Dynamic Policies
Focus
Focus
SaaS Security

Dynamic Policies

Table of Contents

Dynamic Policies

Learn about the dynamic policies that use machine learning and historical data to detect anomalous user behavior.
Where Can I Use This?What Do I Need?
  • Strata Cloud Manager
  • Data Security license
Or any of the following licenses that include the Data Security license:
  • CASB-X
  • CASB-PA
Dynamic policies instruct Behavior Threats to detect anomalies in specific types of user activities by comparing current behavior against historical baselines derived from up to 90 days of data and machine learning. Unlike static policies that use fixed thresholds, dynamic policies adapt to each user's normal behavior patterns—ensuring that incidents reflect genuinely anomalous activity rather than arbitrary limits.
Behavior Threats separates dynamic policies into the following behavioral categories:
  • Spike in Activity—A marked increase in a particular activity within a single hour compared to historical data.
  • Bulk Activity—A marked increase in a particular activity over a span of hours (applicable only for sensitive assets as per policy).
  • Time-Based Activity—An activity performed at an unusual time for that user.
  • Location-Based Activity—An activity performed from an unusual geographic location.
  • Sensitive Data-Transfer Activity—Unusual user access to files containing Enterprise Data Loss Prevention (E-DLP) data patterns.
Policies to Detect a Spike in Activity
Policy NameDescription
Detect spike in Application Usage
Detects spikes in usage for an individual app within a single hour. Behavior Threats logs incidents based on the number of distinct actions a user performs in a particular app compared to their typical interaction pattern.
Detect spike in Data Downloads or Uploads
Detects when a user uploads or downloads a large number of distinct files or folders within a single hour compared to their typical data transfer behavior.
Detect spike in Share, Delete, and Edit actions
Detects spikes in Share, Delete, or Edit actions across all SaaS apps by a single user within a single hour compared to their typical file management behavior.
Detect spike in User Activity
Detects when a user performs excessive interactions with SaaS apps within a single hour compared to their typical interaction volume.
Detect spike in failed logins
Detects when a user tries to log in unsuccessfully into SaaS applications multiple times.
Policies to Detect Bulk Activity
Policy NameDescription
Detect bulk Data Downloads or Uploads
Detects when a user uploads or downloads a large number of files or folders within a span of hours compared to their typical transfer behavior over the same time period.
Detect bulk User Activity
Detects when a user performs excessive interactions with SaaS apps within a span of hours compared to their typical activity volume over the same time period.
Policy to Detect Time-Based Activity
Policy NameDescription
Detect Abnormal User Activity Hours
Detects when users are active outside of the hours they normally access the system. Behavior Threats logs incidents by comparing the time a user is active with their typical hours of activity.
Detect Inactive User ActivityDetects suspicious activity when a previously inactive user suddenly resumes activity after an extended period of inactivity.
Policy to Detect Location-Based Activity
Policy NameDescription
Detect Abnormal Location Access
Detects when users access SaaS apps from an unusual location. Behavior Threats logs incidents by comparing the access location to typical locations for the user and their peers.
Behavior Threats excludes the Allowed list of IP addresses from being detected for anomalies. Historical data or machine learning do not consider these IP addresses for training or inference.
Policy to Detect Sensitive Data Transfer
Policy NameDescription
Detect Unusual Access to Sensitive Data
Detects unusual user access to files containing Enterprise DLP data patterns, including accessing many sensitive files or accessing files with data patterns not normally associated with the user's behavior.
Manage Dynamic Policies
  1. Select Behavior ThreatsPoliciesDynamic.
  2. To enable or disable a single policy, select its toggle. To enable or disable multiple policies at once, change the layout to list view and select the policies you want to change and click Enable or Disable.
    You cannot edit a dynamic policy.