Manage Shadow Data Discovery Groups
Focus
Focus
Enterprise DLP

Manage Shadow Data Discovery Groups

Table of Contents

Manage Shadow Data Discovery Groups

Customize how Enterprise Data Loss Prevention (E-DLP) organizes shadow data by managing groups and category assignments.
Where Can I Use This?What Do I Need?
Strata Cloud Manager
  • Data Security license
  • Enterprise DLP license
Or any of the following licenses that include the Enterprise DLP and Data Security licenses
  • Prisma Access CASB license
  • Next-Generation CASB for Prisma Access and NGFW (CASB-X) license
  • Data Security license
Contact Palo Alto Networks to enable Shadow Data Discovery on your tenant.
After Enterprise Data Loss Prevention (E-DLP) scans your shadow data, it uses AI to automatically map discovered categories to predefined groups. These initial mappings are AI-generated recommendations that you review and adjust if they don't accurately reflect your organization's data. Because the Shadow Data Discovery dashboard displays your shadow data organized by groups at the top level, the group structure you configure directly shapes what you see and how you interpret your data landscape before you take remediation action.
Enterprise DLP organizes discovered documents into two levels of classification:
  • Categories are AI-generated groupings of similar documents based on their content and context. Each category represents a cluster of related documents that Enterprise DLP identified during scanning, such as Cybersecurity and Digital Secret Management or IP Address Management. A category can belong to more than one group.
  • Groups are broader classifications that categories map to, designed to align with common data types and organizational structures, such as Source Code or Personal Financial Data. Groups are what you see at the top level of the Shadow Data Discovery dashboard, with categories nested within them.
Enterprise DLP provides predefined groups that it maps categories to automatically, and you can create custom groups to reflect how your organization structures its data.
After you change a group mapping, the Shadow Data Discovery dashboard takes up to 10 minutes to reflect the updated groupings.
  1. Log in to Strata Cloud Manager.
  2. Select ConfigurationData Loss PreventionShadow Data Discovery and click Group Management.
  3. Manage your shadow data organization using the Group View or Category View.

Group View

Group View lets you browse your predefined and custom groups and see which categories each group contains. Use Group View to create custom groups, assign categories to a group, and move or remove categories.
  1. Select Group View.
  2. Select a predefined group or create a new group from the left-hand panel.
    • Predefined Groups
      Select a predefined group from the left panel to view the categories currently assigned to it. Enterprise DLP provides the following predefined groups:
      • Audit & Risk
      • Corporate Credentials, Secrets & Keys
      • Customer Support
      • Finance
      • HR – Employee Records
      • IT Governance & Risk
      • Legal & Contracts
      • M&A and Corporate Strategy
      • Marketing and Sales Collateral
      • Operations
      • Personal Financial Data
      • PHI – Clinical Terms & Diagnoses
      • PHI – Health Insurance & Regulatory IDs
      • PHI – Pharmaceuticals
      • PII – Personally Identifiable Information
      • Public-facing Corporate Documents
      • R&D / Engineering Designs, Intellectual Property & Trade Secrets
      • Source Code
      • Uncategorized
      You can't rename or delete predefined groups, but you can add or remove categories from them to refine how your shadow data is classified. The Uncategorized group is a catch-all for categories that don't confidently map to any other predefined group. You can move categories out of Uncategorized into other groups, but you can't delete or rename the Uncategorized group itself.
    • Create a New Group
      1. Click + New group.
      2. In the Add Group dialog, enter a Group Name and an optional Description. The description is for your reference only and isn't used for policy. Select at least one category to assign to the group and click Add Group.
  3. Assign one or more categories to your group.
    You can manage categories in a group using the following operations:
    • Assign categories: Add one or more categories to the selected group.
    • Move to: Reassign a category to a different group, removing it from the current group.
    • Clone to: Copy a category to another group while keeping it in the current group. Use this when a category applies to multiple groups.
    • Remove: Remove a category from the group. If the category doesn't belong to any other group, Enterprise DLP places it in Uncategorized.
    1. Select a predefined or custom group and click Assign categories.
    2. Select the categories you want to assign to the group and click Assign.

Category View

Category View lets you browse all categories and see which groups each category belongs to. Use Category View to add or remove group assignments for individual categories from a single location.
  1. Select Category View to manage group assignments for individual categories.
  2. To add a category to a group, click + next to the category and choose a group from the drop-down.
  3. To remove a category from a group, click × on the group name next to the category.
  4. Save the new category to group mapping.