Start a Shadow Data Discovery Scan
Focus
Focus
Enterprise DLP

Start a Shadow Data Discovery Scan

Table of Contents

Start a Shadow Data Discovery Scan

Start a Shadow Data Discovery scan so Enterprise Data Loss Prevention (E-DLP) can detect and categorize shadow data in your environment.
Where Can I Use This?What Do I Need?
Strata Cloud Manager
  • Data Security license
  • Enterprise DLP license
Or any of the following licenses that include the Enterprise DLP and Data Security licenses
  • Prisma Access CASB license
  • Next-Generation CASB for Prisma Access and NGFW (CASB-X) license
  • Data Security license
Contact Palo Alto Networks to enable Shadow Data Discovery on your tenant.
The Shadow Data Discovery process enables Enterprise Data Loss Prevention (E-DLP) to analyze documents at rest in apps you onboarded to Data Security. Enterprise DLP uses machine learning to discover and categorize documents into groups based on their content and context. After analysis completes, Enterprise DLP gives you visibility into your shadow data landscape through an interactive dashboard that displays your data organized by groups at the top level, with categories nested within each group.
Shadow Data Discovery reruns every time Data Security rescans onboarded apps, enabling Enterprise DLP to continuously learn and categorize new documents as they enter your environment. This gives you continuous visibility to help maintain comprehensive protection for sensitive information that traditional pattern-matching approaches might miss, and helps you understand how your organization naturally stores and organizes its documents and what protection gaps might exist.
  1. Log in to Strata Cloud Manager.
  2. Onboard sanctioned SaaS apps to Data Security (SaaS API).
  3. Select ConfigurationData Loss PreventionShadow Data Discovery and click Start Shadow Data Discovery.
  4. Enter the minimum files required to start the data discovery process.
    The value entered here specifies the minimum file volume required for Enterprise DLP to begin categorizing the files detected in supported SaaS apps onboarded to Data Security.
    Enterprise DLP supports up to 50,000 files.
  5. Review the security Channels that Enterprise DLP inspects.
    Enterprise DLP supports shadow data file categorization for the following channels:
  6. Click Start Scan and wait for Enterprise DLP to complete inspection and file categorization for the selected channels.
  7. Review the shadow file summary and analysis by Enterprise DLP.
    Enterprise DLP displays the following summary for the categorized files across all channels.
    • Total number of groups detected.
      Enterprise DLP categorizes all discovered shadow data in English, even if the source files are in other languages.
    • Total number of channels selected.
    • Total number of data profiles that matched.
    • Total number of apps.
    Click View Shadow Data to see a bubble graph and detailed breakdown of the shadow data groups detected by Enterprise DLP.
  8. View Shadow Data to analyze the shadow data discovered by Enterprise DLP.
  9. (Optional) Edit the Shadow Data Discovery settings to modify the channels Enterprise DLP inspects when Data Security rescans your onboarded apps.
  10. Analyze the discovered shadow data to understand what types of sensitive data exist in your organization.
    The Shadow Data Discovery dashboard displays your shadow data organized by groups, with categories nested within each group. Reviewing the groups, sensitivity levels, and file distributions helps you understand your data landscape and identify gaps in your existing data protection policies before you take remediation action.
  11. Manage shadow data discovery groups to customize how Enterprise DLP organizes your shadow data.
    By default, Enterprise DLP maps discovered categories to predefined groups based on content analysis. You can reassign categories to different groups, create custom groups that reflect how your organization structures its data, and remove categories from groups that aren't relevant to your environment. Refining your group mappings gives you a more accurate view of your shadow data landscape before you take remediation action.
  12. Remediate discovered shadow data to prevent exfiltration of sensitive data on subsequent scans.
    Remediation creates a custom document type from the discovered shadow data files, which you can add to a data profile and apply to a data asset policy. This converts your shadow data discoveries into active data protection so that Enterprise DLP detects and acts on sensitive documents in all future scans.