Create an Endpoint DLP policy rule to prevent exfiltration of sensitive data over
peripheral devices or to scan for sensitive data stored on endpoints.
On
May 7, 2025,
Palo Alto Networks is introducing new
Evidence Storage and
Syslog Forwarding service IP
addresses to improve performance and expand availability for these services
globally.
| Where Can I Use This? | What Do I Need? |
|
NGFW (Managed by Strata Cloud Manager)
Prisma Access (Managed by Strata Cloud Manager)
|
Endpoint DLP license - Autonomous DEM (6.0.21 or later for End User Coaching)
- Prisma Access Agent
- Prisma Access 5.1 (Preferred or Innovation) or later
|
Enterprise Data Loss Prevention (E-DLP) supports the following types of Endpoint DLP
policy rules.
Peripheral Control—Policy rule to control exactly who can use
peripheral devices. You can block access to multiple user groups while
excluding others. Use this rule type when you want to restrict peripheral access
by user group, regardless of what data is being transferred.
Data in Motion—Policy rule to inspect and block exfiltration of
sensitive data moving between an endpoint and a peripheral device. Use this
rule type when you want to allow peripheral access but prevent specific
sensitive data from leaving the endpoint.
Data at Rest—A single policy rule to which you add data profiles to
scan managed endpoints for sensitive data stored in local files. The local
detection engine on the Prisma Access Agent performs the scan
directly on the endpoint using predefined regular expression (regex) data
patterns. Use this rule type to discover sensitive data already stored on
endpoints and take remediation action.
Peripheral Control and Data in Motion policy rules work together. A common deployment
pattern is to create a Peripheral Control policy rule that blocks peripheral access
for most users, then create a Data in Motion policy rule that applies to a subset
of users excluded from the block — inspecting file transfers for those users for
sensitive data instead of restricting access outright. This layered approach gives
you broad protection while allowing exceptions for users who need peripheral
access.
Endpoint DLP policy rules are evaluated in top-down order. If two policy rules apply
to the same users and peripherals, Enterprise DLP takes the
Response action based on the first matching policy
rule.
After you push your Endpoint DLP policy rules, review your
audit and push logs to verify the
Prisma Access Agent
received the configuration, and monitor your
DLP
incidents to confirm the rules are enforcing as expected.
Palo Alto Networks recommends reviewing the Policy Rule Example tab before you
create your first rules.
Endpoint DLP Policy Rule Example
Example of creating Endpoint DLP policy rules to control access to peripheral devices
for some users while allowing access to other users.
Log in to
Strata Cloud Manager.
Add a Peripheral to
Endpoint DLP and
Create a Peripheral Group.
Adding peripheral devices and creating peripheral groups is required only if
you want to allow or block access to specific peripheral devices. You can
skip this step if you want to allow or block access to all peripheral
devices of any type.
Repeat this step to add all peripheral devices you want to control access to
using Endpoint DLP. In this example, we are allowing access to a specific
peripheral group.
Configure the
Enterprise DLP match criteria to define custom sensitive
data that you want to inspect for and block in your Data in Motion policy
rule.
Create
custom data
patterns to define your match criteria.
Create a data profile and add
your data patterns.
Select and
Add Policy.
Create a
Peripheral Control policy rule.
In this example, we want to configure a policy rule that restricts endpoint
access to all USB peripheral devices for all users, while excluding two
users approved to have USB connectivity for their endpoints.
Configure the
Basic Information for the
Peripheral Control policy rule.
Make sure that you Enable Policy. Click
Next to continue.
For the Scope, select
Any Users &
Groups.
This option blocks access to all users regardless of the user group
they are associated with. You can exclude one or more users, thereby
allowing their endpoint connectivity to USB peripheral devices you
specify.
In the example below, the Peripheral Control policy rule
Scope is configured to block access to
all users while allowing endpoint connectivity to USB peripheral
devices for Alex Smith and
Ashok Kachana.
For the
Peripherals, select
Any to block connectivity to all USB
peripheral devices. Alternatively, you can
Select
specific USB peripheral devices to
Include or
Exclude.
If you Include specific USB peripheral
devices then endpoint connectivity to only the specified USB
peripheral devices is blocked. All other USB peripheral
device connectivity is allowed.
If you Exclude specific USB peripheral
devices then endpoint connectivity is blocked for all but
excluded USB peripheral devices.
In this example, Any is selected because we
want to block endpoint connectivity for all USB peripheral devices.
This particular policy rule is specific to USB devices so
None is selected for Printers and Network
Shares.
Click Next to continue.
For the Response
Action, select
Block.
For the Evaluation Priority, configure the
Priority
Selection as
1st.
Palo Alto Networks recommends adding Peripheral Control policy rules
designed to block access to peripheral devices at the top of your
policy rulebase hierarchy. This ensures that the correct users are
blocked and not unintentionally given access.
Click Next to continue.
Review the Endpoint DLP policy rule Summary and
Save.
Create a
Data in Motion policy rule.
In this example, we want to configure a policy rule that uses Enterprise DLP to prevent exfiltration of sensitive data for the users
we excluded in the Peripheral Control policy rule.
Configure the Basic Information for the Data in Motion policy
rule.
Make sure that you Enable Policy. Click
Next to continue.
For the Classifiers, select the
Data Profile you
created in the previous step or select a predefined data profile.
For the Scope, select
Select Users.
This option allows you to select the specific users to which the
policy rule applies while excluding all other users.
In the example below, the Data in Motion policy rule Scope is
configured to inspect file movement from the endpoint devices of
Alex Smith and Ashok
Kachana to the USB peripheral devices you specify
in the next step.
Click Next to continue.
For the
Peripherals,
Select a USB peripheral groups to
Include or
Exclude.
If you Include specific USB peripheral
group then Enterprise DLP inspects and renders verdicts
on file movement between the endpoint device and all the
specified USB peripheral devices associated with the
selected peripheral groups. Enterprise DLP inspection
and verdict rendering doesn't occur for file movement for
any other USB device.
If you Exclude one or more USB
peripheral groups then Enterprise DLP inspects and
renders verdicts on file movement between the endpoint
device and all but the excluded USB peripheral groups.
In this example, we included the SANDISK
group to allow write access to a specific set of
USB devices and we want Enterprise DLP inspection and verdict
rendering for these USB peripheral devices when connected to Alex
and Ashok's endpoints. This particular policy rule is specific to
USB devices so None is selected for Printers
and Network Shares.
Click Next to continue.
For the Response
Action, select
Block.
This instructs Enterprise DLP to block file movement from the
endpoint to the USB peripheral device if sensitive data is
detected.
Click Next to continue.
For the Evaluation Priority, configure the
Priority
Selection as
2nd.
Palo Alto Networks recommends adding the Data in Motion policy rules
after your Peripheral Control policy rules to ensure the correct
users are blocked and not unintentionally given access while
forwarding traffic for allowed users to Enterprise DLP.
Click Next to continue.
Review the Endpoint DLP policy rule Summary and
Save.
Review your Endpoint DLP policy rulebase to verify your policy rules are
enabled and ordered correctly.
Review the Priority to ensure your policy rules are
ordered correctly, the Users to confirm your policy
rules target the correct set of users, and the
Peripherals to ensure the policy rules apply to
the intended peripheral device types.
Review your Endpoint DLP
Audit and Push Logs.
Review your Enterprise
DLP Incidents.
A DLP incident is generated when a user moves a file from the endpoint to the
peripheral device but sensitive data is detected and the file move is
blocked because sensitive data was detected.
Create an Endpoint DLP Peripheral Control Policy Rule
Create a peripheral control Endpoint DLP policy rule to granularly control who in
your organization can use peripheral devices.
Log in to
Strata Cloud Manager.
Select and click
Add Policy.
Configure the
Basic Information.
For the
Policy Type, select
Peripheral Control.
Enter a descriptive
Name for the Endpoint DLP
policy rule.
(
Optional) Enter a
Description to
describe the Endpoint DLP policy rule.
Choose the
Severity of the
Enterprise DLP
incident when a user accesses a blocked peripheral device.
Enable Policy is enabled by default and enables
the Endpoint DLP policy rule after you save.
Disable this setting if you don't want to immediately enable the
Endpoint DLP policy rule after creation.
Click
Next to continue.
Configure the
Scope to define which users and endpoint
channels the policy rule applies to.
For Enterprise DLP to take the configured
Response action, both
Users and Endpoint
Channels must be matched.
Select the
Users the policy rule applies
to.
Any Users & Groups
Apply the policy rule to all users. You can
Exclude one or more users from
the policy rule.
Select Users
Apply the policy rule to specific
users and groups.
You can apply the rule to specific users, user groups, or
both.
Include
Exclude—Select one or more users to
exclude from the policy rule. You must select at least one
user group before you can exclude users.
Configure the
Endpoint Channels you want to
allow or block access to.
Each endpoint channel is independent and can be configured
separately. Enable the
Include toggle for
each channel you want the policy rule to cover. You can configure
each channel to apply to any
peripheral added
to
Enterprise DLP or to specific peripheral devices or
peripheral groups.
USB Removable Media
Enable Include to apply the policy
rule to USB peripheral devices.
- Any USB (default)—Rule applies to
all USB peripherals added to Enterprise DLP.
Select USBs
- Include—Rule applies only
to specific USB peripheral groups.
- Exclude—Rule applies to
all USB peripheral devices except for peripheral
devices associated with the selected groups.
Printers
Enable Include to apply the policy
rule to printer peripheral devices.
- Any Printer (default)—Rule
applies to all printer peripherals added to Enterprise DLP.
Select Printers
- Include—Rule applies
only to specific printer peripheral groups.
- Exclude—Rule applies to
all printer peripheral devices except for
peripheral devices associated with the selected
groups.
Network Shares
Enable Include to apply the policy
rule to network share peripheral devices.
- Any Share (default)—Rule applies
to all network share peripherals added to Enterprise DLP.
Select Shares
- Include—Rule applies
only to specific network share peripheral
groups.
- Exclude—Rule applies to
all network share peripheral devices except for
peripheral devices associated with the selected
groups.
Click
Next to continue.
Configure the
Response to define the action
Enterprise DLP takes when a user accesses a blocked peripheral.
Action—Action Enterprise DLP takes if a
User accesses a
Peripheral device defined in the policy
rule Scope.
Alert—
Enterprise DLP generates a
DLP
incident but allows
the endpoint to access the peripheral.
Block—
Enterprise DLP generates a
DLP
incident and blocks
the endpoint from accessing the peripheral.
Incident Assignee—The administrator the
Enterprise DLP
incident is assigned to if one is generated
against the policy rule.
Email Notifications—Add administrators to send
email notifications when an incident is generated against the policy
rule.
Enable End User Notification—Enable end-user
notifications to notify users when they have attempted an action
that is disallowed by the rule. From the list, select a notification
template to associate with the rule.
The template determines the appearance and message text that is
displayed to the user. To
define a new
notification template to associate with the rule, select
+ Create a New Template from the
list.
Click Next to continue.
Define the
Evaluation Priority for the peripheral
control policy rule in your Endpoint DLP policy rulebase.
You can use the Priority Selection to quickly insert
the peripheral control policy rule in the appropriate location in your
policy rulebase hierarchy.
Click Next to continue.
Review the policy rule
Summary to verify it's configured
correctly and click
Save.
Push your Endpoint Policy rule.
Select and click
Push Policies.
(
Optional) Enter a
Description for the
Endpoint DLP policy push.
Review the Push Policies scope to understand which Endpoint DLP policy
rules and peripheral group configuration changes are included in the
push.
Click
Push.
Review your Endpoint DLP
Audit and Push Logs.
Review your Enterprise
DLP Incidents.
A DLP incident is generated when a user accesses a peripheral device that is
blocked by the policy rule.
Create an Endpoint DLP Data in Motion Policy Rule
Create a data in motion Endpoint DLP policy rule to inspect and block sensitive data
moving between an endpoint and a peripheral device.
Printer peripheral devices only
Enterprise DLP inspects only the first five pages of a document and the
first five images included in an inspected file when traffic matches a data in
motion policy rule for Printer peripherals.
The total number of data patterns across all your Endpoint DLP policy rules, the
size of the inspected file, and the total number of images within the file all
impact the time it takes for Enterprise DLP to inspect the file. This is
referred to as the Max Latency. Enterprise DLP
cannot render a verdict if the inspection time exceeds the max latency.
To control the default action
Enterprise DLP takes when the max latency is
reached, edit the
Action When Max Latency is Reached in
the
Endpoint DLP Data Transfer
settings.
Log in to
Strata Cloud Manager.
Configure the
Enterprise DLP match criteria to define custom sensitive
data that you want to inspect for and block.
Create
custom data
patterns to define your match criteria.
Create a data profile and add
your data patterns.
Select and click
Add Policy.
Configure the
Basic Information.
For the
Policy Type, select
Data in
Motion.
Enter a descriptive
Name for the Endpoint DLP
policy rule.
(
Optional) Enter a
Description to
describe the Endpoint DLP policy rule.
Choose the
Severity of the
Enterprise DLP
incident when sensitive data is moved between an endpoint and a
peripheral device.
Enable Policy is enabled by default and enables
the Endpoint DLP policy rule after you save.
Disable this setting if you don't want to immediately enable the
Endpoint DLP policy rule after creation.
Click
Next to continue.
Configure the policy rule
Classifiers to define the
match criteria.
Select the
Data Profile that contains the match
criteria you want to inspect for and block. You can select a
predefined or
custom data profile.
Select the
File Types you want the Endpoint DLP
policy rule to apply to.
You can select
Any File Types (default) to
inspect all
supported file types moved
between an endpoint and the peripheral device.
Configure the
Scope to define which users and endpoint
channels the policy rule applies to.
For Enterprise DLP to take the configured
Response action, both
Users and Endpoint
Channels must be matched.
Select the
Users the policy rule applies
to.
Any Users & Groups
Apply the policy rule to all users. You can
Exclude one or more users from
the policy rule.
Select Users
Apply the policy rule to specific
users and groups.
You can apply the rule to specific users, user groups, or
both.
Include
Exclude—Select one or more users to
exclude from the policy rule. You must select at least one
user group before you can exclude users.
Configure the
Endpoint Channels you want to
inspect and block file movement to when sensitive data is
detected.
Each endpoint channel is independent and can be configured
separately. Enable the
Include toggle for
each channel you want the policy rule to cover. You can configure
each channel to apply to any
peripheral added
to
Enterprise DLP, or to specific peripheral devices or
peripheral groups.
USB Removable Media
Enable Include to apply the policy
rule to USB peripheral devices.
- Any USB (default)—Rule applies
to all USB peripherals added to Enterprise DLP.
Select USBs
- Include—Rule applies
only to specific USB peripheral groups.
- Exclude—Rule applies to
all USB peripheral devices except for peripheral
devices associated with the selected groups.
Printers
Enable Include to apply the policy
rule to printer peripheral devices.
- Any Printer (default)—Rule
applies to all printer peripherals added to Enterprise DLP.
Select Printers
- Include—Rule applies
only to specific printer peripheral groups.
- Exclude—Rule applies to
all printer peripheral devices except for
peripheral devices associated with the selected
groups.
Network Shares
Enable Include to apply the policy
rule to network share peripheral devices.
- Any Share (default)—Rule applies
to all network share peripherals added to Enterprise DLP.
Select Shares
- Include—Rule applies
only to specific network share peripheral
groups.
- Exclude—Rule applies to
all network share peripheral devices except for
peripheral devices associated with the selected
groups.
Click
Next to continue.
Configure the
Response to define the action
Enterprise DLP takes when sensitive data is detected.
Action—Action Enterprise DLP takes if a
User accesses a
Peripheral device defined in the policy
rule Scope.
Alert—
Enterprise DLP generates a
DLP
incident but allows
file movement from the endpoint to the peripheral.
Block—
Enterprise DLP generates a
DLP
incident and blocks
file movement from the endpoint to the peripheral.
Incident Assignee—The administrator the
Enterprise DLP
incident is assigned to if one is generated
against the policy rule.
Email Notifications—Add additional
administrators to send email notifications when an incident is
generated against the policy rule.
Enable End User Notification—Enable end-user
notifications to notify users when they have attempted an action
that is disallowed by the rule. From the list, select a notification
template to associate with the rule.
The template determines the appearance and message text that is
displayed to the user. If the template has exemption requests
enabled, the user will be able to request an exemption directly from
the notification. To
define a new notification
template to associate with the rule, select
+
Create a New Template from the list.
Click Next to continue.
Define the
Evaluation Priority for the peripheral
control policy rule in your Endpoint DLP policy rulebase.
You can use the Priority Selection to quickly insert
the peripheral control policy rule in the appropriate location in your
policy rulebase hierarchy.
Click Next to continue.
Review the policy rule
Summary to verify it's configured
correctly and click
Save.
Push your Endpoint Policy rule.
Select and click
Push Policies.
(
Optional) Enter a
Description for the
Endpoint DLP policy push.
Review the Push Policies scope to understand which Endpoint DLP policy
rules and peripheral group configuration changes are included in the
push.
Click
Push.
Review your Endpoint DLP
Audit and Push Logs.
Review your Enterprise
DLP Incidents.
A DLP incident is generated when a user moves a file from the endpoint to the
peripheral device but sensitive data is detected and the file move is
blocked because sensitive data was detected.
(
Block policy rule for USB and Network Share Peripherals on macOS
only) The
Prisma Access Agent automatically moves a blocked file to
the following local folder on the endpoint for quarantine for 90 days when
Endpoint DLP detects and blocks a file containing sensitive data. The
Prisma Access Agent automatically deletes the file from the endpoint after
90 days.
/Library/Application
Support/PaloAltoNetworks/DLP/quarantine/
This applies to all file movement operations available on macOS. Navigate to
the local folder on the endpoint and move the file to a different folder on
the endpoint to recover the file.
Create an Endpoint DLP Data at Rest Policy Rule
Create a data at rest Endpoint DLP policy rule to scan managed endpoints for
sensitive data stored locally.
Log in to
Strata Cloud Manager.
(
Optional) Create one or more
custom data profiles that support Local
Detection.
Select and click
Create Scan.
Enterprise DLP supports only one data at rest policy rule per
tenant. To detect multiple types of sensitive data, add multiple data
profiles to the single data at rest policy rule.
Add an
Endpoint Compatible data profile to the Data at
Rest policy rule.
Click
Add Local Data Profile to search for and select
an
Endpoint Compatible data profile.
Enable
Trigger an Incident if you want inspected
files on the endpoint that contain sensitive data to generate an
incident.
This setting applies per data profile.
Enabled—
Prisma Access Agent generates a
DLP
incident when it detects sensitive data when a
file that matches a data profile. Scan results also appear
in the
Data Asset
Explorer.
Choose the
Severity for files that match the
data at rest policy rule.
The severity applies to all DLP incidents and assets displayed in the
Data Asset Explorer for all files that match this data profile. You
can select Critical, High, Medium, Low, or Informational.
Repeat this step to add additional
Endpoint
Compatible data profiles.
Select the
File Types to include or exclude in the
scan.
Data at rest scanning supports files up to 100 MB.
(
Optional) Configure the
User scope to define
which users the data at rest policy rule applies to.
Enable
Apply Users match criteria to all enabled data
profiles.
Select the
Users
added using
Cloud Identity Engine
whose endpoints you want to scan.
Any User (default)—Scan endpoints for
all users.
(Optional) Exclude specific
users or groups from inspection.
Select Users—Scan endpoints only for
the users and groups you select.
(Optional) Exclude specific
users or groups from inspection.
Configure the
Folder Paths to define which directories
on the endpoint the scan targets.
Enter the folder paths for each operating system separately. You can specify
paths for macOS, Windows, or both.
Click Add Folder Path to include directories in the scan.
Prisma Access Agent inspects only actual files and directories within
the specified paths, not symbolic links (shortcuts that point to files or
directories in other locations).
Some examples of commonly configured folder paths include:
| macOS | Windows |
| /Users/*/Desktop | C:\Users\*\Desktop |
| /Users/*/Documents | C:\Users\*\Documents |
| /Users/*/Downloads | C:\Users\*\Downloads |
| /Users/*/Library/CloudStorage/GoogleDrive-* | C:\Users\*\AppData\Local\Google\Drive |
| /Users/*/Library/CloudStorage/OneDrive-* | C:\Users\*\OneDrive - Company Name |
Click
Next to continue.
Review the policy rule
Summary to verify the
configuration is correct and click
Save.
Push your Endpoint DLP policy rule.
Select
Push Policies and click
Push Policies.
(
Optional) Enter a
Description for the
Endpoint DLP policy push.
Review the Push Policies scope to understand which Endpoint DLP policy
rules and configuration changes are included in the push.
Click
Push.
Review your Endpoint DLP
Audit and Push
Logs.
Review the
Data Asset Explorer or your
DLP incidents.
The Data Asset Explorer displays assets that match your data at rest policy
rule regardless of whether a DLP incident was generated.
Prisma Access Agent generates a DLP incident when the data at rest scan
detects sensitive data on an endpoint that matches the configured data
profiles and you enabled Trigger an Incident for the
matched data profile.