Install the Enterprise DLP Plugin on Panorama
Focus
Focus
Enterprise DLP

Install the Enterprise DLP Plugin on Panorama

Table of Contents

Install the Enterprise DLP Plugin on Panorama

Install or uninstall the Enterprise Data Loss Prevention (E-DLP) plugin on your Panorama® management server.
On May 7, 2025, Palo Alto Networks is introducing new Evidence Storage and Syslog Forwarding service IP addresses to improve performance and expand availability for these services globally.
You must allow these new service IP addresses on your network to avoid disruptions for these services. Review the Enterprise DLP Release Notes for more information.
Where Can I Use This?What Do I Need?
  • NGFW (Managed by Panorama)
  • Prisma Access (Managed by Panorama)
  • Enterprise Data Loss Prevention (E-DLP) license
    Review the Supported Platforms for details on the required license for each enforcement point.
To use Enterprise Data Loss Prevention (E-DLP), you must first install the device certificate on your Panorama® management server and all managed NGFW, then install the Enterprise DLP plugin on Panorama. The plugin is required to manage your Enterprise DLP configuration and push changes to your managed NGFW; managing the Enterprise DLP configuration directly on your NGFW isn't supported. Before you install, verify that Panorama belongs to the same tenant service group (TSG) as the NGFW or Prisma Access tenants associated with Enterprise DLP. Use Device Associations in Strata Cloud Manager to add Panorama to the TSG if it isn't already associated.
You only need to install the Enterprise DLP plugin on Panorama. All NGFW automatically receive the minimum supported Enterprise DLP plugin version when you install a new PAN-OS version. Manual upgrades on Panorama are only required when upgrading within the same major version (for example, from 5.0.0 to 5.0.1).
The Enterprise DLP plugin creates a temporary __dlp Panorama admin for configuration changes. This account has no login credentials, can't be used to log in to Panorama, isn't listed as a Panoramaadministrator account, and has no access privileges beyond the Enterprise DLP plugin.
  • Supported Panorama and TSG configurations
    Enterprise DLP supports:
    • Associating multiple Panorama management servers with a single Customer Support Account.
    • A Customer Support Account with a single Tenant Service Group (TSG) or multitenant (Parent-Child) TSG hierarchy.
    • One Enterprise DLP license per TSG.
    • Associating up to one standalone Panorama or up to one pair of Panorama management servers in an active/passive high availability (HA) configuration per TSG with an Enterprise DLP license.
      Enterprise DLP synchronization occurs across the specific TSG and not across the entire multitenant TSG hierarchy.
      Enterprise DLP fails to synchronize your configuration to Panorama if you associate more than one standalone Panorama, more than one Panorama HA pair, or any combination of the two, with a TSG.
    While Enterprise DLP and the Customer Support Portal support associating multiple Panorama with a single Customer Support Portal, you must meet the per-TSG Enterprise DLP license and Panorama association requirement to synchronize configuration changes across Panorama and Strata Cloud Manager.
Installing the Enterprise DLP plugin on Panorama automatically hides your existing data patterns (ObjectsCustom ObjectsData Patterns) and data filtering profiles (ObjectsSecurity ProfilesData Filtering). To display them when you need to reference them, you can temporarily enable existing data patterns and profiles.

Install the Enterprise DLP Plugin

Install the Enterprise Data Loss Prevention (E-DLP) plugin on your Panorama® management server.
  1. Activate the Enterprise DLP License.
    You must activate the Enterprise DLP license and associate it with your Panorama and managed devices before you install the Enterprise DLP plugin. This ensures the plugin correctly maps to your TSG and prevents synchronization issues.
  2. Review the Compatibility Matrix to verify the Enterprise DLP plugin version is supported on the PAN-OS version running on Panorama.
  3. Verify that Panorama and your managed devices belong to the same tenant service group (TSG) using Device Associations in Strata Cloud Manager.
    Panorama and any managed devices must belong to the same TSG to synchronize Enterprise DLP data profiles with Strata Cloud Manager and maintain consistent Security policy rule enforcement. If Panorama isn't already associated with the TSG, use Device Associations to add it before you install the plugin.
  4. Add your managed devices to a device group and template stack.
    Device groups and template stacks are required to manage device configurations and push Enterprise DLP configuration changes.
    Skip this step if you already added your managed devices to a device group and template stack.
  5. Install device certificates on Panorama and your managed devices.
    1. Install the Panorama Device Certificate.
      (High Availability) If Panorama is in an active/passive high availability (HA) configuration, install the Panorama device certificate on both HA peers.
    2. Install the Device Certificate for Managed Devices.
      The device certificate is required for all managed devices using Enterprise DLP.
  6. Install the plugin on Panorama.
    1. Log in to the Panorama web interface.
    2. Select PanoramaPlugins and search for the latest version of the Enterprise DLP plugin.
    3. Download the Enterprise DLP plugin.
    4. (HA only) Check (enable) Sync to HA peer to install the Enterprise DLP on the Panorama peer.
      Both HA peers must have the plugin installed. Installing it on only one peer can cause configuration push errors and suspend the active peer.
    5. Install the Enterprise DLP plugin on Panorama.
      Repeat this step on both Panorama HA peers.
  7. Edit the Cloud Content Settings to configure the regional Public Cloud Server FQDN for your deployment.
    Configuring the correct regional FQDN ensures that Enterprise DLP data and data processing, including DLP incidents, reports, and verdicts, are generated in the region that meets your data residency requirements.
  8. Commit and push the new configuration to your managed devices to complete the Enterprise DLP plugin installation.
    The Commit and Push command isn’t recommended for Enterprise DLP configuration changes. Using the Commit and Push command requires the additional and unnecessary overhead of manually selecting the impacted templates and managed devices in the Push Scope Selection.
    • Full configuration push from Panorama
      1. Select CommitCommit to Panorama and Commit.
      2. Select CommitPush to Devices and Edit Selections.
      3. Select Device Groups and Include Device and Network Templates.
      4. Click OK.
      5. Push your configuration changes to your managed devices that are using Enterprise DLP.
    • Partial configuration push from Panorama
      You must always include the temporary __dlp administrator when performing a partial configuration push. This is required to keep Panorama and Strata Cloud Manager in sync.
      For example, if admin is logged in and making changes, they must select both admin and __dlp in the partial commit and push.
      1. Select CommitCommit to Panorama.
      2. Select Commit Changes Made By and then click the current Panorama admin user to select additional admins to include in the partial commit.
        Select your logged-in admin user, the __dlp user, and any other admins whose changes to include. Click OK to continue.
      3. Commit.
      4. Select CommitPush to Devices.
      5. Select Push Changes Made By and then click the current Panorama admin user to select additional admins to include in the partial push.
        Select your logged-in admin user, the __dlp user, and any other admins whose changes to include. Click OK to continue.
      6. Select Device Groups and Include Device and Network Templates.
      7. Click OK.
      8. Push your configuration changes to your managed devices that are using Enterprise DLP.
  9. Activate your Enterprise DLP license for your managed devices.
    Repeat this step for all managed devices using Enterprise DLP.
    1. Log in to the Palo Alto Networks Customer Support Portal.
    2. Select AssetsLicenses & Subscriptions and locate the managed device for which you want to activate Enterprise DLP.
    3. In the Actions column, click Licenses & Subscriptions.
    4. Click Activate License at the bottom of the page.
    5. Select Activate License from the list of Activation Types.
    6. In the Activate Auth-Code field, enter the auth code provided by Palo Alto Networks.
    7. Agree and Submit.
  10. (Optional) Create a Palo Alto Networks Support ticket to enable your Enterprise DLP license to transfer between firewalls.
    In the support ticket, include the following information:
    • The request for a firewall transfer for the Enterprise DLP license.
    • Your CSP account ID and the email associated with your CSP account.
    • The managed device serial number. If you activated the Enterprise DLP license on multiple managed devices, include the serial numbers for all the managed devices in a single support ticket.
    • The auth codes used to activate the Enterprise DLP license on your managed devices.
    • The CSP account ID associated with any managed devices that belong to a different CSP account.
  11. Verify that you successfully activated Enterprise DLP.
    1. On Panorama, select ObjectsDLP to confirm that the Data Filtering Patterns and Data Filtering Profiles automatically populate with the predefined data patterns and profiles.
    2. On the firewall web interface, select DeviceLicenses and verify that the Enterprise DLP successfully activated.
  12. Review the Setup Prerequisites and allow the required ports and FQDNs for your region on your network.
  13. After you successfully install the Enterprise DLP plugin on Panorama, you must create Security policy rules to enable managed devices to use Enterprise DLP.

Install the Enterprise DLP Plugin on Panorama for FedRAMP

Install the Enterprise Data Loss Prevention (E-DLP) plugin on your Panorama® management server in a FedRAMP environment.
FedRAMP is supported on the following Enterprise DLP plugin versions:
  • 3.0.11 and later 3.0 releases
  • 5.0.9 and later 5.0 releases
  • 6.0.3 and later releases
  1. Activate the Enterprise DLP License.
    You must activate the Enterprise DLP license and associate it with your Panorama and managed devices before you install the Enterprise DLP plugin. This ensures the plugin correctly maps to your TSG and prevents synchronization issues.
  2. Review the Compatibility Matrix to verify the Enterprise DLP plugin version is supported on the PAN-OS version running on Panorama.
  3. Verify that Panorama and your managed devices belong to the same tenant service group (TSG) using Device Associations in Strata Cloud Manager.
    Panorama and any managed devices must belong to the same TSG to synchronize Enterprise DLP data profiles with Strata Cloud Manager and maintain consistent Security policy rule enforcement. If Panorama isn't already associated with the TSG, use Device Associations to add it before you install the plugin.
  4. Add your managed devices to a device group and template stack.
    Device groups and template stacks are required to manage device configurations and push Enterprise DLP configuration changes.
    Skip this step if you already added your managed devices to a device group and template stack.
  5. Install device certificates on Panorama and your managed devices.
    1. Install the Panorama Device Certificate.
      (High Availability) If Panorama is in an active/passive high availability (HA) configuration, install the Panorama device certificate on both HA peers.
    2. Install the Device Certificate for Managed Devices.
      The device certificate is required for all managed devices using Enterprise DLP.
  6. Install the plugin on Panorama.
    1. Log in to the Panorama web interface.
    2. Select PanoramaPlugins and search for the latest version of the Enterprise DLP plugin.
    3. Download the Enterprise DLP plugin.
    4. (HA only) Check (enable) Sync to HA peer to install the Enterprise DLP on the Panorama peer.
      Both HA peers must have the plugin installed. Installing it on only one peer can cause configuration push errors and suspend the active peer.
    5. Install the Enterprise DLP plugin on Panorama.
      Repeat this step on both Panorama HA peers.
  7. Log in to the Panorama CLI and set up the Enterprise DLP plugin.
    1. Set the Enterprise DLP plugin cloud mode.
      Setting the cloud mode automatically configures the correct Public Cloud Server FQDN for your FedRAMP environment.
      request plugins dlp set-cloud-mode mode <mode>
      Replace <mode> with the value that matches your FedRAMP environment:
      • gov-mod — FedRAMP Moderate
      • gov-high — FedRAMP High
    2. Reset the Enterprise DLP plugin using either of these commands.
      The plugin uses the default Commercial mode on installation. Reset it to ensure the plugin successfully connects successfully connect to and synchronize with Enterprise DLP.
      • request plugins reset-plugin only plugin plugin-name dlp
      • request plugins reset-plugin plugin-name dlp
  8. Commit and push the new configuration to your managed devices to complete the Enterprise DLP plugin installation.
    The Commit and Push command isn't recommended for Enterprise DLP configuration changes. Using the Commit and Push command requires the additional and unnecessary overhead of manually selecting the impacted templates and managed devices in the Push Scope Selection.
    • Full configuration push from Panorama
      1. Select CommitCommit to Panorama and Commit.
      2. Select CommitPush to Devices and Edit Selections.
      3. Select Device Groups and Include Device and Network Templates.
      4. Click OK.
      5. Push your configuration changes to your managed devices that are using Enterprise DLP.
    • Partial configuration push from Panorama
      You must always include the temporary __dlp administrator when performing a partial configuration push. This is required to keep Panorama and Strata Cloud Manager in sync.
      For example, if admin is logged in and making changes, they must select both admin and __dlp in the partial commit and push.
      1. Select CommitCommit to Panorama.
      2. Select Commit Changes Made By and then click the current Panorama admin user to select additional admins to include in the partial commit.
        Select your logged-in admin user, the __dlp user, and any other admins whose changes to include. Click OK to continue.
      3. Commit.
      4. Select CommitPush to Devices.
      5. Select Push Changes Made By and then click the current Panorama admin user to select additional admins to include in the partial push.
        Select your logged-in admin user, the __dlp user, and any other admins whose changes to include. Click OK to continue.
      6. Select Device Groups and Include Device and Network Templates.
      7. Click OK.
      8. Push your configuration changes to your managed devices that are using Enterprise DLP.
  9. Activate your Enterprise DLP license for your managed devices.
    Repeat this step for all managed devices using Enterprise DLP.
    1. Log in to the Palo Alto Networks Customer Support Portal.
    2. Select AssetsLicenses & Subscriptions and locate the managed device for which you want to activate Enterprise DLP.
    3. In the Actions column, click Licenses & Subscriptions.
    4. Click Activate License at the bottom of the page.
    5. Select Activate License from the list of Activation Types.
    6. In the Activate Auth-Code field, enter the auth code provided by Palo Alto Networks.
    7. Agree and Submit.
  10. (Optional) Create a Palo Alto Networks Support ticket to enable your Enterprise DLP license to transfer between NGFW.
    In the support ticket, include the following information:
    • The request for a firewall transfer for the Enterprise DLP license.
    • Your CSP account ID and the email associated with your CSP account.
    • The managed device serial number. If you activated the Enterprise DLP license on multiple managed devices, include the serial numbers for all the managed devices in a single support ticket.
    • The auth codes used to activate the Enterprise DLP license on your managed devices.
    • The CSP account ID associated with any managed devices that belong to a different CSP account.
  11. Verify that you successfully activated Enterprise DLP.
    1. On Panorama, select ObjectsDLP to confirm that the Data Filtering Patterns and Data Filtering Profiles automatically populate with the predefined data patterns and profiles.
    2. On the firewall web interface, select DeviceLicenses and verify that Enterprise DLP successfully activated.
  12. Review the Setup Prerequisites and allow the required ports and FQDNs for your FedRAMP environment on your network.
  13. Review the supported features for your FedRAMP environment.
  14. After you successfully install the Enterprise DLP plugin on Panorama, you must create Security policy rules to enable managed devices to use Enterprise DLP.

Uninstall the Enterprise DLP Plugin

Uninstall the Enterprise Data Loss Prevention (E-DLP) plugin from your Panorama® management server.
  1. Log in to the Panorama web interface.
  2. Select PoliciesSecurity and remove all Enterprise DLP data filtering profiles from your Security policy rules.
    This step is required to successfully uninstall the Enterprise DLP plugin.
  3. Commit and push your configuration changes to your managed devices using Enterprise DLP.
    The Commit and Push command isn’t recommended for Enterprise DLP configuration changes. Using the Commit and Push command requires the additional and unnecessary overhead of manually selecting the impacted templates and managed devices in the Push Scope Selection.
    1. Select CommitCommit to Panorama and Commit.
    2. Select CommitPush to Devices and Edit Selections.
    3. Select Device Groups and Include Device and Network Templates.
    4. Click OK.
    5. Push your configuration changes to your managed devices that are using Enterprise DLP.
  4. In the Panorama web interface, select PanoramaPlugins and Uninstall the Enterprise DLP plugin.
    (HA) Repeat this step on both Panorama HA peers if Panorama is in an HA configuration.
  5. Commit and push the new configuration to your managed devices to uninstall the Enterprise DLP plugin.
    The Commit and Push command isn’t recommended for Enterprise DLP configuration changes. Using the Commit and Push command requires the additional and unnecessary overhead of manually selecting the impacted templates and managed devices in the Push Scope Selection.
    • Full configuration push from Panorama
      1. Select CommitCommit to Panorama and Commit.
      2. Select CommitPush to Devices and Edit Selections.
      3. Select Device Groups and Include Device and Network Templates.
      4. Click OK.
      5. Push your configuration changes to your managed devices that are using Enterprise DLP.
    • Partial configuration push from Panorama
      You must always include the temporary __dlp administrator when performing a partial configuration push. This is required to keep Panorama and Strata Cloud Manager in sync.
      For example, if admin is logged in and making changes, they must select both admin and __dlp in the partial commit and push.
      1. Select CommitCommit to Panorama.
      2. Select Commit Changes Made By and then click the current Panorama admin user to select additional admins to include in the partial commit.
        Select your logged-in admin user, the __dlp user, and any other admins whose changes to include. Click OK to continue.
      3. Commit.
      4. Select CommitPush to Devices.
      5. Select Push Changes Made By and then click the current Panorama admin user to select additional admins to include in the partial push.
        Select your logged-in admin user, the __dlp user, and any other admins whose changes to include. Click OK to continue.
      6. Select Device Groups and Include Device and Network Templates.
      7. Click OK.
      8. Push your configuration changes to your managed devices that are using Enterprise DLP.

Troubleshoot the Enterprise DLP Plugin

Troubleshoot issues when installing the Enterprise Data Loss Prevention (E-DLP) plugin on your Panorama® management server.
Review the information below if you have trouble installing or upgrading the Enterprise Data Loss Prevention (E-DLP) plugin on your Panorama® management server.

Reset the Enterprise DLP Plugin

In some cases, you may need to reset the Enterprise DLP plugin in the Panorama CLI to resolve Enterprise DLP configuration sync or upgrade issues causing Panorama commit failures or failed plugin validation errors. These errors are often related to the device certificate required on Panorama or the NGFW, or a general connectivity issue preventing Panorama or the NGFW from connecting to Enterprise DLP. This issue manifests in two primary ways:
  • Out-of-Sync State—Occurs when Enterprise DLP can't sync data patterns or data filtering profiles on Panorama with Strata Cloud Manager. This results in commit warnings and commit failures on Panorama.
  • Manual Post-Upgrade Sync—After upgrading from Enterprise DLP plugin 1.0.4 or 1.0.5 to a later version, you must manually synchronize the Enterprise DLP plugin with Strata Cloud Manager.
Review the steps below to identify and resolve.
  1. Log in to the Panorama CLI.
  2. Reset the Enterprise DLP plugin using either of the following commands. They are functionally the same and both reset the Enterprise DLP plugin.
    • request plugins reset-plugin only plugin plugin-name dlp
    • request plugins reset-plugin plugin-name dlp
  3. Review the plugin reset command responses.
    A successful plugin reset returns one of the following responses.
    • pass dlp reset local state, then synced candidate configuration
    • plugin dlp has been reset
    An unsuccessful plugin reset returns one the following responses.
    • fail DLP reset failure, check DLP plugin log
      Plugin reset failed due to an issue with the device certificate on Panorama and requires the data security administrators to investigate the plugin log.
    • Cannot perform operation : DLP not provisioned for this tenant
      Plugin reset failed due to Panorama not having a valid Enterprise DLP tenant ID.
  4. Investigate further depending on the error message Panorama returned when resetting the plugin,
    • fail DLP reset failure, check DLP plugin log
      Check the Enterprise DLP plugin log on Panorama.
      admin>tail follow yes mp-log plugin_dlp.log
      Look for the following device certificate errors.
      ERROR: [dlp_agent] Cannot load the device certificate for authentication
      ERROR: [dlp_agent] Tenant: , Result: fail, Message: Cannot load the device certificate for authentication
      If you find these device certificate errors, install the Panorama device certificate and reset the plugin.
      If you installed the Panorama device certificate and continue to experience errors after a plugin reset, continue to the next step.
    • Cannot perform operation : DLP not provisioned for this tenant
      1. Check that Panorama successfully provisioned your Enterprise DLP tenant ID.
        admin>show system state | match cfg.platform.dlp_tenant_id
      2. Panorama returns one of the following responses.
        • Provisioned Enterprise DLP Tenant ID:
          cfg.platform.dlp_tenant_id: <numerical tenant ID>
          If Panorama successfully provisioned your Enterprise DLP tenant ID and you continue to experience issues resetting the Enterprise DLP plugin, review your Panorama connectivity and logs. There might be unrelated network configurations causing this error. Additionally, ensure that you enabled Enterprise DLP on your network. Continue to the next step to troubleshoot NGFW connectivity issues.
        • No Provisioned Enterprise DLP Tenant ID:
          cfg.platform.dlp_tenant_id: 0
          Continue to the next step to provision the Enterprise DLP tenant ID on Panorama.
      3. Provision the Enterprise DLP tenant ID on Panorama.
        admin>request plugins dlp provision-tenant
        Panorama returns the following responses.
        • Successful Provisioning:
          Pass
          DLP Provision Successful
        • Failed Provisioning - Generic
          fail
          DLP Provisioning Failed - Empty tenant ID
          If Panorama returns this response, review your Panorama connectivity and logs. There might be unrelated network configurations preventing Panorama from contacting Enterprise DLP. Additionally, ensure that you enabled Enterprise DLP on your network.
        • Failed Provisioning - Panorama Device Certificate
          fail
          DLP Provisioning Failed - Thermite Cert is not installed
          If Panorama returns this response, install the Panorama device certificate and provision the Enterprise DLP tenant ID.
  5. Troubleshoot NGFW connectivity issues.
    1. Log in to the NGFW CLI.
    2. Check the CTD-Agent status.
      admin>show ctd-agent status security-client
    3. Review the Cloud connection status.
      If the status displays connected there might issues not related to the Enterprise DLP or the device certificate.
      If the status displays disconnected, install the device certificate on your NGFW.
    4. Restart the Enterprise DLP agent.
      admin>debug software restart process ctd-agent
    5. Check the Cloud connection status again.

Panorama Commit Failure After Upgrade to PAN-OS 11.1 or Later

In PAN-OS 11.0 and later releases and Enterprise DLP plugin 4.0 and later releases, Enterprise DLP removed the Any setting for the data filtering profile File Type setting. Panorama experiences the following validation error when you commit a configuration change if you have any data filtering profiles with the Any File Type setting configured after upgrading to PAN-OS 11.0 or later release and Enterprise DLP plugin 4.0 or later release:
Validation Error: deviceconfig -> plugins -> dlp -> internal -> dlp-data-profiles -> <Profile Name> -> file-type-array -> any 'any' is not a valid reference deviceconfig -> plugins -> dlp -> internal -> dlp-data-profiles -> Bulk CCN -> file-type-array is invalid
To resolve this validation error, contact Palo Alto Networks Customer Support to open a ticket and request that a migration script convert all your existing predefined and custom data filtering profiles. You must contact Palo Alto Networks because the migration includes predefined data filtering profiles that are Read Only and cannot be modified.
When you submit the support ticket, include the commit validation error and the Tech Support File in your migration request ticket.