Cisco Secure Access Help

PDF

Cisco Secure Access Help

Add a SaaS API Rule to the Data Loss Prevention Policy

Want to summarize with AI?

Log in

Provides instructions for completing the Add a SaaS API Rule to the Data Loss Prevention Policy workflow in Cisco Secure Access. Configure an SaaS API Rule to set the criteria as to what triggers the scanning.


Configure an SaaS API Rule to set the criteria as to what triggers the scanning. As files in the selected tenant are scanned upon content change and context (sharing) change, Secure Access assesses the file against this rule's criteria. If a match is made, this rule's action is immediately enforced. If Secure Access detects a violation, the offending file is listed in the Data Loss Prevention Report.

An SaaS API Rule must have at least one of the following two criteria defined:

  • Data Classifications — Include files that match data classification of your own making or a built-in data classification provided by Secure Access.

  • File Labels — Include files that have specific file label names configured in the value of the files' document properties, or include files that have no labels configured. Secure Access scans for file labels on the following file types: .doc, .pdf, .rtf, .xls, .ppt, .odp, .ods, .odt, .pptx, .xlsx, .docx, and .eml.

    • Microsoft Information Protection (MIP) labels are used to classify and protect data in Microsoft 365 files.

    • Titus labels are a third-party classification system provided by Fortra that can provide additional classification and protection features for Microsoft 365 files.

    • Microsoft Office Sensitivity Labels are a specific type of MIP label focused on indicating the sensitivity of data within Microsoft 365 files.

    The types of file labels Secure Access can scan varies depending on the platform of the tenant:
    • For AWS S3, Azure Storage, Confluence, Dropbox, GitHub, Google Drive, Jira, ServiceNow, Slack, and Webex Teams you can apply filters for MIP and Titus labels.

    • For Microsoft 365 and Box you can apply filters for MIP and Titus labels, and Microsoft Office Sensitivity Labels. (Within the Box application, sensitivity labels are referred to as classification labels.)

    • For Salesforce you can apply filters for Microsoft Office document properties, or Adobe PDF document properties.

Note
Changes to the share permissions or other options on a folder does not trigger a scan of the contents of that folder.

SaaS API rules configured to scan Microsoft Outlook messages scan only outgoing messages. Violations can be triggered by material found in the email subject, message body, or attachments; a single email message may trigger multiple violations: one for the message subject and body, and one for each attachment.

Procedure

  1. Create a DLP SaaS API Rule Step 1 — Establish General Settings

  2. Select Data Classifications to apply to the rule.

  3. Make Files Control selections for the rule

  4. Select Platform and Tenant for the rule

  5. Select Users whose files are included or excluded from scanning for this rule

  6. Select Resource Labels for the rule

  7. Select Resources for the rule

  8. Configure Exposure Settings for processing the files to search for data violations

  9. Select Action to be performed when data matches the rule

  10. Enable and configure an Email Notifications to be sent to users when a violation occurs


Create a DLP SaaS API Rule Step 1 — Establish General Settings

This is the first step in the process to add a SaaS API rule to a DLP policy, in which you create the rule and establish its basic characteristics.

Procedure

  1. Navigate to Secure > Policy > Data Loss Prevention Policy, click Add Rule, and choose SaaS API Rule.

  2. In the Add New SaaS API Rule page, enter a meaningful Rule Name and Description. Choose a Severity value from the drop-down based on the risk involved or importance within the ruleset. (Assigning severity values can help later on when you need to filter events in the Data Loss Prevention report.)

    Severity section with option to select the severity level

Create a DLP SaaS API Rule Step 2 — Select Data Classifications

This is the second step in the process to add a SaaS API rule to a DLP policy, in which you select the data classifications to apply to the rule.

Procedure

  1. Under Data Classifications select where in scanned files you would like this rule to search for the data classifications that you choose:

    Data Classifications page showing options to define search criteria for the selected data classifications

    Content—(Default) Scans only the content of files for the selected data classifications.

    • For Outlook this option scans the subject line and message body of incoming email, and the file content of attachments to incoming email.

    • For Salesforce, chatter posts and sObjects can be scanned for content only.

    • For Confluence, this option scans page headings and contents, file attachments to pages, and comment headings and contents. Secure Access does not scan file attachments to Confluence comments, or Confluence database tables or whiteboards.

    • For Jira, this option scans page headings and contents, comment headings and contents, and file attachments to pages and comments.

    File Name—Scans only file names for the selected data classifications.

    • For Outlook this option scans the subject line and message body for incoming email, and the file name for attachments to incoming email.

    • For Confluence this option scans page headings and contents, and the file names for attachments to pages. Secure Access does not scan file attachments to Confluence comments, or Confluence database tables or whiteboards.

    • For Jira this option scans page headings and contents, and the file names for attachments to pages and comments.

    Content and File Name—Scans content and file names for the selected data classifications. Both content and file name do not need to match for the rule to apply, only one or the other.

    Note
    Choosing Content, File Name, or Content and File Name refers to scanning file uploads for the selected data classifications and configured file labels.
  2. Select Data Classifications to apply this rule; you can choose data classifications of your own making or built-in data classifications provided by Secure Access. (See Manage Data Classifications and Built-In Data Classifications.) Hover over PREVIEW to view data identifiers associated with each data classification.

    Data Classifications section with an option for selecting the required classifications to apply this rule

Create a DLP SaaS API Rule Step 3 — Select Files Controls

This is the third step in the process to add a SaaS API rule to a DLP policy, in which you select the files controls to apply to the rule.

In the Files Control area, choose the file filters to apply to this rule. The file filters available depend on the platform you have chosen:

  • For AWS S3, Azure Storage, Dropbox, Google Drive, Salesforce, ServiceNow, Slack, and Webex Teams you can apply filters for MIP and Titus labels, and file size. You can also filter for files with no labels.

  • For Microsoft 365 and Box you can apply filters for MIP and Titus labels, Microsoft Office Sensitivity Labels, and file size. (Within the Box application, sensitivity labels are referred to as classification labels.) You can also filter for files with no labels.

Note
You cannot select labels for filtering and filter for files with no labels in a single rule.

Procedure

  1. For all platforms select File Size filter criteria.

    The File Size area has two use cases:

    • In a rule with only custom file size criteria, DLP applies the rule action to files that match the file size criteria, regardless of content. (This may be useful in situations where you want to exclude certain low-risk files below a certain size from inspection, so as not to waste processing time on insignificant events.)

    • In a rule that specifies a custom file size along with other criteria such as Data Classification, the DLP applies the rule action to files that match the other criteria within the file size specified up to the first 50 MB of plain text. (Secure Access does not scan file content beyond the first 50 MB regardless of the file size specified here.)

    In the File Size area choose from two options:

    • To scan up to the first 50 MB of plain text of all files that meet other criteria defined by this rule, enable the File Size toggle and do not select custom sizes. (A rule that uses this option must also specify Data Classifications.)

    • To specify the minimum and maximum size limits the system will scan for files that meet other inclusion criteria defined by this rule, if there are any, enable the File Size toggle and select custom size values. If the file size exceeds the first 50 MB of the file, Secure Access scans only up to the first 50 MB of plain text in the file. (I.e., if you specify a minimum file size greater than 50 MB, Secure Access will not scan for other criteria specified in the rule.)

      You can choose to apply the rule action only to files that are greater than a minimum size you specify, or to files that are within a range of sizes you specify. (If you specify a maximum size without specifying a minimum size, the minimum size defaults to 0.) You can specify file sizes in KB or MB.

    Including files by file size
  2. In the File Type area, configure the rule to include specific file types or to exclude unrecognized file types.

    1. Click the toggle to enable file type filtering.
      Including files by file type
    2. To include file types, use the search box to search for file types or browse within the lists for file types. Check the boxes for the file types to include individually or by group. Selected file types appear on the right.
      Selecting specific file types to include in Real Time DLP rule
    3. To exclude file types, check Select the file type for exclusion check box.

      In Excluded File Types section, use the search box to search for file types or browse within the lists for file types. Check the boxes for file types to exclude individually or by group. Selected file types appear on the right.

      Selecting file types to be excluded from Real Time DLP rule
  3. Specify MIP and Titus labels.

    For all platforms, you can enable MIP and Titus labels and add up to 10 case-sensitive file label names to apply to the rule. The rule will search for any of the configured label names in the files’ document properties. This includes Microsoft Office Document Properties and Adobe PDF Document Properties.

    For Outlook, this applies to files attached to incoming mail. File uploads to Confluence and Jira are not scanned for file labels.

    Secure Access scans for file labels on the following file types: .doc, .pdf, .rtf, .xls, .ppt, .odp, .ods, .odt, .pptx, .xlsx, .docx, and .eml.

    The Mip Titus Labels interface.
  4. For Microsoft 365 OneDrive or Sharepoint tenants, or for Box tenants, select Sensitivity Labels.

    For Microsoft 365 OneDrive or Sharepoint tenants, or for Box tenants, you can enable sensitivity labels and select from the list of sensitivity labels that have been created for your tenant. You may select any number of the labels displayed.

    Secure Access scans for file labels on the following file types: .doc, .pdf, .rtf, .xls, .ppt, .odp, .ods, .odt, .pptx, .xlsx, .docx, and .eml.

    Note
    Within the Box application, these labels are referred to as classification labels.
    Note
    Secure Access supports the detection of Microsoft sensitivity labels in the inspected file's properties values for Microsoft Word, Excel, PowerPoint, and .pdf files. Ensure you configure the rule with the name of the sensitivity labels, not the display names.

    The system does not scan the following for file labels:

    • Files attached to Outlook emails.

    • File uploads to Jira.

    • File uploads to Confluence.

    Note
    If you create new sensitivity labels for your Microsoft 365 or Box tenant, it may take up to four hours for them to appear in the Secure Access interface.
    The Sensitivity Labels interface.
  5. In the Unclassified Files area, click the toggle to include files that have no labels associated with them.

    This includes Microsoft Office Document Properties (or Titus labels) and Adobe PDF Document Properties, as well as Microsoft Office Sensitivity Labels (which are referred to as classification labels in Box).

    For Microsoft Office Document Properties, this includes only the Label Value field in the custom document properties.

    Secure Access scans for file labels on the following file types: .doc, .pdf, .rtf, .xls, .ppt, .odp, .ods, .odt, .pptx, .xlsx, .docx, and .eml.

    The Un Classified Files interface.

Create a DLP SaaS API Rule Step 4 — Select Platform and Tenant

This is the fourth step in the process to add a SaaS API rule to a DLP policy, in which you select one platform and tenant for the rule.

Procedure

In the Platform area, select one platform and tenant for this rule. Only platforms with authorized tenants will appear in the list.
Note

When you select Microsoft 365 you can select both OneDrive and SharePoint, but you cannot select Outlook in combination with Microsoft OneDrive or SharePoint in the same rule.

Platform page with option for selecting one platform and tenant for the rule
Note

When you select Confluence or Jira, each of the tenants you have established for that platform will appear; you must choose one.

The Choose Aconfluence Tenant interface.

Create a DLP SaaS API Rule Step 5 — Select Users

This is the fifth step in the process to add a SaaS API rule to a DLP policy, in which you select users whose files are included or excluded from scanning for this rule.

Procedure

In the Include and Exclude area, select users whose files are included or excluded from scanning for this rule. Make selections to include or exclude users from being matched. (For Outlook, user refers to the email sender. For Confluence and Jira, user refers to the owner of the page to which the file is attached.)
  • Click the Include all users radio button to scan files from all users, including external collaborators.

    Note
    If you have selected a Salesforce Commerce tenant, Include all users is the only option available.
    Include and Exclude section with an option to include all users to scan all files from all users
  • Click the Include specific users radio button to scan files from users selected in one of the following ways:

    • Check the Select users check box to include scanning for selected users as per the rule. You can select the entire AD group or search for identities by AD username or AD Group. The selected identities appear in the box on the right.

      Include and Exclude section showing an option to scan file from specific users
      Note
      Identities added to a category after the category has been included or excluded from a rule will be included or excluded from the rule as if they were part of the category at the time the rule was created.
    • Check the Manually add user domain destinations check box to specify domains where rules will apply to users within those domains.

      This option appears only if you have chosen Outlook or Webex Teams for Platform. You can enter a maximum of 1,000 user domain destinations.

      • For Outlook Secure Access scans message recipients for domain destination matches.

      • For Webex Teams Secure Access scans the Webex space owner for domain destination matches.

      Include and Exclude section with an option to manually add domains for applying rules to users
    • Check the Manually add user email addresses check box to specify email addresses of file owners to which the rule will apply.

      Enter the users' email addresses in the text box.

      Include and Exclude section with an option to manually add file owners email addresses for applying rule
  • Check the Exclude specific file users check box to exclude selected users from being matched by this rule. Similarly to selecting identities for inclusion, you can select all AD groups, All AD Users, individual groups, or individual users. Search for identities by AD user name or by AD Group name. Selected identities will appear in the box on the right.

    Include and Exclude section with an option to exclude selected users from being matched by this rule

Create a DLP SaaS API Rule Step 6 — Select Resource Labels

This is the sixth step in the process to add a SaaS API rule to a DLP policy, in which you add the resource labels.

Procedure

The Resource Labels area appears only if you have selected AWS or Azure for Platform. In the Resource Labels area, enter key/value pairs you have applied as tags to objects in AWS S3 buckets or Azure storage accounts or containers. Each resource label you enter here identifies the data Umbrella will monitor within your buckets (for AWS) or storage accounts or containers (for Azure). It may take a few minutes for resource labels you enter here to propagate to the policy page, depending on how many there are and the state of the discovery process.
Reource Labels page showing an option for adding resource labels

Create a DLP SaaS API Rule Step 7 — Select Resources

This is the seventh step in the process to add a SaaS API rule to a DLP policy, in which you add resources.

Procedure

The Resources area appears only if you have selected AWS S3, Azure Storage, or Webex for Platform.Under Resources make selections to define S3 buckets (for AWS) or containers (for Azure) to include or exclude from being matched by this rule:
  • Click the Include all resources radio button (the default) to include all resources available on your platform for scanning associated with your account (including non-admin resources).

    Resources section with an option to include all resources available on your platform for scanning
  • Click the Include specific resources radio button to display a list of resources available and select the ones you want to include for matching.

    • For AWS you can select S3 buckets

      Resources section showing an option to select S3 buckets
    • For Azure you can select containers

      Resources section showing an option to select containers
    • For Webex you can select Webex Teams and Webex Spaces

      Resources section showing an option to select Webex TeamsResources section showing an option to select Webex space

Create a DLP SaaS API Rule Step 8 — Configure Exposure Settings

This is the eighth step in the process to add a SaaS API rule to a DLP policy, in which you select the file sharing permissions for processing the files to search for data violations.

Procedure

Under Exposure, optionally select the file sharing permissions to consider when processing files to search for data violations:
  • Shared Publicly- Select to include files accessible to all users with the link to the file.

  • Shared with External Users- Select to include files shared with users who do not belong to the authorized domains.

  • Domain-wide Share- Select to include files shared with all users in a domain.

  • Shared with Internal Users- Select to include files shared with users who belong to the authorized domains.

  • Shared with Specific Users- Select to include files shared with specific users by their email addresses.

  • Shared with Specific domains- Select to include files shared with specific, defined domains.

The table below indicates which Exposure settings are available for each platform:

Shared Publicly Domain-wide share Shared with internal users Shared with external users Shared with specific users Shared with specific domains
AWS S3
Azure Storage
Box
Confluence
Dropbox
GitHub
Google
Jira
Microsoft Office 365 SharePoint Online
Microsoft Office 365 OneDrive
Microsoft Office 365 Outlook
Salesforce
Service Now
Slack
Webex Teams

Use the Exclude section to refine rule processing by omitting specific entities from your policy. Check Exclude specific users to enable the addition of individual email addresses or entire domains that you want to exclude from data violation monitoring

  • Add user email addresses- Select to specify individual user email addresses to exclude from the rule.

  • Add user domains- Check to specify user domains to exclude from the rule.

The table below indicates which Exclude settings are available for each platform:

Add user email addresses Add user domains
AWS S3
Azure Storage
Box
Confluence
Dropbox
GitHub
Google
Jira
Microsoft Office 365 SharePoint Online
Microsoft Office 365 OneDrive
Microsoft Office 365 Outlook
Salesforce
Service Now
Slack
Webex Teams
Note
You can configure a policy using only Exposure settings for M365, Google, Salesforce, and GitHub.
Note
Exclusion settings take precedence over inclusion settings; if a user or domain is selected in both sections, the exclusion will override the inclusion.
Note

A DLP rule can be configured with either Data Classifications, File Labels or both. Exposure is an optional criterion.

When a DLP rule is configured with all 3 criteria, then a DLP event is raised when any of the selected Data Classifications and when any of the configured file labels are detected in the inspected file and when the file’s permissions match any of the selected exposure settings.


Create a DLP SaaS API Rule Step 9 — Select Action

This is the ninth step in the process to add a SaaS API rule to a DLP policy, in which you select an Action to be performed when data matches the rule.

Procedure

  1. From the Action drop-down list, choose Monitor, Quarantine, Delete or Revoke Access.

    • Monitor- Detects and logs a DLP event for every modified file violating this rule's criteria

    • Quarantine- Isolates a file that violates the rule criteria to the quarantine folder (except for Salesforce) and revokes all shares

    • Delete- Permanently deletes when a change is detected that violates the rule criteria (This option is available only for Webex Teams, and applies for a violation within a post, as well as a violation within a file attached to a post.)

    • Revoke Access- Removes public link, all external or internal users, and any share permission within the entire organization. This action also removes the file owner and transfers the ownership to the selected user.

    The table below indicates which Actions settings are available for each platform:

    Monitor Quarantine Delete Revoke Access
    AWS S3
    Azure Storage
    Box
    Confluence
    Dropbox
    GitHub
    Google
    Jira
    Microsoft Office 365 Sharepoint Online
    Microsoft Office 365 OneDrive
    Microsoft Office 365 Outlook
    Salesforce
    Salesforce Commerce
    Service Now
    Slack
    Webex Teams
    Action section with an option to monitor or quarantine files to enforce for files violating this rule's criteria

    If you choose Quarantine for Microsoft OneDrive, Sharepoint Online, Box, Dropbox, or Google Drive:

    • The file identified as exposing sensitive data is moved to the Cisco_Quarantine/DLP folder Secure Access created in the root path of the Global Admin who authorized the tenant.

    • In lieu of the quarantined file, a text file is left in the original location with the name filename.ppt_Unique-Event-ID_Cisco_Quarantined.txt explaining to the original File Owner that the file is identified as exposing sensitive data and for more information to contact their organization administrator.

    • The user who authorizes access to Secure Access will have access to the quarantine folder. All other accesses and collaborators are removed.

    • Thus, we recommend that the admin add the relevant DLP Admins as additional collaborators to the folder.

    If you choose Quarantine for ServiceNow:

    • The file identified as exposing sensitive data is moved to a table named Cisco_Quarantine_Malware which can be access only by the admin user who authorized the ServiceNow tenant.

    • A footprint is attached to the notes\activities area of the table the file was originally attached to. This footprint will notify users that the file has been identified as malware, and for more information they should contact their administrator.

    If you choose Quarantine for Salesforce:

    • Secure Access applies the Quarantine response action to files only (including those attached to chatter posts). Secure Access performs the following for quarantined Salesforce files:

      • Remove all collaborators and change the file owner to the Salesforce admin who has performed the authorization, and who has been assigned the permisson set for the quarantine app. In Salesforce, the admin can see a list of quarantined files by using the App Launcher to search for "Cisco Secure Access SF Quarantine," then selecting the All Quarantines option.

        All Quarantines page showing a list of quarantined files obtained by searching using App Launcher

        Click on the listing for an individual file to see the information about it:

        View the information about each quarantined file
      • Replace the file in its original location with a text file named filename_Cisco_Quarantined.txt explaining to the original file owner that the file is identified as malware and for more information to contact their organization administrator.

    Note
    • Quarantine attempts may fail if the files have been locked or blocked by settings within their native platforms. Settings local to the platform where a file resides take precedence over Secure Access' ability to detect or remediate DLP violations or malware.

    • If your DLP rules process files from Microsoft OneDrive, SharePoint Online, Box, Dropbox, ServiceNow, Salesforce, or Google Drive and you restore a quarantined file that still violates rule criteria, the system will quarantine that file again. To prevent the system from quarantining the file again, remove the file's violation, or update the rule's criteria.

  2. If you chose Microsoft Office 365 OneDrive, Microsoft Office Sharepoint Online, Box, Dropbox, Google Drive, or Service Now, you can define the message to appear in the Tombstone File when files are quarantined.

    A file with malicious content may be quarantined when first detected during the SaaS API scanning process, or the user may choose to manually quarantine a file when reviewing the Data Loss Prevention Report. In either case, when a file is quarantined Secure Access creates a tombstone file as described in the previous step. You determine the contents of this tombstone file:

    • To Use the Default Tombstone Template:

      1. Click Default.

      2. To preview the content of tombstone text, click on Preview Default Tombstone. You can review the text, but you cannot change it.

        View default tombstone template
      3. Click CLOSE to close the preview.

    • To Use a Custom Tombstone Template:

      1. Click Custom.

      2. From the drop-down list, select an existing custom template, or choose Create new tombstone Template. If you select an existing custom template, you can click PREVIEW AND EDIT to review and change the template.

        Select custom tombstone template
      3. When you choose to create or edit a custom template for tombstone text you will see one of these two dialogs, which are almost identical:

        Create or edit a custom tombstone template

        The Edit Custom Tombstone Template includes a DELETE link which you can use to delete a custom template that is no longer needed. You cannot delete a template that is in use by any rule.

        To create a new template or change an existing template:

        1. Enter a unique Custom Template Name.

        2. Enter the text of the tombstone file in the Message Body text box.

          The text can include the following variables, which you must enclose in braces ( {} ):

          • {eventId} - The unique identifier the system generates for the policy violation event.

          • {detectedTimestamp} - The date and time the violation was detected, formatted as shown in this example: "Oct 1, 2023 at 14:04 UTC"

          • {actorName} - Name of the user whose action triggered the violation. (The system gets this from the tenant associated with the violation. Depending on application and file settings, this information may not be available, in which case the the system replaces this variable with blank text.)

          • {actorEmail} - Email address of the user whose action triggered the violation. (The system gets this from the tenant associated with the violation. Depending on application and file settings, this information may not be available, in which case the system replaces this variable with blank text.)

          • {fileName} - Name of the data file that triggered the violation.

          • {ruleName} - Name of the rule that was triggered.

          • {matchedClassifications} - The data classifications associated with the violation. (See Manage Data Classifications.)

          • {fileOwnerName} - Name of the file owner. (The system gets this from the tenant associated with the violation. Depending on application and file settings, this information may not be available, in which case the the system replaces this variable with blank text.)

          • {fileOwnerEmail} - Email address of the file owner. (The system gets this from the tenant associated with the violation. Depending on application and file settings, this information may not be available, in which case the the system replaces this variable with blank text.)

          • {fileLocation} - The file URL.

          Note
          The system replaces a variable with blank text if there is no value assigned to the variable or if an invalid variable name appears within the braces.
        3. Click SAVE to complete the changes.

  3. If you chose Revoke Access for Action:

    • If you chose Google Drive for the Platform, select from the following options:

      • Remove public link: Removes any file link that has public exposure.

      • Remove share exclusively with internal users: Removes all internal users of files that were shared with few specific internal users.

      • Remove share with any external user: Removes all external users. (External users are not part of the organization domain)

      • Remove specific shares: Entered email addresses or group email addresses are removed.

      • Remove org-wide share link: Removes any share permission with the entire organization.

      • Remove owner: Removes the file owner and transfers ownership to a new email address.


      Action section with options to select enforcement actions for files that violate rule's criteria
    • If you chose Microsoft 365 Sharepoint Online or Microsoft 365 OneDrive for the Platform, select from the following options:

      • Remove public link: Removes any file link that has public exposure.

      • Remove org-wide share link: Removes any share permission with the entire organization.


      Action section with options to select enforcement actions for files that violate rule's criteria
    • If you chose Box for the platform, select the following option:

      • Remove public link: Removes any file link that has public exposure.


      Action section with options to select enforcement actions for files that violate rule's criteria
    • If you chose Dropbox for the platform, select from the following options:

      • Remove public link: Removes any file link that has public exposure.

      • Remove share exclusively with internal users: Removes all internal users of files that were shared with few specific internal users.

      • Remove share with any external user: Removes all external users. (External users are not part of the organization domain.)

      • Remove specific shares: Entered email addresses or group email addresses are removed.

      • Remove org-wide share link: Removes any share permission with the entire organization.


      Action section with options to select enforcement actions for files that violate rule's criteria
  4. If you chose Box , Microsoft Office 365 Sharepoint Online , or Microsoft Office 365 OneDrive for platform, you can choose from AdvancedSettings under Action.

    • For Microsoft Office 365 Sharepoint Online or Microsoft Office 365 OneDrive, you can specify MIP file labels that Umbrella will apply to files that match the rule. Enter the key (and optionally the value) for each label to apply.

      Action section with options to select enforcement actions for files violating criteria and advanced settings to add MIP File Labels
    • For Box:

      • You can specify MIP file labels that Umbrella will apply to files that match the rule. Enter the key (and optionally the value) for each label to be applied.

      • You can also select from the list of sensitivity labels that have been created for your Box tenant. You may select any one of the labels displayed.

        Note
        If you create new sensitivity labels for your Box tenant, it may take up to four hours for them to appear in the Secure Access interface. Also be aware that within the Box application, these labels are referred to as classification labels.
        Action section with options to select enforcement actions for files violating criteria and advanced settings to add Sensitivity Labels

Create a DLP SaaS API Rule Step 10 — Enable and Configure Email Notifications

This is the tenth and final step in the process to add a SaaS API rule to a DLP policy, in which you may optionally select to configure and enable email notifications to send users when data matches the rule.

Procedure

  1. Under User Notifications click the User Notifications toggle button to enable and configure an email notification to be sent to any of the following users:

    • The owner of the file associated with a rule violation (for Outlook, this is the sender of the email).

    • The user who performs an action that triggers a rule violation (for Outlook, this is the sender of the email).

    • The manager of the user who triggered the violation.

    • Any email address(es) of your choice.

    You can use a default email template provided by the system, or create your own custom template.

    Note
    If you select the Salesforce platform and the quarantine response action, User Notifications will be automatically enabled. Quarantine notifications will be sent to the file owner and the initiator of the event that triggered the quarantine action.
    User Notifications page with an option to enable user notifications
    1. Click the User Notifications toggle button.

      Enabling user notifications
    2. Select one or all of the following email recipients:

      • File owner - The owner of the file associated with the rule violation

      • Event actor - The user who performs an action that triggers the rule violation

      • Actor's manager—The manager of the user who triggered the violation.

        This feature is available only when email addresses for reporting managers in Active Directory are synchronized for DLP notifications. As a result, the Actor's manager checkbox appearance varies depending upon the current configuration settings when viewing a rule:

        Checkbox Appearance Meaning
        The Sync Enabled Email Disabled interface.

        Reporting manager’s email sync is enabled, but notifications to the actor’s manager are not selected for this rule.

        Email notifications for rule violations will not be sent to the event actor’s manager.

        The Sync Enabled Email Enabled interface.

        Reporting manager’s email sync is enabled, and notifications to the actor’s manager are selected for this rule.

        Email notifications for violations will be sent to the event actor’s manager.

        The Sync Disabled Email Disabled interface.

        Reporting manager’s email sync is disabled, and notifications to the actor’s manager are not selected for this rule.

        Email notifications for rule violations will not be sent to the event actor’s manager.

        The Sync Disabled Email Enabled interface.

        Reporting manager’s email sync is disabled, and notifications to the actor’s manager are selected for this rule.

        Email notifications for rule violations will not be sent to the event actor’s manager.

      • Custom recipient—Allows you to specify email addresses of your choice. To use this option, select the Custom recipient checkbox, and enter one or more valid email addresses in the text box. These addresses will receive notifications whenever this rule is violated.

        Note
        If you have selected a Salesforce Commerce tenant, Custom recipient is the only option available.
    3. Choose the email template:

      To Use the Default Email Template:

      1. Click Default Email.

      2. To preview the content of the email that will be send to users, click on Preview Default Email. You can review the email subject line and text, but you cannot change it.

        Preview Default Email section displaying the email subject line and content
      3. (Optional) To send a test copy of the email to an address of your choosing, enter an address in Preview Test Email and click SEND PREVIEW to send the message. (By default the system uses the email address of the logged in user.)

      4. Click CLOSE to return to the Data Loss Prevention Policy page.

      To Use a Custom Email Template:

      1. Click Custom Email.

      2. From the drop-down list, select an existing custom template, or choose CREATE CUSTOM TEMPLATE. If you select an existing custom template, you can click Preview and Edit Custom Email to review and change the template.

        User Notifications page showing an option to create new email template
      3. When you choose to create or edit a custom template for email notifications of policy violations you will see one of these two dialogs, which are almost identical:

        View New Custom Email Template and Edit Custom Email Template pages

        The Edit Custom Email Template includes a DELETE link which you can use to delete a custom template that is no longer needed. You may not delete a template that is in use by any rule.

        To create a new template or change an existing template:

        1. Enter a unique Custom Email Template Name.

        2. Enter an Email Subject Line.

        3. Enter the text of the email in the Email Body text box.

          The email text can include the following variables, which you must enclose in braces ( {} ):

          • {eventId} - The unique identifier the system generates for the policy violation event.

          • {detectedTimestamp} - The date and time the violation was detected, formatted as shown in this example: "Oct 1, 2023 at 14:04 UTC"

          • {actorName} - Name of the user whose action triggered the violation. (The system gets this from the tenant associated with the violation. Depending on application and file settings, this information may not be available, in which case the the system replaces this variable with blank text.)

          • {actorEmail} - Email address of the user whose action triggered the violation. (The system gets this from the tenant associated with the violation. Depending on application and file settings, this information may not be available, in which case the the system replaces this variable with blank text.)

          • {fileName} - Name of the data file that triggered the violation.

          • {ruleName} - Name of the rule that was triggered.

          • {matchedClassifications} - The data classifications associated with the violation. (See Manage Data Classifications.)

          • {destination} - The application or platform type of the tenant associated with the violation. (E.g., Google Drive or One Drive; see Manage Tenant Controls.)

          • {fileOwnerName} - Name of the file owner. (The system gets this from the tenant associated with the violation. Depending on application and file settings, this information may not be available, in which case the the system replaces this variable with blank text.)

          • {fileOwnerEmail} - Email address of the file owner. (The system gets this from the tenant associated with the violation. Depending on application and file settings, this information may not be available, in which case the the system replaces this variable with blank text.)

          • {fileLocation} - The file URL.

          Note
          The system replaces a variable with blank text if there is no value assigned to the variable or if an invalid variable name appears within the braces.
        4. (Optional) To send a test copy of the email to an address of your choosing, enter an address in Preview Test Email and click SEND PREVIEW to send the message. (By default the system uses the email address of the logged in user.)

        5. Click SAVE to return to return to the Data Loss Prevention Policy page.

  2. Click Save. All fields must have options selected to save.