

      **Line format** :`<loadbalancer id="ReverseProxy" address="<host>:<port>/tc/fms/" />`

      **For Example** ,`<loadbalancer id="ReverseProxy" address="http://tclu0310.Secude.local:8080/tc/fms/" />`

   3. Save the file.

2. **Step 2** . Modify the FCC file.

   1. Go to the Siemens installed location `<Installed_Path>\Siemens\Teamcenter12\tccs\fcc.xml`\>.

      **For example** ,`C:\Program Files\Siemens\Teamceter12\tccs\fcc.xml`

   2. Open the XML file with administrator privileges and add the following line along with the port number as shown in the example below:

      **Line format** : `<parentfsc address="http://<host>:<port>/tc/fms" priority="0" transport="lan"/> <assignment address="parentfsc address">`

      **For Example** , `<parentfsc address="http://tclu0310.Secude.local:8080/tc/fms" priority="0" transport="lan"/> <assignment mode = "parentfsc">`
   3. Save the file.

3. **Step 3** . Restart the Siemens service.

   1. Restart the Teamcenter FSC Service (**FSC_\<serverhostname\>_Teamcenter** ) via the **Windows Services Manager**.

   2. Please note that whenever XML files are modified, the FSC service should be restarted.

### Configuration Using the Command Line

This is an alternative method of configuring the HaloCAD and HaloENGINE parameters using the command line.

Prerequisite: Ensure HaloCAD for Teamcenter is installed.

Follow the command-line instructions. A sample is provided below:

1. Open a command prompt, navigate to the destination folder, then type java -jar halocad-teamcenter-config-\<version\>.jar -shell and press **Enter**.

       C:\Program Files\Secude\HaloCADTeamcenter\config>java -jar halocad-teamcenter-config-<version>.jar -shell
       -----------------------------------------------------------------
       -----------------------------------------------------------------
       HaloCAD for Teamcenter
       Config Path: C:\Program Files\Secude\HaloCADTeamcenter\config
       1. Teamcenter Configuration
       2. Primary HaloENGINE Configuration
       3. SOA Validation
       4. Others
       0. Exit
       Note: If an invalid value is entered, the default value will be applied.
       Please choose an option:1

       -----------------------------------------------------------------

       -----------------------------------------------------------------
       Teamcenter Configuration:
       -----------------------------------------------------------------
       Enter the Proxy URL:
       http://tclu0310.secude.local:8080

       Enter the Tomcat path:
       C:\Program Files\Secude\Tomcat

       Fail Safe Mode: (Default:Tolerant)
       1. Tolerant
       2. Strict

       Please choose an option:
       1

       Fail Optimization: (Default:Single Label Optimization)
       1. Multi Label Optimization
       2. Single Label Optimization

       Please choose an option:1

       Awc Microservice: (Default:AWC Disable)
       1. AWC Enable
       2. AWC Disable

       Please choose an option:
       2

       Log Level: (Default:INFO)
       1. INFO
       2. DEBUG
       3. ERROR

       Please choose an option:
       2

       Enter the FMS Target URI:
       http://tclu0310.secude.local:4544

       Enter the AWC Target URI:
       http://tclu0310.secude.local:80/awc

       Enter the Group Name:
       dba

       Enter the Serverhost:
       http://tclu0310.secude.local:80/tc

       Enter the TC Username:
       teamcenter_admin

       Enter the TC Password:

       -----------------------------------------------------------------
       Teamcenter Configuration:

       Proxy URL                       :http://tclu0310.secude.local:8080
       Tomcat Path                     :C:\Program Files\Secude\Tomcat
       Fail Safe Mode                  :Tolerant
       Fail Optimization               :Multi Label Optimization
       Awc Microservice                :AWC Disable
       Log Level                       :DEBUG
       FMS Target URL                  :http://tclu0310.secude.local:4544
       AWC Target URL                  :http://tclu0310.secude.local:80/awc
       Group Name                      :dba
       Server host                     :http://tclu0310.secude.local:80/tc
       TC UserName                     :teamcenter_admin

       1. Modify all configuration
       2. Modify the particular configuration
       3. Back to main menu
       0. Exit

       Please choose an option:
       3
       --------------------------------------------------------------------------------
       1. Teamcenter Configuration
       2. Primary HaloENGINE Configuration
       3. SOA Validation
       4. Others
       0. Exit
       Note: If an invalid value is entered, the default value will be applied.
       Please choose an option:2
       --------------------------------------------------------------------------------
       --------------------------------------------------------------------------------
       Certificate Configuration:
       --------------------------------------------------------------------------------
       Enter the Primary Certificate Path:
       C:\Users\Administrator\Desktop\Certs\Teamcenter01_ClientKey.jks
       File name:Teamcenter01_ClientKey.jks.

       Enter the Primary certificate Password:

       Enter the Primary HaloENGINE Host:
       10.41.14.169

       Enter the Primary HaloENGINE Endpoint Port: (Default:8746)
       8746

       Enter the Customer ID:
       halo_customer

       Enter the System ID:
       TEAMCENTER01

       Secondary HaloENGINE: (Default:Disable Secondary HaloENGINE)
       1. Disable Secondary HaloENGINE
       2. Enable Secondary HaloENGINE

       Please choose an option:
       1
       Saved Successfully.
       --------------------------------------------------------------------------------
       Primary HaloENGINE Configuration:

       Primary Certificate Name         :Teamcenter01_ClientKey.jks
       Primary HaloENGINE Host          :10.41.14.169
       Primary HaloENGINE Endpoint Port :8746
       HaloENGINE Service File Mode     :File Path
       Customer ID                      :halo_customer
       System ID                        :TEAMCENTER01
       Secondary HaloENGINE             :Disable Secondary HaloENGINE

       1. Modify all configuration
       2. Modify the particular configuration
       3. Back to main menu
       0. Exit
       Please choose an option:
       3
       --------------------------------------------------------------------------------
       1. Teamcenter Configuration
       2. Primary HaloENGINE Configuration
       3. SOA Validation
       4. Others
       0. Exit
       Note: If an invalid value is entered, the default value will be applied.
       Please choose an option:3
       --------------------------------------------------------------------------------

       --------------------------------------------------------------------------------
       SOA Login connection status:
       --------------------------------------------------------------------------------
       1. Check SOA connection status
       0. Exit

       Please choose a valid option:1
       Checking Teamcenter Login status, Please wait.
       Oct 25, 2024 3:11:58 AM com.secude.halocad.teamcentercmd.AppXSessionCMD loginShell
       INFO: TC--> Login successful

       1. Check Status again
       2. Back to main menu
       0. Exit

       Please choose an option:
       2
       --------------------------------------------------------------------------------
       1. Teamcenter Configuration
       2. Primary HaloENGINE Configuration
       3. SOA Validation
       4. Others
       0. Exit
       Note: If an invalid value is entered, the default value will be applied.
       Please choose an option:4
       --------------------------------------------------------------------------------
       Others...
       Custom Attribute                 :No

       1. Custom Attribute
       2. Back to main menu
       0. Exit

       Please choose an option:
       1
       --------------------------------------------------------------------------------
       Custom Attribute: (Default:No)
       1. No
       2. Yes

       Please choose an option:
       1
       Custom Attribute Disabled Successfully.
       --------------------------------------------------------------------------------

2. Click **Close**to close the command prompt.

---
version: "2.8"
language: "en"
---
# Configuring the Tomcat Service

**About the Term "HaloENGINE Tomcat Service"**

The HaloENGINE Tomcat Service is a common component used in both the HaloENGINE and HaloCAD products. Since it was initially developed for HaloENGINE and later adopted across HaloCAD, all Tomcat instances in Secude appear under the name "HaloENGINE Tomcat Service."

During installation, Azure details are provided to initialize the HaloENGINE Tomcat Service. After successful authentication, the labels are fetched automatically. To update MPIP-related details (such as the Application ID), use`heslibconfig.exe`.

**Default locations of log files**  

|      **Name**      |                                       **Default Path**                                        |
|--------------------|-----------------------------------------------------------------------------------------------|
| HaloCAD log        | `C:\Program Files\Secude\Tomcat\logs\haloproxy.log`                                           |
| Configuration tool | `C:\Program Files\Secude\HaloCADTeamcenter\HaloENGINEService\lib\heslibconfig.exe`            |
| MIP logs           | `C:\Program Files\Secude\HaloCADTeamcenter\HaloENGINEService\logs\mip_cache_storage\mip\logs` |

*Default locations*

To update your Azure details, follow the procedure below.

1. Open the Command Prompt with elevated rights (Run as Administrator).

2. Navigate to the directory where `heslibconfig.exe` is located.

3. To view the list of available options in silent mode, enter the following command:

   **Type** `heslibconfig.exe -help`

   **Press** `Enter`

   **Output**

   `Usage:`

   `heslibconfig.exe -testmip`

   `heslibconfig.exe -update -applicationid <application_id> -tenantid <tenant_id> -thumbprint <thumb_print> -cloudtype <(Commercial|Custom|Germany|US_DoD|US_GCC|US_GCC_HIGH|US_Sec|US_Nat|China_01) (if cloudtype is Custom) <protectioncloudurl> <policycloudurl>`

4. The following command illustrates how to update json file.

   `heslibconfig.exe -update -applicationid 9f0de2dd-8d49-4a3f-9676-bf4b6ff17d44 -tenantid 8c425ee7-352a-4657-ac77-7dc198712cb3 -thumbprint 961602617275c2ab538cf28bb3648c0c6d97edab -cloudtype Custom https://api.aadrm.com https://dataservice.protection.outlook.com`

5. A confirmation message appears stating that the configuration JSON file location has been successfully updated, `...\config\HaloENGINESVC.json`

**Configuration change in JSON File**

After installation, navigate to the configuration folder`...\HaloENGINEService\config`, and you will find a JSON file that contains the HaloENGINE Tomcat Service configuration properties. Note: From the list of default parameters, only the parameters listed below should be modified, and only when necessary. All other parameters must remain at their default values to ensure proper system functionality and stability.  

|        **Name**        |                                                                                                                                                                                                                                                                           **Description**                                                                                                                                                                                                                                                                           |
|------------------------|---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| block_pii              | Enable or disable the visibility of Personally Identifiable Information (PII) in the MIP SDK logs. * false---PII will be visible in clear text in the MIP SDK logs. * true---PII will be masked with asterisks in the MIP SDK logs. This helps to protect the PII's confidentiality.                                                                                                                                                                                                                                                                                |
| cachetype              | MPIP cache storage type used by the service. * In Memory---0, maintains the storage cache in memory in the application. * On Disk---1 (default storage type), stores the database (SQLite3) on disk in the directory provided in the settings object. The database is stored in plaintext. * On Disk Encrypted---2, stores the database (SQLite3) on disk in the directory provided in the settings object. The database is encrypted using OS-specific APIs.                                                                                                       |
| cacheuserlicense       | * 0---false, End User License (EUL) will NOT be stored in the MPIP cache storage. * 1---true (default value), End User License (EUL) will be stored in the MPIP cache storage                                                                                                                                                                                                                                                                                                                                                                                       |
| databoundary           | Audit and telemetry events are sent to the nearest collector, where these events are stored and processed. Other options: 1. Asia 2. Europe_MiddleEast_Africa 3. European_Union 4. North_America For example, if your AIP administrator sets North_America, the HaloENGINE Tomcat Service forces all telemetry and audit data to go directly to North America.                                                                                                                                                                                                      |
| enabledke              | Double Key Encryption * 0 (default value)---Disables the DKE functionality in the HaloENGINE Tomcat Service. * 1 (On)---Enables the DKE functionality in the HaloENGINE Tomcat Service. Please be aware that DKE labels are only visible when DKE functionality is enabled.                                                                                                                                                                                                                                                                                         |
| enablefiletracking     | To register a protected file to track and revoke. * 0 (default value)---the protected file will not be registered for file tracking and access revocation. * 1---The protected file will be registered for file tracking and access revocation                                                                                                                                                                                                                                                                                                                      |
| enableminimaltelemetry | To transmit diagnostic information to Microsoft. * 0 (default value)---all diagnostic events are transmitted. * 1---Minimum diagnostic events are transmitted.                                                                                                                                                                                                                                                                                                                                                                                                      |
| log_level              | The available log levels are ERROR, WARNING, INFO, and DEBUG.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| log_purge              | It indicates removing files older than a defined time frame. By default, the log files older than 7 days will be deleted.                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| streambuffersize       | It is a buffer size used for memory-based encryption with the MIP SDK. When the allotted buffer size is exceeded, an additional memory of stream buffer size is allocated, and this process is repeated until the encryption/decryption operation is completed. The default setting is 10MB.                                                                                                                                                                                                                                                                        |
| templatefile_purge     | Defines the purge time of template files that are generated for every CAD assembly file (compound file) download. The default value set is one hour. For example, when a file is downloaded at 15:25 hours, the HaloENGINE Tomcat Service creates a template file in the tmp\\GUID folder (which can be located in the HaloENGINE Tomcat Service user's profile folder). In the background, it examines and deletes files that have reached the configured time, i.e., after 16:25 hours. Note: This is only applicable in the event of CAD assembly file labeling. |

*HaloENGINE Tomcat service configuration*

## **WinHTTP Proxy Settings**

To allow MIP SDK to use the proxy settings set up in your environment, follow the steps below:

**Determine whether the proxy server has been properly set up by running the following command.**

    C:\Windows\system32>netsh winhttp show proxy

    Current WinHTTP proxy settings:

    Direct access (no proxy server).

If the response to the command is as shown above, it indicates that the proxy server has not been configured in the registry for WinHTTP.

**To configure the proxy server for WinHTTP, use the following command:**

**Syntax** : `C:\Windows\system32>netsh winhttp set proxy <proxyservername>:<portnumber>`

**Example** : `C:\Windows\system32>netsh winhttp set proxy 190.160.166.191:8080`

In this case, the proxy server has been set up with `190.160.166.191:8080`. Once this command is executed successfully, the registry is updated with the proxy server URL, and the HaloENGINE Tomcat Service ensures that the configured proxy settings are applied.

---
version: "2.8"
language: "en"
---
# Appendix

This section provides supplemental information.

## Supported FMS Configurations

Teamcenter supports various FMS configurations based on the volume of files to be stored, how often files are accessed by clients, and client geographical location (remote).

For illustration purposes, the supported configurations are listed below:

1. **Single FSC**

   1. **With single volume** --Typically for simple deployment. Teamcenter provides a single FSC that mounts a single volume. In this case, enter the URL in the "[FMS Target URL](https://help.secude.com/halocad-for-siemens-teamcenter/2.8/configuring-the-halocad-proxy.md#FMS)".

   2. **With multiple volumes** -- A standard small or medium deployment with a large volume of file storage. In this case, each volume will have an entry under this FSC. Here, enter the URL in the "[FMS Target URL](https://help.secude.com/halocad-for-siemens-teamcenter/2.8/configuring-the-halocad-proxy.md#FMS)" field.

   3. A sample of the FMS master file is shown below for illustration purposes:

      `<fscgroup id="mygroup">`

      `<loadbalancer id="ReverseProxy" address="http://SAMPLE.local:8080/tc/fms" />`

      `<fsc id="FSC_SAMPLE_Teamcenter_3" address="http://SAMPLE.local:4544" ismaster="true">`

      `<volume id="9c1cfc281ec644eabec6" enterpriseid="-1234567890" root="C:\Program Files\Siemens\volume" priority="0" />`

      `<transientvolume id="v6ca776c74e437d98ef662ecb5751tt" enterpriseid="-1234567890" root="C:\\Temp\\transientVolume_Teamcenter" />`

      `</fsc>`

2. **Multiple FSCs with Multiple Volumes** -- Numerous files are accessed simultaneously by the clients from more than one FSC or a single file from any one of the configured FSC. For instance, in the below case, a client is configured to connect with more than one FSC. Therefore, you must specify the details in the [Other Target URL](https://help.secude.com/halocad-for-siemens-teamcenter/2.8/configuring-the-halocad-proxy.md#OT) field.

   ![Teamcenter_Other URI.png](https://help.secude.com/__attachments/a_c1251f05b04d55ae77c6711e90080b989b289c0c2780f430f2746bea4b9aef48/Teamcenter_Other%20URI.png?cb=ed0d25fffaff494d2149f02faf4aae66)

   *Other Target URL Setup*

   A sample of the FMS master file is shown below for illustration purposes:

       <fscgroup id="mygroup">
       <loadbalancer id="ReverseProxy" address="http://PUN-FMS:8080/tc/fms"/>
       <fsc id="PUN-FMS_usprd01" address="http://PUN-FMS:4544" ismaster="true">
       <volume id="123d0000000f8c9bd0d7" enterpriseid="-1234567890" root="E:\Siemens\usprd01_vols\dba_vol1" priority="0" />
       <volume id="456a000001388c9bd0d7" enterpriseid="-1234567890" root="E:\Siemens\usprd01_vols\lyn_vol1" priority="0" />
       <volume id="7898001339268c9bd0d7" enterpriseid="-1234567890" root="F:\Siemens\usprd01_vols\dba_vol2" priority="0" />
       <volume id="0123001339268c9bd0d7" enterpriseid="-1234567890" root="F:\Siemens\usprd01_vols\lyn_vol2" priority="0" />
       <transientvolume id="7f16bd0578697f1eb1bbb4b5020aadef" enterpriseid="-1234567890" root="D:\\Temp\\transientVolume_usprd01" priority="0" />
       </fsc>
       <fsc id="PUN-FMS_YUN_WEB20P_usprd01" address="http://PUN-FMS-WEB:4544" ismaster="false">
       <transientvolume id="8c425ee7352a4657ac777dc198712cb3" enterpriseid="-1234567890" root="D:\\Temp\\transientVolume_usprd01" priority="0" />
       </fsc>
       <fsc id="PUN-FMS_YUT_usprd01" address="http://PUN-FMS-YUT:4544" ismaster="true">
       <volume id="c07e4bfa95a44a0894b0" enterpriseid="-1234567890" root="D:\Siemens\usprd01_vols\YUT_vol1" priority="0" />
       </fsc>
       <fsc id="PUN-FMS_YRT_usprd01" address="http://PUN-FMS-YRT:4544" ismaster="true">
       <volume id="9c1cfc281ec644eabec6" enterpriseid="-1234567890" root="D:\Siemens\usprd01_vols\YRT_vol1" priority="0" />
       </fsc>
       <clientmap subnet="127.0.0.1" mask="0.0.0.0">
       <assignedfsc fscid="PUN-FMS_YUN_WEB20P_usprd01" priority="0" />
       </clientmap>
       </fscgroup>

## Failover Mechanism for HaloENGINE in HaloCAD for PLM

Server failover between two systems supports uninterrupted operation and service reliability in case of a breakdown. The server failover configuration is "active-standby," meaning that the primary server is "active", and the secondary server is "standby."

HaloCAD for PLMsupports connection failover between two HaloENGINEs. Here's a summary of its purpose:

1. **High Availability** : If the primary HaloENGINE fails, the secondary HaloENGINE will take over, reducing downtime and maintaining continuous operation.

   **Example** : Let us assume that your business process requires no downtime.

   As per the business security policy, your administrator has configured Fail-Safe Mode as Strict to block any file upload or download whenever an error occurs. If HaloENGINE encounters an unexpected issue, failure to obtain label information will prevent file download or upload. In this instance, the failover mechanism in HaloENGINE will be the ideal option for dealing with such unforeseen scenarios, with no impact on the end user. Thus, even if the primary HaloENGINE connection fails, HaloCAD recognizes the failure and instantly switches to the secondary HaloENGINE to continue providing services.

   Once the primary HaloENGINE is restored, it will be a standby for the secondary HaloENGINE. If there is any failure in the secondary HaloENGINE, the primary HaloENGINE will again take over the operations.

   ![Common_Failover-01.png](https://help.secude.com/__attachments/a_e6614ec719eee4cd35653bf74fd229e0e9f8949ac1cae6bc2a8a3543bfa96b12/Common_Failover-01.png?cb=cc2e5bd73e82b814346be5b3f1bc6d3b)

   *Failover Mechanism for HaloENGINE in HaloCAD for PLM*
2. **Redundancy**: It provides redundancy, which means there is always another HaloENGINE ready to take over if the primary one fails. This minimizes the possibility of a single point of failure.

3. **Data Integrity and Consistency**: In the event of a failure, the failover technique can help guarantee that data is consistent and file upload/download activities are not lost, which is crucial for systems that rely on high data security.

  **Failover Mechanism Requirement**

1. Network Infrastructure: Minimal Secondary HaloENGINE needs to be segmented so that the primary and secondary HaloENGINEs don't share the same network.

2. Data replication: Both HaloENGINEs must have the same classification profiles and rules.

## Third-Party Libraries

Third-party software/code is included or bundled with Secude's products according to its appropriate license. Secude conducts testing to make sure the third-party products are compatible with and perform as intended with Secude applications.

The third-party libraries and dependencies used by HaloCAD for Teamcenter are shown in the table below.  

|    **Library**     | **Version** |                                      **Source Code**                                       |                                                               **License Link**                                                               |
|--------------------|-------------|--------------------------------------------------------------------------------------------|----------------------------------------------------------------------------------------------------------------------------------------------|
| HTTP-Proxy-Servlet |             | <https://github.com/mitre/HTTP-Proxy-Servlet>                                              | <https://github.com/mitre/HTTP-Proxy-Servlet/blob/master/LICENSE.txt>                                                                        |
| httpmime           | 4.5.+       | <https://mvnrepository.com/artifact/org.apache.httpcomponents/httpmime>                    | <http://www.apache.org/licenses/LICENSE-2.0.txt>                                                                                             |
| httpclient         | 4.5.+       | <https://mvnrepository.com/artifact/org.apache.httpcomponents/httpclient>                  | <http://www.apache.org/licenses/LICENSE-2.0.txt>                                                                                             |
| mail               | 2.1.1       | <https://mvnrepository.com/artifact/javax.mail/mail>                                       | <http://www.sun.com/cddl> <https://glassfish.java.net/public/CDDL+GPL_1_1.html>                                                              |
| commons-io         | 2.+         | <https://mvnrepository.com/artifact/commons-io/commons-io>                                 | <https://www.apache.org/licenses/LICENSE-2.0.txt>                                                                                            |
| javax.servlet-api  | 5.0.0       | <https://mvnrepository.com/artifact/javax.servlet/javax.servlet-api>                       | <https://glassfish.dev.java.net/nonav/public/CDDL+GPL.html>                                                                                  |
| jna                | 5.13.0      | <https://mvnrepository.com/artifact/net.java.dev.jna/jna>                                  | <http://www.apache.org/licenses/LICENSE-2.0.txt> <http://www.gnu.org/licenses/licenses.html>                                                 |
| jna-platform       | 5.13.0      | <https://mvnrepository.com/artifact/net.java.dev.jna/jna-platform>                         | <http://www.apache.org/licenses/LICENSE-2.0.txt> [http://www.gnu.org/licenses/licenses.html](http://www.apache.org/licenses/LICENSE-2.0.txt) |
| MIP SDK            | 1.18.103    | <https://learn.microsoft.com/en-us/information-protection/develop/version-release-history> | <https://docs.microsoft.com/en-us/information-protection/develop/>                                                                           |
| MSAL               | 4.82.1      | <https://github.com/AzureAD/microsoft-authentication-library-for-dotnet>                   | <https://github.com/AzureAD/microsoft-authentication-library-for-dotnet/blob/master/LICENSE>                                                 |
| Spdlog             | 1.15.3      | -                                                                                          | <https://github.com/gabime/spdlog>                                                                                                           |

*Third-party libraries*

## **Metadata Definition**

The table below lists the Teamcenter metadata available in the HaloENGINE.  

|       **Teamcenter metadata**       |                                                                                               **Use**                                                                                               |
|-------------------------------------|-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| user_role                           | Derivation from the user role. Multiple roles may be assigned to a single user. (For example, Designer and Engineer)                                                                                |
| user_def_group                      | Derivation from a group of users who log in. (For example, a user from the Engineering group)                                                                                                       |
| gov_clearance                       | Derivation from a specific object based on value or licensing value. (For example, secret - single value field)                                                                                     |
| ip_clearance                        | Derivation from intellectual property (IP) classification values and clearance levels assigned to data objects and users for IP access evaluation. (For example, super-secret - single value field) |
| user_name                           | Derivation from Teamcenter logged-in users. (For example, John and Derek)                                                                                                                           |
| file_type                           | Derivation from file type and Teamcenter object data. (NX file types and MS Office native file types) (For example, prt, asm, and XLSX)                                                             |
| gov_classification                  | Derivation from a Teamcenter object based on its value or license value. (For example, secret - single value field)                                                                                 |
| obj_project_names                   | Derivation from Teamcenter object data. The object could be used in several projects. (For example, project1; project2- multi-value- field)                                                         |
| ip_classification                   | Derivation from Teamcenter's intellectual property (IP). (For example, secret, internal, and confidential - single value field)                                                                     |
| preexpression_custom_pre-expression | Derivation from custom pre-expression. 1. Yes 2. No                                                                                                                                                 |

*Teamcenter metadata*

## Download Log Definition

This section explains the log definition for every log format that HaloENGINE supports.

### What is SIEM Integration?

SIEM, which stands for Security Information and Event Management, is a comprehensive approach to managing an organization's security information and events. SIEM integration refers to the process of incorporating SIEM solutions into an organization's existing IT infrastructure to enhance its ability to monitor, detect, and respond to security incidents. To support this approach, HaloENGINE transmits logs in JavaScript Object Notation (JSON), Log Event Extended Format (LEEF), and Common Event Format (CEF).

1. Common Event Format is an open log management standard developed by HP ArcSight. CEF comprises a standard prefix and a variable extension that is formatted as key-value pairs.

2. Log Event Extended Format is a customized event format for IBM Security QRadar. LEEF comprises a LEEF header, event attributes, and an optional Syslog header.

3. JavaScript Object Notation is a lightweight text-based open standard designed for human-readable data interchange.

These logs are forwarded to the communications module, which transmits them to your collection server via UDP or TCP. Ideally, a SIEM (Microsoft Azure Sentinel, Splunk, RSA, and others) server would scan the received messages, sort them, and alert your security team.  
![Autodesk Vault_Forwarding logs.png](https://help.secude.com/__attachments/a_caa4b5c382070a1ab60279c3c4b89c51b1f903bd989889a1c05ee4c5c2bfb2e1/Autodesk%20Vault_Forwarding%20logs.png?cb=830c00f8f714410293fe6ff0beebd44e)

*Forwarding logs*

### **Why CEF Standard?**

The CEF format is an open log management standard that simplifies log management. CEF allows third parties to create their device schemas that are compatible with a standard that is used industry-wide for normalizing security events. Technology companies and customers can use the standardized CEF format to facilitate data collection and aggregation, for later analysis by an enterprise management system. CEF is an extensible, text-based format designed to support multiple device types by offering the most relevant information. It defines the syntax for log records consisting of a standard header and a variable extension, formatted as key-value pairs.

**Syslog and CEF Header**

The data is normalized and categorized into the ArcSight CEF for easy correlation and analysis. CEF uses Syslog as a transport mechanism. It uses the following format, consisting of a Syslog prefix, a header, and an extension, as shown below. If an event producer is unable to write Syslog messages, it is still possible to write the events to a file.  

|--------------------------------|
| `Prefix │ Header │[Extension]` |

*CEF format*  

|-------------------------------------------------------------------------------------------------------------------|
| `10:29:48.486 host CEF:Version|Device Vendor|DeviceProduct|Device Version|Signature ID|Name|Severity|[Extension]` |

*CEF format sample*  

| **Format** |                                                                                                                                                                                                                                                                                         **Description**                                                                                                                                                                                                                                                                                          |             **Example**              |
|------------|--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|--------------------------------------|
| Prefix     | Syslog applies a prefix to each message, no matter which device it arrives from, that contains the date and hostname.                                                                                                                                                                                                                                                                                                                                                                                                                                                                            | `10:29:48.486`                       |
| Header     | Version is an integer and identifies the version of the CEF format. The current CEF version is 0 (CEF:0).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        | `CEF:0`                              |
| Header     | Device Vendor, Device Product, and Device Version are strings that uniquely identify the type of sending device.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 | `|Secude|HaloCAD|6.10.0.0|`          |
| Header     | * Device Event Class ID is a unique identifier per event-type. * This can be a string or an integer. Device Event Class ID identifies the type of event reported.                                                                                                                                                                                                                                                                                                                                                                                                                                | `100` (User download)                |
| Extension  | The Extension field contains a collection of key-value pairs. The keys are part of a predefined set. The standard allows for including additional keys as outlined in "ArcSight Extension Dictionary". An event can contain any number of key-value pairs in any order, separated by spaces (""). If a field contains a space, such as a filename, this is valid and can be logged in exactly that manner. Secude uses only Standard Key Names from ArcSight Extension Directory and no custom extensions. The reason for that is to avoid significant limitations custom extensions will cause. | Please refer to the following table. |

*CEF Header details*  

|------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| `12:39:08.384 CEF:0|Secude|HaloCAD|6.10.1.0|106|user upload|1|deviceCustomDate1Label=exportTime deviceCustomDate1=Apr 16 2026 07:09:08 UTC externalId=453FFC46378F471BA774D309DB99AA54 deviceCustomDate2Label=logTime deviceCustomDate2=Apr 16 2026 07:09:08 UTC act=unblocked;unlabeled;decrypted;protected_originally fname=checki_exc_4sv09j4bn7aj7.xlsx filePath=FMS_SHA256_SIGNATURE=9ab166ff5a71001c22d2fc93c3f19077217f61a9142bc6dc5f90a7d90a8c848003c66796365c9623698f7a4db018f61e988cce819a4b66de054217c0d65b6c72;\dba_67fe4f61\checki_exc_4sv09j4bn7aj7.xlsx fileType=xlsx fsize=49395 in=7693 shost=TC11 duser=infodba,type:TEAMCENTER dst=10.41.14.203 requestClientApplication=[null] cs2Label=DataDestination cs2=[ platform\=[Unknown], browser\=[FMS-FCC/2406 (bd:20240517) FMS-FCC/2406 (bd:20240517)], browser_version\=[null], device_type\=[null], terminal_id\=[SVLU0310], destination_attributes\=[{ key\=[client_ip], value\=[10.41.14.203], type\=[null] }, { key\=[client_host], value\=[SVLU0310], type\=[null] }] ] cs3Label=DataOrigin cs3=[ source_type\=[PLM], system_name\=[TC11], client_type\=[TEAMCENTER], plm_info\=[{ key\=[file_name], value\=[checki_exc_4sv09j4bn7aj7.xlsx], type\=[null] }, { key\=[folder_name], value\=[dba_67fe4f61], type\=[null] }, { key\=[ip_classification], value\=[super-secret], type\=[null] }]] cs4Label=ClassifyProtectionData cs4=[ error\=[false], author\=[HaloENGINE Service] ]` |

*CEF sample*

### Why LEEF Standard?

The Log Event Extended Format (LEEF) is a customized event format for IBM Security QRadar that contains readable and easily processed events for QRadar.

**Syslog and LEEF Header**

The LEEF format consists of a Syslog header, a LEEF header, and event attributes. The Syslog header is an optional field. The Syslog header contains the timestamp and IPv4 address or hostname of the system that sends the event. The LEEF header is a required field for LEEF events. The LEEF header is a pipe delimited (\|) set of values that identifies your software or appliance to QRadar. Event attributes identify the payload information of the event that is produced by your appliance or software. Every event attribute is a key-value pair with a tab that separates individual payload events.  

|---------------------------------------------------|
| `Syslog Header │ LEEF Header │[Event Attributes]` |

*LEEF format*  

| `12:19:21.901 LEEF:2.0|Secude|HaloCAD|6.10.1.0|106|^|exportTime=Apr 16 2026 06:49:21 UTC^eventName=user upload^externalId=1F26CC928AB54656B8202FEA7948C6EA^logTime=Apr 16 2026 06:49:21 UTC^act=unblocked;unlabeled;decrypted;protected_originally^fname=xlsxte_exc_6j409v0bn79m8.xlsx^filePath=FMS_SHA256_SIGNATURE=acb57878d26493703ee825e4dc074b06b8ba66b19873bd294f159a26d790ba588dc9e01bd566e2d9c9d626df086c717089c356b81056f1cb89b2107708741d6b;\dba_67fe4f61\xlsxte_exc_6j409v0bn79m8.xlsx^ftype=xlsx^fsize=49392^fdwnsize=7693^shost=TC11^usrName=infodba,type:TEAMCENTER^dst=10.41.14.203^usrAgent=[null]^dataDestination=[ platform=[Unknown], browser=[FMS-FCC/2406 (bd:20240517) FMS-FCC/2406 (bd:20240517)], browser_version=[null], device_type=[null], terminal_id=[SVLU0310], destination_attributes=[ {key=[client_ip], value=[10.41.14.203], type=[null]}, {key=[client_host], value=[SVLU0310], type=[null]} ] ]^dataOrigin=[ source_type=[PLM], system_name=[TC11], client_type=[TEAMCENTER], plm_info=[ {key=[file_name], value=[xlsxte_exc_6j409v0bn79m8.xlsx], type=[null]}, {key=[folder_name], value=[dba_67fe4f61], type=[null]}, {key=[ip_classification], value=[super-secret], type=[null]} ] ]^classifyProtectionData=[ error=[false], author=[HaloENGINE Service] ]` |
|-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|

*LEEF format sample*  

|    **Format**    |              **Description**              |                                                                                                                **Example**                                                                                                                 |
|------------------|-------------------------------------------|--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| Syslog Header    | The Syslog header contains the timestamp. | `14:37:02.651`                                                                                                                                                                                                                             |
| LEEF Header      | LEEF:version                              | An integer value that identifies the major and minor version of the LEEF format that is used for the event, for example, `LEEF:2.0|Vendor|Product|Version|EventID|`                                                                        |
| LEEF Header      | Product name                              | A text string that identifies the product that sends the event log to QRadar, for example, `LEEF:2.0|Secude|HaloCAD|6.10.0.0|100|`                                                                                                         |
| LEEF Header      | Product version                           | A string that identifies the version of the software or appliance that sends the event log, for example, `LEEF:2.0|Secude|HaloCAD|6.10.0.0|100|`                                                                                           |
| LEEF Header      | EventID                                   | A unique identifier for an event.                                                                                                                                                                                                          |
| LEEF Header      | Delimiter Character                       | Pipe Specifies an alternative delimiter to the attributes. You can use a single character or the hex value for that character. The hex value can be represented by the prefix 0x or x, followed by a series of 1-4 characters (0-9A-Fa-f). |
| Event Attributes | Predefined Key Entries                    | A set of key-value pairs that provide detailed information about the security event. Each event attribute must be separated by a tab or the delimiter character, but the order of attributes is not enforced.                              |

*LEEF Header details*

### **Why JSON Standard?**

The JSON format is a lightweight text-based interchange format used for serializing and transmitting structured data over the network connection. Furthermore, it supports Security Information and Event Management solutions (e.g., Microsoft Azure Sentinel, Splunk, etc.,) seamlessly.

JSON syntax is considered as a subset of JavaScript syntax; it includes the following:

1. Data is represented in name/value pairs.

2. Curly braces hold objects and each name is followed by ':'(colon), the name/value pairs are separated by ','(comma).

3. Square brackets hold arrays and values are separated by ','(comma).

|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| `12:32:13.101 {"log_id":"334957EF6AE34C51881F2FF9ACC7C87F","product":"HaloCAD","source_host":{"shost":"TC11"},"protection":{"policy_id":"d7e95033-e7f1-4218-8941-7d60d8e9cf69","extended_tags":[],"policy_name":"CADSecured","error":false},"destination_info":{"hostname":"SVLU0310","destination_attributes":[{"value":"10.41.14.203","key":"client_ip"},{"value":"SVLU0310","key":"client_host"}],"destination_ip":"10.41.14.203","os":"Unknown","recipients":[],"browser":"FMS-FCC/2406 (bd:20240517)","device_type":"null","browser_version":"null","user_agent":"null"},"classification":{"classification_by_system":[],"classification_by_user":[]},"version":"6.10.1.0","log_time":"Apr 16 2026 07:02:13 UTC","event_id":100,"data_origin":{"generic_info":"null","sap_info":"null","system_name":"TC11","pre_process_info":[],"source_type":"PLM","client_type":"TEAMCENTER","plm_info":[{"value":"NewTestNewTomcat.xlsx","key":"original_file_name"},{"value":"dba_67fe4f61","key":"folder_name"},{"value":"top-secret","key":"ip_classification"},{"value":"dba","key":"user_def_group"}],"bi_info":"null"},"user_info":{"user_email":"HaloENGINE Service","user_type":"DBA;PartnerContractAdmin","user_name":"infodba"},"file_info":{"file_path":"FMS_SHA256_SIGNATURE=0d60b2bef67b10d74626f7cf651d1c47ac8783189fb14d666b1ff978bc278bef37d253fbadc6f8c3da642a813be4a617f946d11ba60e40d32032525465ddaed7;\\dba_67fe4f61\\testne_exc_1xm031cb4ujq6.xlsx","file_name":"NewTestNewTomcat.xlsx","file_type":"xlsx","download_file_size":44544,"original_file_size":7693},"action":["unblocked","labeled","protected"],"export_time":"Apr 16 2026 07:02:12 UTC","event":"user download"}` |

*JSON format*

## Deactivating the HaloCAD for Teamcenter

For any diagnostic testing purposes in connection with HaloCAD, you may need to deactivate HaloCAD for a while. In such cases, follow the procedure below:

1. **Step 1** . Stop **fsc**service.

   Remove the changes done in FMS master file `fmsmaster_FSC_<ComputerName>_Teamcenter.xml`

   **For example,** `<loadbalancer id="ReverseProxy" address="http://tclu0310.Secude.local:8080/tc/fms/" />`
2. **Step 2**. Remove the changes made in the FCC file.

   1. Go to `<installed_path>\Teamcenter12\tccs\bin>`, and execute **CMD** with administrator privilege.

   2. Type `fccstat.exe -stop` and press **Enter**.

   3. Remove the changes on the line in the `fcc.xml` file.

   4. FCC Line format: `<parentfsc address="http://:/tc/fms" priority="0" transport="lan"/> <assignment address="parentfsc address">`

   5. Alternatively, you can use the backup files of these two.

3. **Step 3.** Start **fsc**service.

   1. Type `fccstat.exe -start` and press **Enter**.

   2. Type `fccstat.exe -status` and press **Enter**. You will receive a confirmation message without the Haloproxy port number, which confirms that HaloCAD is not active.

4. **Step 4** . Remove the two **system** **variables** - **Default_Transient_Server** and **Fms_BootStrap_Urls**.

5. **Step 5** . Restart **Server Manager** from `services.msc`.

6. Complete your investigation and then activate it, as described in the section "[TCCS Configuration - Step 2](https://help.secude.com/halocad-for-siemens-teamcenter/2.8/configuring-the-halocad-proxy.md#TCCSStep2)".

## Uninstalling the HaloCAD for Teamcenter

Once you stop using the HaloCAD component, you can uninstall it. Uninstall removes all files and registry settings that were added to your computer at the time of initial installation.

Prerequisite: Make sure to close the configuration tool before performing uninstallation. Otherwise, an error message will appear such as "*Kindly close the running config tool and proceed uninstallation!*"

**Method #1**

1. Click **Start** menu \> go to **Control Panel** \> **Programs** \>**Programs and Features** \> **Uninstall a Program** \>select**HaloCAD for Teamcenter** application from the list \> right-click and select **Uninstall** option or double-click on the installer `HaloCAD_Teamcenter_Setup.exe` file.

2. Depending on your Windows security settings, you may get a security warning as "*Do you want to allow the following program to make changes to this computer* ?". If you get this security warning, click the **Yes** button to confirm that you want to uninstall the HaloCAD component.

3. The following confirmation message appears.

   ![Uninstall Message #1.png](https://help.secude.com/__attachments/a_afcdae6f70e996916f6b66a38cbaae909a4f97e8741ac7c6e01205cc40f7cab2/Uninstall%20Message%20%231.png?cb=bf661cf846256f99efc5d8fabb620988)

   *Uninstall Message #1*
4. Click **Yes** to confirm that you want to remove it from the computer.

   ![Uninstall Message #2.png](https://help.secude.com/__attachments/a_c8b7fdcb4e3d9a33c6dde1234b5f9898a9f9a29b5824f4ff0ecd53d6dab30337/Uninstall%20Message%20%232.png?cb=616f253f7bd4a35212dc2f996675b9d8)

   *Uninstall Message #2*
5. The HaloCAD component has been successfully uninstalled. Click **OK**to close the dialog.

6. The uninstalling process is complete.

**Method #2**

The HaloCAD component can be removed using the command line, as illustrated in the sample below.

1. Open a command prompt.

2. Navigate to the HaloCAD component's directory.

   **Example:** `HaloCAD_Teamcenter_Setup.exe -uninstall`

3. The uninstalling process is complete.

---
version: "2.8"
language: "en"
---
# Installation Manual

## Introduction

Companies across various industries, including automotive, aviation, and high-tech, create and manage their intellectual property (IP) based on drawings. These drawings are created digitally using computer-aided design (CAD) applications and are shared with users outside the organization owing to business considerations. It's essential to understand the potential risks associated with sharing business information. Comprehensive security measures are crucial for mitigating risks and protecting sensitive data. HaloCAD, a purpose-built data protection solution, is designed to help organizations achieve this objective effectively.

### How does HaloCAD for PLM protect your Data?

The HaloCAD for PLM solution integrates seamlessly with the PLM application, including the features of HaloCAD PROTECT and HaloCAD MONITOR, while utilizing Microsoft Purview Information Protection (MPIP), formerly Microsoft Information Protection (MIP), to provide Enterprise Digital Rights Management (EDRM) capabilities.

It provides access to MPIP-protected files, including label handling and privilege enforcement. Any file access actions, such as check-out or export, that may result in a download are intercepted by the HaloCAD for PLM solution, automatically protected based on predefined rules, and then delivered to the end user. Similarly, file access actions such as check-in or upload are intercepted and examined. If a protected file is detected, it is decrypted, and the unprotected file is returned to the PLM vault. For CAD users, the handling of CAD files remains seamless, as these processes occur entirely in the background. By applying MPIP labels, the solution ensures end-to-end security for CAD files, while all upload and download activities are continuously monitored and logged to provide complete traceability.

### About this Manual

This manual provides step-by-step guidance for installing and configuring HaloCAD for Teamcenter.  
**Reference**

Before proceeding with the instructions in this manual, administrators should:

1. Review the Technical Reference Manual to understand HaloCAD's architecture and prerequisites.

2. Refer to the Release Notes to verify the supported CAD applications.

### **Reference Manuals**

The table below describes where to obtain information in the HaloCAD documentation set.  

|                                                                                                                                                                                              **For information on**                                                                                                                                                                                               |                     **Refer to**                     |
|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|------------------------------------------------------|
| Step 1: For details on supported operating systems, file types, and CAD applications, see the Release Notes.                                                                                                                                                                                                                                                                                                      | `HaloCAD_Teamcenter_ReleaseNotes_EN_Online.pdf`      |
| Step 2: Prerequisites 1. Before installing, it is recommended that you fulfill the prerequisites, such as registering an application in Microsoft Entra ID 2. HaloCAD Architecture 3. Registering an Application in Microsoft Entra ID - Web 4. Office 365 Subscription Details 5. Recommended URLs, Addresses, and Ports for MPIP 6. Enable Support for TLS 1.2 at the Client Workstation for Microsoft Entra ID | `HaloCAD_Technical_Reference_Manual_EN_Online.pdf`   |
| Step 3: How to install HaloCAD Add-on for NX                                                                                                                                                                                                                                                                                                                                                                      | `HaloCAD_NX_Manual_Installation_EN_Online.pdf`       |
| Step 4: Install and configure HaloENGINE                                                                                                                                                                                                                                                                                                                                                                          | `HaloENGINE_Manual_Installation_EN_Online.pdf`       |
| Step 5: Install and configure HaloCAD for Teamcenter                                                                                                                                                                                                                                                                                                                                                              | Refer to the current manual.                         |
| Step 6: Workflow illustrating protection and decryption                                                                                                                                                                                                                                                                                                                                                           | `HaloCAD_Teamcenter_Manual_Operations_EN_Online.pdf` |

*HaloCAD reference documentation*

### Component Functions

Supported PLM CAD Integration: HaloCAD for Teamcenter---Siemens NX Integration

The following components are involved in the HaloCAD architecture when deployed in an integrated environment:

1. HaloCAD Add-on for NX

2. HaloCAD for Teamcenter

3. HaloENGINE

4. Microsoft Purview Information Protection

The following list outlines the functions of each component.

1. HaloCAD Add-on for NX - Operates within the Siemens NX application.

2. Receives protected files from Teamcenter and displays their associated labels while enforcing permissions.

3. Logs all add-on--related activities for auditing purposes.

**HaloCAD for Teamcenter performs the following functions:**

1. It resides on the same network as the Siemens Teamcenter PLM server and acts as a proxy for client traffic to the PLM server

2. It is a proxy component that listens for check-in and check-out actions initiated by the user via AWC browser / RAC session /other clients (MS Office or NX).

3. Connects to Microsoft Purview Information Protection to download sensitivity labels for file processing.

4. Collects metadata for the user-selected file.

5. Obtains action and label information for the user-selected file from HaloENGINE for file processing.

6. Performs encryption and forwards the file stream to the CAD client during check-out operations.

7. Performs decryption and stores the unprotected file in the PLM Vault during check-in operations.

8. Logs HaloCAD for Teamcenter component activities to the local log and sends monitor logs to the HaloENGINE.

**Recommendations for improving performance**

**MPIP offline access**

Configure the labels to allow offline access. This must be configured in the Microsoft Purview portal under **Items** \> **Allow offline access** \> **Always** . Choosing this option could have an effect on the revocation process. Therefore, it needs to be taken into account when choosing the offline access option. Please refer to the Microsoft Documentation "[Restrict access to content by using sensitivity labels to apply encryption](https://learn.microsoft.com/en-us/purview/encryption-sensitivity-labels)".

**HaloENGINE performs the following functions:**

1. HaloENGINE is a Java-based server component that exposes a web service to HaloCAD for Teamcenter.

2. Connects to Microsoft Purview Information Protection to download sensitivity labels and make them available for configuration.

3. Implements business logic.

4. Logs events received from HaloCAD for Teamcenter.

**Microsoft Purview Information Protection**

HaloCAD seamlessly integrates with Microsoft Purview Information Protection solution to protect your sensitive documents. Microsoft Purview Information Protection is an industry document security solution that enables businesses to ensure that only authorized users can open the protected content while also regulating what they can do with it, such as print, edit, or save. Even if sensitive data is leaked accidentally or maliciously, unauthorized parties cannot view it in clear text, thus leaving it useless.  
**Microsoft documentation**

This manual assumes that you already have a complete setup of Microsoft Purview Information Protection and you are familiar with using the Microsoft Purview portal and related concepts. If you are new, you can refer to Microsoft's online documentation for setup and configuration.

[Next Page](https://help.secude.com/llms-full.txt/1)
