Enterprise Data Loss Prevention Features
Focus
Focus
Next-Generation Firewall

Enterprise Data Loss Prevention Features

Table of Contents

Enterprise Data Loss Prevention Features

New Enterprise DLP features for 12.1.

Granular Data Profiles

August 2025
  • Introduced in PAN-OS 12.1.2
Prisma Access support added in the Prisma Access 6.1.0 release.
Granular data profiles enhance your Enterprise Data Loss Prevention (E-DLP) detection capabilities by allowing you to apply differentiated inline content inspection requirements and response actions within the same Security policy rule. For example, you can use a single granular data profile to block high-risk data patterns while alerting on lower-risk ones, set varying log severities for different data profiles, and set specific file types for each data profile included in the granular data profile.
Granular data profiles simplify policy rulebase management by consolidating multiple rules into a single, more flexible Security policy rule. Furthermore, they reduce false positive detections and allow your data security admins to achieve a more nuanced approach to data protection that aligns closely with your organization's risk management strategy while maintaining a lean and efficient Security policy rulebase.

WebSocket Support

May 2026
  • Introduced in PAN-OS 12.1.7
Enterprise Data Loss Prevention (E-DLP) supports the inspection of data in transit that is not part of a formal file upload. This non-file traffic inspection helps prevent the exfiltration of sensitive data through collaboration applications, web forms, cloud applications, and social media. However, this non-file traffic inspection is designed for transactional web traffic (HTTP/HTTPS), where the client and server exchange data in discrete, request-response cycles. In contrast, a WebSocket connection provides a persistent, bidirectional data stream over a single connection, allowing for continuous communication without the overhead of individual request-response cycles. While a WebSocket connection can provide better performance for real-time applications, it introduces unique security challenges for preventing data loss. These challenges exist because the persistent nature of the connection allows data to flow continuously rather than in distinct bursts, and can bypass traditional traffic-inspection methods.
To address these challenges, Enterprise DLP has expanded its non-file support to include inspection of WebSocket traffic. This capability allows the detection engine to examine WebSocket persistent streams in real time to identify sensitive patterns previously hidden within the open connection. Enterprise DLP supports WebSocket inspection for the following widely adopted applications that rely heavily on streaming data:
  • Microsoft Copilot
  • Perplexity
You can enable WebSocket inspection by editing the Enterprise DLP data filtering settings.