Create an Endpoint DLP Policy Rule
Focus
Focus
Enterprise DLP

Create an Endpoint DLP Policy Rule

Table of Contents

Create an Endpoint DLP Policy Rule

Create an Endpoint DLP policy rule to prevent exfiltration of sensitive data over peripheral devices or to scan for sensitive data stored on endpoints.
On May 7, 2025, Palo Alto Networks is introducing new Evidence Storage and Syslog Forwarding service IP addresses to improve performance and expand availability for these services globally.
You must allow these new service IP addresses on your network to avoid disruptions for these services. Review the Enterprise DLP Release Notes for more information.
Where Can I Use This?What Do I Need?
NGFW (Managed by Strata Cloud Manager)
Prisma Access (Managed by Strata Cloud Manager)
  • Endpoint DLP license
  • Autonomous DEM (6.0.21 or later for End User Coaching)
  • Prisma Access Agent
  • Prisma Access 5.1 (Preferred or Innovation) or later
Enterprise Data Loss Prevention (E-DLP) supports the following types of Endpoint DLP policy rules.
  • Peripheral Control—Policy rule to control exactly who can use peripheral devices. You can block access to multiple user groups while excluding others. Use this rule type when you want to restrict peripheral access by user group, regardless of what data is being transferred.
  • Data in Motion—Policy rule to inspect and block exfiltration of sensitive data moving between an endpoint and a peripheral device. Use this rule type when you want to allow peripheral access but prevent specific sensitive data from leaving the endpoint.
  • Data at Rest—A single policy rule to which you add data profiles to scan managed endpoints for sensitive data stored in local files. The local detection engine on the Prisma Access Agent performs the scan directly on the endpoint using predefined regular expression (regex) data patterns. Use this rule type to discover sensitive data already stored on endpoints and take remediation action.
Peripheral Control and Data in Motion policy rules work together. A common deployment pattern is to create a Peripheral Control policy rule that blocks peripheral access for most users, then create a Data in Motion policy rule that applies to a subset of users excluded from the block — inspecting file transfers for those users for sensitive data instead of restricting access outright. This layered approach gives you broad protection while allowing exceptions for users who need peripheral access.
Endpoint DLP policy rules are evaluated in top-down order. If two policy rules apply to the same users and peripherals, Enterprise DLP takes the Response action based on the first matching policy rule.
After you push your Endpoint DLP policy rules, review your audit and push logs to verify the Prisma Access Agent received the configuration, and monitor your DLP incidents to confirm the rules are enforcing as expected.
Palo Alto Networks recommends reviewing the Policy Rule Example tab before you create your first rules.

Endpoint DLP Policy Rule Example

Example of creating Endpoint DLP policy rules to control access to peripheral devices for some users while allowing access to other users.
  1. Log in to Strata Cloud Manager.
  2. Add a Peripheral to Endpoint DLP and Create a Peripheral Group.
    Adding peripheral devices and creating peripheral groups is required only if you want to allow or block access to specific peripheral devices. You can skip this step if you want to allow or block access to all peripheral devices of any type.
    Repeat this step to add all peripheral devices you want to control access to using Endpoint DLP. In this example, we are allowing access to a specific peripheral group.
  3. Configure the Enterprise DLP match criteria to define custom sensitive data that you want to inspect for and block in your Data in Motion policy rule.
    1. Create custom data patterns to define your match criteria.
      Alternatively, you can use the predefined data patterns instead of creating custom data patterns.
    2. Create a data profile and add your data patterns.
      Alternatively, you can use the predefined data profiles instead of creating custom data profiles.
  4. Select ConfigurationData Loss PreventionEndpoint DLP Policy and Add Policy.
  5. Create a Peripheral Control policy rule.
    In this example, we want to configure a policy rule that restricts endpoint access to all USB peripheral devices for all users, while excluding two users approved to have USB connectivity for their endpoints.
    1. Configure the Basic Information for the Peripheral Control policy rule.
      Make sure that you Enable Policy. Click Next to continue.
    2. For the Scope, select Any Users & Groups.
      This option blocks access to all users regardless of the user group they are associated with. You can exclude one or more users, thereby allowing their endpoint connectivity to USB peripheral devices you specify.
      In the example below, the Peripheral Control policy rule Scope is configured to block access to all users while allowing endpoint connectivity to USB peripheral devices for Alex Smith and Ashok Kachana.
    3. For the Peripherals, select Any to block connectivity to all USB peripheral devices. Alternatively, you can Select specific USB peripheral devices to Include or Exclude.
      • If you Include specific USB peripheral devices then endpoint connectivity to only the specified USB peripheral devices is blocked. All other USB peripheral device connectivity is allowed.
      • If you Exclude specific USB peripheral devices then endpoint connectivity is blocked for all but excluded USB peripheral devices.
      In this example, Any is selected because we want to block endpoint connectivity for all USB peripheral devices. This particular policy rule is specific to USB devices so None is selected for Printers and Network Shares.
      Click Next to continue.
    4. For the Response Action, select Block.
      Click Next to continue.
    5. For the Evaluation Priority, configure the Priority Selection as 1st.
      Palo Alto Networks recommends adding Peripheral Control policy rules designed to block access to peripheral devices at the top of your policy rulebase hierarchy. This ensures that the correct users are blocked and not unintentionally given access.
      Click Next to continue.
    6. Review the Endpoint DLP policy rule Summary and Save.
  6. Create a Data in Motion policy rule.
    In this example, we want to configure a policy rule that uses Enterprise DLP to prevent exfiltration of sensitive data for the users we excluded in the Peripheral Control policy rule.
    1. Configure the Basic Information for the Data in Motion policy rule.
      Make sure that you Enable Policy. Click Next to continue.
    2. For the Classifiers, select the Data Profile you created in the previous step or select a predefined data profile.
      Click Next to continue.
    3. For the Scope, select Select Users.
      This option allows you to select the specific users to which the policy rule applies while excluding all other users.
      In the example below, the Data in Motion policy rule Scope is configured to inspect file movement from the endpoint devices of Alex Smith and Ashok Kachana to the USB peripheral devices you specify in the next step.
      Click Next to continue.
    4. For the Peripherals, Select a USB peripheral groups to Include or Exclude.
      • If you Include specific USB peripheral group then Enterprise DLP inspects and renders verdicts on file movement between the endpoint device and all the specified USB peripheral devices associated with the selected peripheral groups. Enterprise DLP inspection and verdict rendering doesn't occur for file movement for any other USB device.
      • If you Exclude one or more USB peripheral groups then Enterprise DLP inspects and renders verdicts on file movement between the endpoint device and all but the excluded USB peripheral groups.
      In this example, we included the SANDISK group to allow write access to a specific set of USB devices and we want Enterprise DLP inspection and verdict rendering for these USB peripheral devices when connected to Alex and Ashok's endpoints. This particular policy rule is specific to USB devices so None is selected for Printers and Network Shares.
      Click Next to continue.
    5. For the Response Action, select Block.
      This instructs Enterprise DLP to block file movement from the endpoint to the USB peripheral device if sensitive data is detected.
      Click Next to continue.
    6. For the Evaluation Priority, configure the Priority Selection as 2nd.
      Palo Alto Networks recommends adding the Data in Motion policy rules after your Peripheral Control policy rules to ensure the correct users are blocked and not unintentionally given access while forwarding traffic for allowed users to Enterprise DLP.
      Click Next to continue.
    7. Review the Endpoint DLP policy rule Summary and Save.
  7. Review your Endpoint DLP policy rulebase to verify your policy rules are enabled and ordered correctly.
    Review the Priority to ensure your policy rules are ordered correctly, the Users to confirm your policy rules target the correct set of users, and the Peripherals to ensure the policy rules apply to the intended peripheral device types.
  8. Review your Endpoint DLP Audit and Push Logs.
  9. Review your Enterprise DLP Incidents.
    A DLP incident is generated when a user moves a file from the endpoint to the peripheral device but sensitive data is detected and the file move is blocked because sensitive data was detected.

Create an Endpoint DLP Peripheral Control Policy Rule

Create a peripheral control Endpoint DLP policy rule to granularly control who in your organization can use peripheral devices.
  1. Log in to Strata Cloud Manager.
  2. Select ConfigurationData Loss PreventionEndpoint DLP Policy and click Add Policy.
  3. Configure the Basic Information.
    1. For the Policy Type, select Peripheral Control.
    2. Enter a descriptive Name for the Endpoint DLP policy rule.
    3. (Optional) Enter a Description to describe the Endpoint DLP policy rule.
    4. Choose the Severity of the Enterprise DLP incident when a user accesses a blocked peripheral device.
    5. Enable Policy is enabled by default and enables the Endpoint DLP policy rule after you save.
      Disable this setting if you don't want to immediately enable the Endpoint DLP policy rule after creation.
    6. Click Next to continue.
  4. Configure the Scope to define which users and endpoint channels the policy rule applies to.
    For Enterprise DLP to take the configured Response action, both Users and Endpoint Channels must be matched.
    1. Select the Users the policy rule applies to.
      • Any Users & Groups
        Apply the policy rule to all users. You can Exclude one or more users from the policy rule.
      • Select Users
        Apply the policy rule to specific users and groups. You can apply the rule to specific users, user groups, or both.
        Include
        • Select Users—Select one or more specific users the rule applies to.
        • Select Groups—Select one or more user groups the rule applies to.
        Exclude—Select one or more users to exclude from the policy rule. You must select at least one user group before you can exclude users.
    2. Configure the Endpoint Channels you want to allow or block access to.
      Each endpoint channel is independent and can be configured separately. Enable the Include toggle for each channel you want the policy rule to cover. You can configure each channel to apply to any peripheral added to Enterprise DLP or to specific peripheral devices or peripheral groups.
      • USB Removable Media
        Enable Include to apply the policy rule to USB peripheral devices.
        • Any USB (default)—Rule applies to all USB peripherals added to Enterprise DLP.
        • Select USBs
          • Include—Rule applies only to specific USB peripheral groups.
          • Exclude—Rule applies to all USB peripheral devices except for peripheral devices associated with the selected groups.
      • Printers
        Enable Include to apply the policy rule to printer peripheral devices.
        • Any Printer (default)—Rule applies to all printer peripherals added to Enterprise DLP.
        • Select Printers
          • Include—Rule applies only to specific printer peripheral groups.
          • Exclude—Rule applies to all printer peripheral devices except for peripheral devices associated with the selected groups.
      • Network Shares
        Enable Include to apply the policy rule to network share peripheral devices.
        • Any Share (default)—Rule applies to all network share peripherals added to Enterprise DLP.
        • Select Shares
          • Include—Rule applies only to specific network share peripheral groups.
          • Exclude—Rule applies to all network share peripheral devices except for peripheral devices associated with the selected groups.
    3. Click Next to continue.
  5. Configure the Response to define the action Enterprise DLP takes when a user accesses a blocked peripheral.
    • Action—Action Enterprise DLP takes if a User accesses a Peripheral device defined in the policy rule Scope.
      • AlertEnterprise DLP generates a DLP incident but allows the endpoint to access the peripheral.
      • BlockEnterprise DLP generates a DLP incident and blocks the endpoint from accessing the peripheral.
    • Incident Assignee—The administrator the Enterprise DLP incident is assigned to if one is generated against the policy rule.
    • Email Notifications—Add administrators to send email notifications when an incident is generated against the policy rule.
    • Enable End User Notification—Enable end-user notifications to notify users when they have attempted an action that is disallowed by the rule. From the list, select a notification template to associate with the rule.
      The template determines the appearance and message text that is displayed to the user. To define a new notification template to associate with the rule, select + Create a New Template from the list.
    Click Next to continue.
  6. Define the Evaluation Priority for the peripheral control policy rule in your Endpoint DLP policy rulebase.
    You can use the Priority Selection to quickly insert the peripheral control policy rule in the appropriate location in your policy rulebase hierarchy.
    Click Next to continue.
  7. Review the policy rule Summary to verify it's configured correctly and click Save.
  8. Push your Endpoint Policy rule.
    1. Select Endpoint DLP PolicyPush Policies and click Push Policies.
    2. (Optional) Enter a Description for the Endpoint DLP policy push.
    3. Review the Push Policies scope to understand which Endpoint DLP policy rules and peripheral group configuration changes are included in the push.
    4. Click Push.
  9. Review your Endpoint DLP Audit and Push Logs.
  10. Review your Enterprise DLP Incidents.
    A DLP incident is generated when a user accesses a peripheral device that is blocked by the policy rule.

Create an Endpoint DLP Data in Motion Policy Rule

Create a data in motion Endpoint DLP policy rule to inspect and block sensitive data moving between an endpoint and a peripheral device.
Printer peripheral devices only
Enterprise DLP inspects only the first five pages of a document and the first five images included in an inspected file when traffic matches a data in motion policy rule for Printer peripherals.
The total number of data patterns across all your Endpoint DLP policy rules, the size of the inspected file, and the total number of images within the file all impact the time it takes for Enterprise DLP to inspect the file. This is referred to as the Max Latency. Enterprise DLP cannot render a verdict if the inspection time exceeds the max latency.
To control the default action Enterprise DLP takes when the max latency is reached, edit the Action When Max Latency is Reached in the Endpoint DLP Data Transfer settings.
  1. Log in to Strata Cloud Manager.
  2. Configure the Enterprise DLP match criteria to define custom sensitive data that you want to inspect for and block.
    1. Create custom data patterns to define your match criteria.
      Alternatively, you can use the predefined data patterns instead of creating custom data patterns.
    2. Create a data profile and add your data patterns.
      Alternatively, you can use the predefined data profiles instead of creating custom data profiles.
  3. Select ConfigurationData Loss PreventionEndpoint DLP Policy and click Add Policy.
  4. Configure the Basic Information.
    1. For the Policy Type, select Data in Motion.
    2. Enter a descriptive Name for the Endpoint DLP policy rule.
    3. (Optional) Enter a Description to describe the Endpoint DLP policy rule.
    4. Choose the Severity of the Enterprise DLP incident when sensitive data is moved between an endpoint and a peripheral device.
    5. Enable Policy is enabled by default and enables the Endpoint DLP policy rule after you save.
      Disable this setting if you don't want to immediately enable the Endpoint DLP policy rule after creation.
    6. Click Next to continue.
  5. Configure the policy rule Classifiers to define the match criteria.
    1. Select the Data Profile that contains the match criteria you want to inspect for and block. You can select a predefined or custom data profile.
    2. Select the File Types you want the Endpoint DLP policy rule to apply to.
      You can select Any File Types (default) to inspect all supported file types moved between an endpoint and the peripheral device.
  6. Configure the Scope to define which users and endpoint channels the policy rule applies to.
    For Enterprise DLP to take the configured Response action, both Users and Endpoint Channels must be matched.
    1. Select the Users the policy rule applies to.
      • Any Users & Groups
        Apply the policy rule to all users. You can Exclude one or more users from the policy rule.
      • Select Users
        Apply the policy rule to specific users and groups. You can apply the rule to specific users, user groups, or both.
        Include
        • Select Users—Select one or more specific users the rule applies to.
        • Select Groups—Select one or more user groups the rule applies to.
        Exclude—Select one or more users to exclude from the policy rule. You must select at least one user group before you can exclude users.
    2. Configure the Endpoint Channels you want to inspect and block file movement to when sensitive data is detected.
      Each endpoint channel is independent and can be configured separately. Enable the Include toggle for each channel you want the policy rule to cover. You can configure each channel to apply to any peripheral added to Enterprise DLP, or to specific peripheral devices or peripheral groups.
      • USB Removable Media
        Enable Include to apply the policy rule to USB peripheral devices.
        • Any USB (default)—Rule applies to all USB peripherals added to Enterprise DLP.
        • Select USBs
          • Include—Rule applies only to specific USB peripheral groups.
          • Exclude—Rule applies to all USB peripheral devices except for peripheral devices associated with the selected groups.
      • Printers
        Enable Include to apply the policy rule to printer peripheral devices.
        • Any Printer (default)—Rule applies to all printer peripherals added to Enterprise DLP.
        • Select Printers
          • Include—Rule applies only to specific printer peripheral groups.
          • Exclude—Rule applies to all printer peripheral devices except for peripheral devices associated with the selected groups.
      • Network Shares
        Enable Include to apply the policy rule to network share peripheral devices.
        • Any Share (default)—Rule applies to all network share peripherals added to Enterprise DLP.
        • Select Shares
          • Include—Rule applies only to specific network share peripheral groups.
          • Exclude—Rule applies to all network share peripheral devices except for peripheral devices associated with the selected groups.
    3. Click Next to continue.
  7. Configure the Response to define the action Enterprise DLP takes when sensitive data is detected.
    • Action—Action Enterprise DLP takes if a User accesses a Peripheral device defined in the policy rule Scope.
      • AlertEnterprise DLP generates a DLP incident but allows file movement from the endpoint to the peripheral.
      • BlockEnterprise DLP generates a DLP incident and blocks file movement from the endpoint to the peripheral.
    • Incident Assignee—The administrator the Enterprise DLP incident is assigned to if one is generated against the policy rule.
    • Email Notifications—Add additional administrators to send email notifications when an incident is generated against the policy rule.
    • Enable End User Notification—Enable end-user notifications to notify users when they have attempted an action that is disallowed by the rule. From the list, select a notification template to associate with the rule.
      The template determines the appearance and message text that is displayed to the user. If the template has exemption requests enabled, the user will be able to request an exemption directly from the notification. To define a new notification template to associate with the rule, select + Create a New Template from the list.
    Click Next to continue.
  8. Define the Evaluation Priority for the peripheral control policy rule in your Endpoint DLP policy rulebase.
    You can use the Priority Selection to quickly insert the peripheral control policy rule in the appropriate location in your policy rulebase hierarchy.
    Click Next to continue.
  9. Review the policy rule Summary to verify it's configured correctly and click Save.
  10. Push your Endpoint Policy rule.
    1. Select Endpoint DLP PolicyPush Policies and click Push Policies.
    2. (Optional) Enter a Description for the Endpoint DLP policy push.
    3. Review the Push Policies scope to understand which Endpoint DLP policy rules and peripheral group configuration changes are included in the push.
    4. Click Push.
  11. Review your Endpoint DLP Audit and Push Logs.
  12. Review your Enterprise DLP Incidents.
    A DLP incident is generated when a user moves a file from the endpoint to the peripheral device but sensitive data is detected and the file move is blocked because sensitive data was detected.
  13. (Block policy rule for USB and Network Share Peripherals on macOS only) The Prisma Access Agent automatically moves a blocked file to the following local folder on the endpoint for quarantine for 90 days when Endpoint DLP detects and blocks a file containing sensitive data. The Prisma Access Agent automatically deletes the file from the endpoint after 90 days.
    /Library/Application Support/PaloAltoNetworks/DLP/quarantine/
    This applies to all file movement operations available on macOS. Navigate to the local folder on the endpoint and move the file to a different folder on the endpoint to recover the file.

Create an Endpoint DLP Data at Rest Policy Rule

Create a data at rest Endpoint DLP policy rule to scan managed endpoints for sensitive data stored locally.
  1. Log in to Strata Cloud Manager.
  2. (Optional) Create one or more custom data profiles that support Local Detection.
  3. Select ConfigurationData Loss PreventionEndpoint DLP and click Create Scan.
    Enterprise DLP supports only one data at rest policy rule per tenant. To detect multiple types of sensitive data, add multiple data profiles to the single data at rest policy rule.
  4. Add an Endpoint Compatible data profile to the Data at Rest policy rule.
    1. Click Add Local Data Profile to search for and select an Endpoint Compatible data profile.
      Data at rest scanning supports predefined regex data profiles and custom data profiles that support Local Detection only.
    2. Enable Trigger an Incident if you want inspected files on the endpoint that contain sensitive data to generate an incident.
      This setting applies per data profile.
      • EnabledPrisma Access Agent generates a DLP incident when it detects sensitive data when a file that matches a data profile. Scan results also appear in the Data Asset Explorer.
      • Disabled—No DLP incident is generated. Scan results appear in the Data Asset Explorer only.
    3. Choose the Severity for files that match the data at rest policy rule.
      The severity applies to all DLP incidents and assets displayed in the Data Asset Explorer for all files that match this data profile. You can select Critical, High, Medium, Low, or Informational.
    4. Repeat this step to add additional Endpoint Compatible data profiles.
  5. Select the File Types to include or exclude in the scan.
    • Any File Types (default)—Scan all supported file types.
      (Optional) Exclude specific file types from the scan.
    • Select File Types—Scan only the file types you select.
    Data at rest scanning supports files up to 100 MB.
  6. (Optional) Configure the User scope to define which users the data at rest policy rule applies to.
    1. Enable Apply Users match criteria to all enabled data profiles.
    2. Select the Users added using Cloud Identity Engine whose endpoints you want to scan.
      • Any User (default)—Scan endpoints for all users.
        (Optional) Exclude specific users or groups from inspection.
      • Select Users—Scan endpoints only for the users and groups you select.
        (Optional) Exclude specific users or groups from inspection.
  7. Configure the Folder Paths to define which directories on the endpoint the scan targets.
    Enter the folder paths for each operating system separately. You can specify paths for macOS, Windows, or both.
    Click Add Folder Path to include directories in the scan.
    Prisma Access Agent inspects only actual files and directories within the specified paths, not symbolic links (shortcuts that point to files or directories in other locations).
    Some examples of commonly configured folder paths include:
    macOSWindows
    /Users/*/DesktopC:\Users\*\Desktop
    /Users/*/DocumentsC:\Users\*\Documents
    /Users/*/DownloadsC:\Users\*\Downloads
    /Users/*/Library/CloudStorage/GoogleDrive-*C:\Users\*\AppData\Local\Google\Drive
    /Users/*/Library/CloudStorage/OneDrive-*C:\Users\*\OneDrive - Company Name
  8. Click Next to continue.
  9. Review the policy rule Summary to verify the configuration is correct and click Save.
  10. Push your Endpoint DLP policy rule.
    1. Select Push Policies and click Push Policies.
    2. (Optional) Enter a Description for the Endpoint DLP policy push.
    3. Review the Push Policies scope to understand which Endpoint DLP policy rules and configuration changes are included in the push.
    4. Click Push.
  11. Review your Endpoint DLP Audit and Push Logs.
  12. Review the Data Asset Explorer or your DLP incidents.
    The Data Asset Explorer displays assets that match your data at rest policy rule regardless of whether a DLP incident was generated.
    Prisma Access Agent generates a DLP incident when the data at rest scan detects sensitive data on an endpoint that matches the configured data profiles and you enabled Trigger an Incident for the matched data profile.