Learn how to enable group-based selective scanning.
| Where Can I Use This? | What Do I Need? |
|
|
Or any of the following licenses that include the Data Security license:
|
The steps to enable group-based selective scanning are the
same for both new customers
integrating CIE with Data Security and
legacy customers integrating Azure Active Directory with Data Security.
Group-based
selective scanning is the ability to include or exclude specific AD
groups from scans. Sometimes you might want to monitor the assets and accounts of
specific groups of users and not others. If your cloud app supports selective
scanning,
Data Security enables you to select which directory groups to
include or exclude from both forward scan and backward scan.
Selective scanning is supported by specific cloud apps. By default, selective scanning is not
enabled, and it’s important that you decide if you want to enable selective
scanning—before you connect a cloud app to Data Security. Otherwise, you
must delete the cloud app instance, then reconnect the cloud app to Data Security to rediscover all assets and events for all users: all assets
and events previously stored will be deleted and incidents reported for users no
longer included in the selected groups are automatically closed.
Before you enable selective scanning,
learn about selective scanning behaviors.