Enterprise DLP
Enterprise DLP Migrator
Table of Contents
Expand All
|
Collapse All
Enterprise DLP Docs
-
- About Enterprise DLP
- What’s Supported with Enterprise DLP?
- Data Patterns, Document Types, and Data Profiles
- Enable Role Based Access
- Edit the Cloud Content Settings
- Edit the Enterprise DLP Data Filtering Settings
- Edit the Enterprise DLP Snippet Settings
- Configure Syslog Forwarding for Enterprise DLP Incidents
- Request a New Feature
-
-
- Enable Existing Data Patterns and Filtering Profiles
- Modify a DLP Rule on Strata Cloud Manager
- Create a SaaS Security Policy Recommendation to Leverage Enterprise DLP
- Reduce False Positive Detections
- Data Dictionaries
- Recommendations for Security Policy Rules
- Enterprise DLP Migrator
-
-
-
- Driver License - Australia
- Driver License - Austria
- Driver License - Belgium
- Driver License - Brazil
- Driver License - Bulgaria
- Driver License - Canada
- Driver License - China
- Driver License - Croatia
- Driver License - Cyprus
- Driver License - Czech Republic
- Driver License - Denmark
- Driver License - Estonia
- Driver License - Finland
- Driver License - France
- Driver License - Germany
- Driver License - Greece
- Driver License - Hungary
- Driver License - Iceland
- Driver License - Ireland
- Driver License - Italy
- Driver License - Japan
- Driver License - Latvia
- Driver License - Liechtenstein
- Driver License - Lithuania
- Driver License - Luxembourg
- Driver License - Malta
- Driver License - Netherlands
- Driver License - New Zealand
- Driver License - Norway
- Driver License - Poland
- Driver License - Portugal
- Driver License - Romania
- Driver License - Slovakia
- Driver License - Slovenia
- Driver License - South Africa
- Driver License - South Korea
- Driver License - Spain
- Driver License - Sweden
- Driver License - Switzerland
- Driver License - Taiwan
- Driver License - Turkey
- Driver License - UK
- Driver License - US
- Driver License - US - AK
- Driver License - US - AL
- Driver License - US - AR
- Driver License - US - AZ
- Driver License - US - CA
- Driver License - US - CO
- Driver License - US - CT
- Driver License - US - DC
- Driver License - US - DE
- Driver License - US - FL
- Driver License - US - GA
- Driver License - US - HI
- Driver License - US - IA
- Driver License - US - ID
- Driver License - US - IL
- Driver License - US - IN
- Driver License - US - KS
- Driver License - US - KY
- Driver License - US - LA
- Driver License - US - MA
- Driver License - US - ME
- Driver License - US - MI
- Driver License - US - MN
- Driver License - US - MO
- Driver License - US - MS
- Driver License - US - MT
- Driver License - US - NC
- Driver License - US - ND
- Driver License - US - NE
- Driver License - US - NH
- Driver License - US - NM
- Driver License - US - NV
- Driver License - US - NY
- Driver License - US - OH
- Driver License - US - OK
- Driver License - US - OR
- Driver License - US - PA
- Driver License - US - RI
- Driver License - US - SC
- Driver License - US - SD
- Driver License - US - TN
- Driver License - US - TX
- Driver License - US - UT
- Driver License - US - VA
- Driver License - US - VT
- Driver License - US - WA
- Driver License - US - WI
- Driver License - US - WV
- Driver License - US - WY
- National ID - Albania
- National Id - Argentina ID
- National ID - Australia
- National Id - Austria - Central Register of Residents
- National Id - Austria Social Security Card - e-card
- National ID - Bahrain
- National Id - Belgium - Citizen Service Number - BSN
- National Id - Belgium - National Registration Number
- National ID - Bosnia and Herzegovina
- National ID - Brazil
- National Id - Brazil - CNPJ
- National Id - Brazil - CPF
- National Id - Bulgaria - Uniform Civil Number
- National Id - Canada - Social Insurance Number - SIN
- National ID - Chile
- National Id - China ID
- National Id - Colombia National ID
- National ID - Costa Rica
- National Id - Croatia - Personal Identification Number
- National ID - Cuba
- National Id - Cyprus - Identity Card
- National Id - Czech - Birth Number
- National Id - Czech - National eID Card
- National Id - Denmark - CPR Number
- National ID - Dominican Republic
- National ID - Ecuador
- National ID - Egypt
- National Id - Estonia - Personal Identification Code
- National Id - Finland - Personal Identity Code - HETU
- National Id - France - INSEE
- National Id - France - Social Security Number - NIR
- National Id - Germany
- National Id - Greece
- National Id - Hong Kong ID
- National Id - Hungary - Personal Identification Number
- National Id - Iceland
- National ID - India
- National ID - Indonesia
- National ID - Iran
- National Id - Ireland - Personal Public Service Number - PPSN
- National ID - Israel
- National Id - Italy - Fiscal Code Card - Codice Fiscale
- National Id - Japan Corporate Number
- National Id - Japan My Number
- National ID - Kazakhstan
- National ID - Kuwait
- National Id - Latvia - Personal Public Service Number - PPSN
- National Id - Liechtenstein
- National Id - Lithuania
- National Id - Luxembourg
- National Id - Malaysia National ID
- National Id - Malta
- National ID - Mexico
- National ID - Moldova
- National ID - Montenegro
- National Id - Netherlands - Citizen Service Number - BSN
- National ID - North Macedonia
- National Id - Norway - Identification Number - Fødselsnummer
- National ID - Pakistan
- National ID - Paraguay
- National ID - Peru
- National ID - Philippines
- National Id - Poland
- National Id - Portugal
- National Id - Romania - Identity Card - CNP
- National ID - Russia
- National ID - Serbia
- National Id - Singapore NRIC
- National Id - Slovakia
- National Id - Slovenia
- National ID - South Africa
- National ID - South Korea
- National Id - Spain - National Identity Document - Documento Nacional de Identidad
- National ID - Sri Lanka
- National Id - Sweden - Personal Identity Number
- National ID - Switzerland
- National Id - Taiwan ID
- National Id - Thailand ID
- National Id - Turkey Identification Number
- National Id - UAE Emirates ID
- National Id - UK National Insurance Number - NINO
- National ID - Uruguay
- National Id - US Social Security Number - SSN
- National ID - Venezuela
- Passport - Australia
- Passport - Austria
- Passport - Belgium
- Passport - Brazil
- Passport - Bulgaria
- Passport - Canada
- Passport - Croatia
- Passport - Cyprus
- Passport - Czech Republic
- Passport - Denmark
- Passport - Estonia
- Passport - Finland
- Passport - France
- Passport - Germany
- Passport - Greece
- Passport - Hungary
- Passport - Iceland
- Passport - Ireland
- Passport - Italy
- Passport - Latvia
- Passport - Liechtenstein
- Passport - Lithuania
- Passport - Luxembourg
- Passport - Malta
- Passport - Netherlands
- Passport - New Zealand
- Passport - Norway
- Passport Number - China
- Passport Number - Singapore
- Passport Number - South Africa
- Passport number - South Korea
- Passport number - Taiwan
- Passport - Poland
- Passport - Portugal
- Passport - Romania
- Passport - Slovakia
- Passport - Slovenia
- Passport - Spain
- Passport - Sweden
- Passport - Switzerland
- Passport - Turkey
- Passport - UK
- Passport - US
- Tax Id - Australia
- Tax Id - Austria
- Tax Id - Belgium
- Tax Id - Brazil
- Tax Id - Bulgaria
- Tax ID - Canada
- Tax ID - China
- Tax ID - Costa Rica
- Tax Id - Cyprus
- Tax Id - Czech Republic
- Tax Id - Denmark
- Tax ID - Dominican Republic
- Tax Id - Estonia
- Tax Id - Finland
- Tax Id - France
- Tax Id - Germany
- Tax Id - Greece
- Tax Id - Hungary
- Tax Id - Iceland
- Tax Id - India - PAN
- Tax Id - Ireland
- Tax Id - Italy
- Tax ID - Japan
- Tax Id - Latvia
- Tax Id - Liechtenstein
- Tax Id - Lithuania
- Tax Id - Luxembourg
- Tax Id - Malta
- Tax Id - Netherlands
- Tax Id - New Zealand
- Tax Id - Norway
- Tax Id - Poland
- Tax Id - Portugal
- Tax Id - Romania
- Tax Id - Slovakia
- Tax Id - Slovenia
- Tax ID - South Africa
- Tax ID - South Korea
- Tax Id - Spain
- Tax Id - Sweden
- Tax Id - Switzerland
- Tax ID - Taiwan
- Tax Id - Turkey
- Tax Id - UK - UTR
- Tax Id - US - TIN
-
-
-
-
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- April 2024
- March 2024
- January 2024
- December 2023
- November 2023
- October 2023
- August 2023
- July 2023
- June 2023
- May 2023
- March 2023
- February 2023
- January 2023
- November 2022
- October 2022
- August 2022
- July 2022
- June 2022
- May 2022
- April 2022
- March 2022
- February 2022
- January 2022
- December 2021
- November 2021
- October 2021
- September 2021
- July 2021
- New Features in Enterprise DLP Plugin 5.0
- New Features in Enterprise DLP Plugin 4.0
- New Features in Enterprise DLP Plugin 3.0
- New Features in Enterprise DLP Plugin 1.0
-
- Known Issues in the Enterprise DLP Cloud Service
- Known Issues in Endpoint DLP
-
- Known Issues in Enterprise DLP Plugin 3.0.9
- Known Issues in Enterprise DLP Plugin 3.0.8
- Known Issues in Enterprise DLP Plugin 3.0.7
- Known Issues in Enterprise DLP Plugin 3.0.6
- Known Issues in Enterprise DLP Plugin 3.0.5
- Known Issues in Enterprise DLP Plugin 3.0.4
- Known Issues in Enterprise DLP Plugin 3.0.3
- Known Issues in Enterprise DLP Plugin 3.0.2
- Known Issues in Enterprise DLP Plugin 3.0.1
- Known Issues in Enterprise DLP Plugin 3.0.0
-
- Known Issues in Enterprise DLP Plugin 1.0.8
- Known Issues in Enterprise DLP Plugin 1.0.7
- Known Issues in Enterprise DLP Plugin 1.0.6
- Known Issues in Enterprise DLP Plugin 1.0.5
- Known Issues in Enterprise DLP Plugin 1.0.4
- Known Issues in Enterprise DLP Plugin 1.0.3
- Known Issues in Enterprise DLP Plugin 1.0.2
- Known Issues in Enterprise DLP Plugin 1.0.1
- Enterprise DLP Limitations
- Changes to Default Behavior
-
Enterprise DLP Migrator
Migrate your existing data loss prevention policy rules from your old data loss
prevention service provider to Enterprise Data Loss Prevention (E-DLP).
Where Can I Use This? | What Do I Need? |
---|---|
|
Or any of the following licenses that include the Enterprise DLP license
|
Use the Enterprise Data Loss Prevention (E-DLP) Migrator to migrate your Symantec DLP policy rules
and convert them into SaaS Security Data Asset policy rules. This allows
you to quickly transition to Palo Alto Networks Enterprise DLP without the need
to manually recreate all your Data Asset policy rules designed to prevent
exfiltration of sensitive data.
To migrate your existing Symantec DLP policy rules, you simply need to export them
from Symantec DLP and import them into the Enterprise DLP migration tool. The
Enterprise DLP migration tool then evaluates the imported Security policy
rules to verify that they are compatible with Enterprise DLP and SaaS Security. Enterprise DLP creates a data pattern and a classic data profile with names identical to the migrated Symantec DLP
policy rule as part of the migration to capture the traffic match criteria.
If Enterprise DLP detects an incompatible Security policy rule traffic match
criteria, you can choose to delete the incompatible match criteria from the Symantec
DLP policy rule before the migration begins or choose to exclude that specific
Symantec DLP policy from migration. Enterprise DLP adds a successfully migrated
Symantec DLP policy rule as a Disabled
SaaS Security Data Asset policy rule. You can then review the Data Asset
policy rule, make changes if needed, and enable the policy rule.
Enterprise DLP supports migration of Symantec DLP policy rules in
.xml format and with one or more of the following
match criteria:
- Regular expressions—A customized expression that defines a specific text pattern to inspect for and block.
- Keywords—Specific words specified to improve detection accuracy and reduce false positives. Referred to as Proximity Keywords in Palo Alto Networks Enterprise DLP.
- Data Identifiers—The data match criteria added to a Symantec DLP policy rule Referred to as a data pattern in Palo Alto Networks Enterprise DLP.
- Response Action—Enterprise DLP supports one Response Action per Symantec DLP policy rule. Enterprise DLP applies the highest priority Response Action if it detects a Symantec DLP policy rule with more than one Response Action.The priority list of Symantec DLP Response Actions is:
- Quarantine
- Remove Collaboration Action and Remove Collaboration LinkIn SaaS Security, the Change Sharing Action in a Data Asset policy rule allows you to remove collaborators and links using one Data Asset policy rule.
- Notify Owner
- Export your existing Symantec DLP policy rules in .xml format.
- Log in to Strata Cloud Manager.
- Select ManageConfigurationSaaS SecuritySettingsAll SettingsDLP Migration Assistant.
- Upload the Symantec DLP policy rules to the Enterprise DLP Migrator.
- Enter a descriptive Migration Name for the Symantec DLP policy rule migration.
- In the Upload XML Files section, drag and drop the Symantec DLP policy rules files in .xml format.
- Import the XML files you uploaded to the Enterprise DLP Migrator.Enterprise DLP begins to import and analyze your uploaded policy rules to verify compatibility. Continue to the next step once the import status reaches 100%.
- Review your uploaded policy rules.Enterprise DLP lists the number of compatible, partially compatible, and incompatible policy rules from the total number of policy rules uploaded in the previous step.
- Compatible—Policy rule is compatible with Enterprise DLP and is ready for migration. No further review required to prepare the policy rule for migration to Enterprise DLP.
- Partially Compatible—Policy rule contains one or more traffic match criteria that are incompatible with Enterprise DLP. Review and delete the incompatible traffic match conditions before you can migrate the policy rule to Enterprise DLP.
- Incompatible—All traffic match criteria in the policy rule are incompatible with Enterprise DLP. You can't migrate an incompatible Symantec DLP policy rule to Enterprise DLP.
The Notes column displays the specific issue causing the traffic match incompatibility with Enterprise DLP. - Review and address your Partially Compatible policy rules.Skip this step if you want to only migrate Compatible rules and don't want to migrate any Partially Compatible policy rules.You can also select multiple Partially Compatible policy rules to review. If you select multiple policy rules, you must switch between them to address each policy rule individually.Enterprise DLP Migrator does not support turning an Incompatible policy rule into a Compatible policy rule.Below is an example of Partially Compatible Symantec DLP policy rules an admin might need review before migration to Enterprise DLP.
- Select one or more Partially Compatible policy rules you want to review.
- Review Selected.
- Select the Incompatible traffic match criteria and Delete.When prompted, confirm you want to Delete the selected incompatible traffic match criteria.If you selected multiple policy rules, use the navigation arrows in the top-right corner of the Review Policy page and repeat this step until you delete all incompatible traffic match criteria.After you delete all incompatible traffic match criteria from the selected Partially Compatible policy rules, click the X in the top-right corner to continue migration to Enterprise DLP.
- The policy rules now show that they are Compatible and Ready to Migrate.
- Migrate one or more policy rules to Enterprise DLP.
- In the Review Policies page, select one or more policy rules and Migrate to PANW.
- Enterprise DLP displays a verification window detailing the number of Compatible policy rules selected for migration.Additionally, you can specify whether these policy rules are automatically Enabled after successful migration. By default, all migrated policy rules are Disabled.
- Migrate the selected policy rules.
- A progress bar displays the current policy rule migration progress.
- Enterprise DLP displays a summary of the successfully migrated policy rules.Additionally, you can:
- Export PDF—Export a PDF file of the policy rules you migrated to Enterprise DLP. You download the PDF to your local device.
- Migration History—Redirected to the view the history of all previous successful policy rule migrations.
- View Policies—Redirected to view your migrated policy rules in the SaaS Security Data Asset Policies to review and enable.
Click View Policies to continue to the next step. - Review and enable your migrated policy rules.
- After a successful policy rule migration, click View Policies or select ManageConfigurationSaaS SecurityData SecurityPoliciesData Asset Policies.If you manually navigated to the SaaS Security Data Asset Policies, you also need to apply the Status: Disabled filter.
- Click the Policy Name to review the traffic match criteria and verify Enterprise DLP successfully migrated the policy rule.The Data Asset policy rule name is the same as the Symantec DLP policy rule XML file name you uploaded in the previous step. Enterprise DLP automatically populates the following Data Asset policy rule settings:
- Description—Original Symantec DLP policy rule honored during migration and applied to the new Data Asset policy rule to preserve any important information and descriptions about the policy rule.
- Data Profile—Enterprise DLP enables the Data Pattern/Profile match criteria and attaches the Data Profile created during the migration that contains all the traffic match criteria to the Data Asset policy rule.If you want to improve Enterprise DLP detection capabilities and accuracy with advanced detection methods, you must recreate the data profile as an advanced data profile or create a nested data profile. In either case, you must reattach the new data profile to the Data Asset policy rule.
- Action—The SaaS Security equivalent of the Response Action from the Symantec DLP policy rule.
You can edit the migrated Data Asset policy rule Policy Name or make any other changes as needed from this page. Click Save if you made any changes or Cancel if you reviewed the migrated policy rule match criteria and confirmed you don't need to make any changes. - Expand the Action column and Enable the policy rule.
- Apply the Status: Enabled filter and order your policy rule as needed.Refer to the Recommendations for Security Policy Rules for more information on how to order your policy rules in your policy rulebase.
- Repeat this step for all migrated policy rules.