Create an Endpoint DLP Data in Motion Policy Rule
Focus
Focus
Enterprise DLP

Create an Endpoint DLP Data in Motion Policy Rule

Table of Contents


Create an Endpoint DLP Data in Motion Policy Rule

Create a data in motion Endpoint DLP policy rule to inspect and block sensitive data moving between an endpoint and a peripheral device.
Printer peripheral devices only
Enterprise DLP inspects only the first five pages of a document and the first five images included in an inspected file when traffic matches a data in motion policy rule for Printer peripherals.
The total number of data patterns across all your Endpoint DLP policy rules, the size of the inspected file, and the total number of images within the file all impact the time it takes for Enterprise DLP to inspect the file. This is referred to as the Max Latency. Enterprise DLP cannot render a verdict if the inspection time exceeds the max latency.
To control the default action Enterprise DLP takes when the max latency is reached, edit the Action When Max Latency is Reached in the Endpoint DLP Data Transfer settings.
  1. Log in to Strata Cloud Manager.
  2. Configure the Enterprise DLP match criteria to define custom sensitive data that you want to inspect for and block.
    1. Create custom data patterns to define your match criteria.
      Alternatively, you can use the predefined data patterns instead of creating custom data patterns.
    2. Create a data profile and add your data patterns.
      Alternatively, you can use the predefined data profiles instead of creating custom data profiles.
  3. Select ConfigurationData Loss PreventionEndpoint DLP Policy and click Add Policy.
  4. Configure the Basic Information.
    1. For the Policy Type, select Data in Motion.
    2. Enter a descriptive Name for the Endpoint DLP policy rule.
    3. (Optional) Enter a Description to describe the Endpoint DLP policy rule.
    4. Choose the Severity of the Enterprise DLP incident when sensitive data is moved between an endpoint and a peripheral device.
    5. Enable Policy is enabled by default and enables the Endpoint DLP policy rule after you save.
      Disable this setting if you don't want to immediately enable the Endpoint DLP policy rule after creation.
    6. Click Next to continue.
  5. Configure the policy rule Classifiers to define the match criteria.
    1. Select the Data Profile that contains the match criteria you want to inspect for and block. You can select a predefined or custom data profile.
    2. Select the File Types you want the Endpoint DLP policy rule to apply to.
      You can select Any File Types (default) to inspect all supported file types moved between an endpoint and the peripheral device.
  6. Configure the Scope to define which users and endpoint channels the policy rule applies to.
    For Enterprise DLP to take the configured Response action, both Users and Endpoint Channels must be matched.
    1. Select the Users the policy rule applies to.
      • Any Users & Groups
        Apply the policy rule to all users. You can Exclude one or more users from the policy rule.
      • Select Users
        Apply the policy rule to specific users and groups. You can apply the rule to specific users, user groups, or both.
        Include
        • Select Users—Select one or more specific users the rule applies to.
        • Select Groups—Select one or more user groups the rule applies to.
        Exclude—Select one or more users to exclude from the policy rule. You must select at least one user group before you can exclude users.
    2. Configure the Endpoint Channels you want to inspect and block file movement to when sensitive data is detected.
      Each endpoint channel is independent and can be configured separately. Enable the Include toggle for each channel you want the policy rule to cover. You can configure each channel to apply to any peripheral added to Enterprise DLP, or to specific peripheral devices or peripheral groups.
      • USB Removable Media
        Enable Include to apply the policy rule to USB peripheral devices.
        • Any USB (default)—Rule applies to all USB peripherals added to Enterprise DLP.
        • Select USBs
          • Include—Rule applies only to specific USB peripheral groups.
          • Exclude—Rule applies to all USB peripheral devices except for peripheral devices associated with the selected groups.
      • Printers
        Enable Include to apply the policy rule to printer peripheral devices.
        • Any Printer (default)—Rule applies to all printer peripherals added to Enterprise DLP.
        • Select Printers
          • Include—Rule applies only to specific printer peripheral groups.
          • Exclude—Rule applies to all printer peripheral devices except for peripheral devices associated with the selected groups.
      • Network Shares
        Enable Include to apply the policy rule to network share peripheral devices.
        • Any Share (default)—Rule applies to all network share peripherals added to Enterprise DLP.
        • Select Shares
          • Include—Rule applies only to specific network share peripheral groups.
          • Exclude—Rule applies to all network share peripheral devices except for peripheral devices associated with the selected groups.
    3. Click Next to continue.
  7. Configure the Response to define the action Enterprise DLP takes when sensitive data is detected.
    • Action—Action Enterprise DLP takes if a User accesses a Peripheral device defined in the policy rule Scope.
      • AlertEnterprise DLP generates a DLP incident but allows file movement from the endpoint to the peripheral.
      • BlockEnterprise DLP generates a DLP incident and blocks file movement from the endpoint to the peripheral.
    • Incident Assignee—The administrator the Enterprise DLP incident is assigned to if one is generated against the policy rule.
    • Email Notifications—Add additional administrators to send email notifications when an incident is generated against the policy rule.
    • Enable End User Notification—Enable end-user notifications to notify users when they have attempted an action that is disallowed by the rule. From the list, select a notification template to associate with the rule.
      The template determines the appearance and message text that is displayed to the user. If the template has exemption requests enabled, the user will be able to request an exemption directly from the notification. To define a new notification template to associate with the rule, select + Create a New Template from the list.
    Click Next to continue.
  8. Define the Evaluation Priority for the peripheral control policy rule in your Endpoint DLP policy rulebase.
    You can use the Priority Selection to quickly insert the peripheral control policy rule in the appropriate location in your policy rulebase hierarchy.
    Click Next to continue.
  9. Review the policy rule Summary to verify it's configured correctly and click Save.
  10. Push your Endpoint Policy rule.
    1. Select Endpoint DLP PolicyPush Policies and click Push Policies.
    2. (Optional) Enter a Description for the Endpoint DLP policy push.
    3. Review the Push Policies scope to understand which Endpoint DLP policy rules and peripheral group configuration changes are included in the push.
    4. Click Push.
  11. Review your Endpoint DLP Audit and Push Logs.
  12. Review your Enterprise DLP Incidents.
    A DLP incident is generated when a user moves a file from the endpoint to the peripheral device but sensitive data is detected and the file move is blocked because sensitive data was detected.
  13. (Block policy rule for USB and Network Share Peripherals on macOS only) The Prisma Access Agent automatically moves a blocked file to the following local folder on the endpoint for quarantine for 90 days when Endpoint DLP detects and blocks a file containing sensitive data. The Prisma Access Agent automatically deletes the file from the endpoint after 90 days.
    /Library/Application Support/PaloAltoNetworks/DLP/quarantine/
    This applies to all file movement operations available on macOS. Navigate to the local folder on the endpoint and move the file to a different folder on the endpoint to recover the file.