Edit the Shadow Data Discovery Settings
Focus
Focus
Enterprise DLP

Edit the Shadow Data Discovery Settings

Table of Contents

Edit the Shadow Data Discovery Settings

Configure the Shadow Data Discovery settings to define control how Enterprise Data Loss Prevention (E-DLP) discovers and categorizes unstructured data in your environment
Where Can I Use This?What Do I Need?
Strata Cloud Manager
  • Data Security license
  • Enterprise DLP license
Or any of the following licenses that include the Enterprise DLP and Data Security licenses
  • Prisma Access CASB license
  • Next-Generation CASB for Prisma Access and NGFW (CASB-X) license
  • Data Security license
Enterprise DLP Shadow Data Discovery is Early Access.
Contact your Palo Alto Networks sales representative to enable this feature on your Enterprise DLP tenant.
Modify the Shadow Data Discovery settings after your data security administrator initialize a Shadow Data Discovery scan to dynamically update the file volume range and data channels Enterprise Data Loss Prevention (E-DLP) inspects for shadow data. These settings control how Enterprise DLP discovers and categorizes shadow data in your environment.
Changes to the Shadow Data Discovery settings take effect whenever Data Security (SaaS API) rescans onboarded apps and does not apply retroactively. The Shadow Data Discovery service maintains these settings as the authoritative source, syncing them across your Enterprise DLP deployment for consistent operation. These configurations ultimately determine when your organization transitions from collecting raw data to having actionable insights about sensitive information that traditional pattern-based detection might miss.
  1. Log in to Strata Cloud Manager.
  2. Select ConfigurationData Loss PreventionSettingsShadow Data Discovery.
  3. Review the enforcement Channels you want Enterprise DLP to inspect and categorize.
    Enterprise DLP supports shadow data file categorization for the following enforcement channels.
    • SaaS APIEnterprise DLP inspects files at rest for supported SaaS apps onboarded to Data Security.
  4. Save Changes.