Static Policies
Focus
Focus
SaaS Security

Static Policies

Table of Contents

Static Policies

Learn about the static policies that use preconfigured thresholds to detect specific threat indicators such as impossible travel, risky IPs, and multi-channel DLP violations.
Where Can I Use This?What Do I Need?
  • Strata Cloud Manager
  • Data Security license
Or any of the following licenses that include the Data Security license:
  • CASB-X
  • CASB-PA
Static policies use preconfigured thresholds to detect specific threat indicators. Unlike dynamic policies that rely on machine learning baselines, static policies trigger when user actions meet or exceed a defined threshold—providing deterministic, rule-based detection for well-known attack patterns. Each static policy has a configurable weight from 1 to 10 that determines its contribution to the user's overall risk score.
We initially introduced the static policies as predefined user activity policies in the Data Security product. These predefined policies are no longer available for newly provisioned tenants and have been deprecated for all tenants from May 30, 2025. If you are currently using the legacy predefined policies in Data Security, transition to the new static policies in Behavior Threats for continued functionality and access to the latest features. See the LIVEcommunity blog for a detailed explanation of this transition.
Static Policies
Policy NameDescription
DLP Violations Across Channels
Aggregates DLP incidents across all 6 enforcement channels (Endpoint DLP, NGFW, Email DLP, Prisma® Access, SaaS API, and Prisma® Browser) to detect users with a high volume of data loss prevention violations. When a user exceeds the configured threshold (default: 5 medium/high/critical violations per day), Behavior Threats creates an incident with drill-down details and links to UIM.
The policy ingests DLP violations from: Endpoint DLP, NGFW, Email DLP, Prisma Access, SaaS API, and Prisma Browser. You can configure the threshold, channels monitored, severity filter, enforcement action filter, and data profiles to exclude.
Unsafe VPN
Detects when a user accesses an app from an unauthorized or unsanctioned VPN, including personal VPNs and known consumer VPNs. The use of an unsafe VPN might indicate that the user is hiding their IP address to avoid auditing and tracking, or that a malicious actor is attempting to decrypt traffic to steal user credentials.
You can add custom IP addresses/Subnets to the IP Addresses to Exclude list so that Behavior Threats excludes them from being detected for anomalies. Select ConfigurationSaaS SecurityBehavior ThreatsPoliciesPolicy DetailsEdit PolicyConfigure ScopeAdd IP Address to add custom IP addresses/Subnets to be excluded. These IP addresses/Subnets are applicable only for static policies and not dynamic policies.
Impossible Traveler
Detects when a user accesses an app from different locations within a time frame that could not accommodate travel between the locations. This impossible travel might indicate that the user's account is compromised.
In addition to the Allowed list of IP addresses, you can add custom IP addresses/Subnets to the IP Addresses to Exclude list so that Behavior Threats excludes them from being detected for anomalies. Select ConfigurationSaaS SecurityBehavior ThreatsPoliciesPolicy DetailsEdit PolicyConfigure ScopeAdd IP Address to add custom IP addresses/Subnets to be excluded. These IP addresses/Subnets are applicable only for static policies and not dynamic policies.
Login Failures
Detects when a user has more than 5 consecutive failed login attempts to an app within 30 minutes. Multiple login failures might indicate an attempt to breach the user account.
Risky IPs
Detects when a user accesses an app from a suspicious IP address. Suspicious IP addresses include malicious IP addresses identified by Unit 42®, known Tor exit nodes, and IP addresses belonging to Bulletproof Hosting Providers (BHPs). Access from a risky IP address likely indicates that the user's account was breached.
You can add custom IP addresses/Subnets to the IP Addresses to Exclude list so that Behavior Threats excludes them from being detected for anomalies. Select ConfigurationSaaS SecurityBehavior ThreatsPoliciesPolicy DetailsEdit PolicyConfigure ScopeAdd IP Address to add custom IP addresses/Subnets to be excluded. These IP addresses/Subnets are applicable only for static policies and not dynamic policies.
Inactive Account Access
Detects when a user accesses an app using an account that has been inactive for over 30 days. Inactive account access might indicate that the user's account was breached.
Unsafe Location
Detects when a user accesses an app from a country that the United States Department of the Treasury considers unsafe. These countries are known origins of cyber attacks. User access from an unsafe location likely indicates that the user's account was breached.
You can add custom IP addresses/Subnets to the IP Addresses to Exclude list so that Behavior Threats excludes them from being detected for anomalies. Select ConfigurationSaaS SecurityBehavior ThreatsPoliciesPolicy DetailsEdit PolicyConfigure ScopeAdd IP Address to add custom IP addresses/Subnets to be excluded. These IP addresses are applicable only for static policies and not dynamic policies.
Malware Detection
Detects when a user interacts with a file that contains malware. This activity might identify a malicious user and is a threat to your organization.
Manage Static Policies
  1. Select Behavior ThreatsPoliciesStatic.
  2. To enable or disable a single policy, select its toggle. To enable or disable multiple policies at once, select the policies you want to change and click Enable or Disable.
  3. Use the Edit option under the Action menu to edit individual policies. After modifying the following as per your need, select NextSave.
    You cannot edit the name and description of static policies.
    • Severity
    • Enable or disable the policy.
    • Scope of the policy: Users and IP addresses to exclude.
    • Set policy actions: Notify via email.