Provides instructions for completing the Add a SaaS API Rule to the Data Loss Prevention Policy workflow in Cisco Secure Access. Configure an SaaS API Rule to set the criteria as to what triggers the scanning.
Configure an SaaS API Rule to set the criteria as to what triggers the scanning. As files in the selected tenant are scanned upon content change and context (sharing) change, Secure Access assesses the file against this rule's criteria. If a match is made, this rule's action is immediately enforced. If Secure Access detects a violation, the offending file is listed in the Data Loss Prevention Report.
An SaaS API Rule must have at least one of the following two criteria defined:
-
Data Classifications — Include files that match data classification of your own making or a built-in data classification provided by Secure Access.
-
File Labels — Include files that have specific file label names configured in the value of the files' document properties, or include files that have no labels configured. Secure Access scans for file labels on the following file types: .doc, .pdf, .rtf, .xls, .ppt, .odp, .ods, .odt, .pptx, .xlsx, .docx, and .eml.
-
Microsoft Information Protection (MIP) labels are used to classify and protect data in Microsoft 365 files.
-
Titus labels are a third-party classification system provided by Fortra that can provide additional classification and protection features for Microsoft 365 files.
-
Microsoft Office Sensitivity Labels are a specific type of MIP label focused on indicating the sensitivity of data within Microsoft 365 files.
-
For AWS S3, Azure Storage, Confluence, Dropbox, GitHub, Google Drive, Jira, ServiceNow, Slack, and Webex Teams you can apply filters for MIP and Titus labels.
-
For Microsoft 365 and Box you can apply filters for MIP and Titus labels, and Microsoft Office Sensitivity Labels. (Within the Box application, sensitivity labels are referred to as classification labels.)
-
For Salesforce you can apply filters for Microsoft Office document properties, or Adobe PDF document properties.
-
Changes to the share permissions or other options on a folder does not trigger a scan of the contents of that folder.
SaaS API rules configured to scan Microsoft Outlook messages scan only outgoing messages. Violations can be triggered by material found in the email subject, message body, or attachments; a single email message may trigger multiple violations: one for the message subject and body, and one for each attachment.
Procedure
-
Create a DLP SaaS API Rule Step 1 — Establish General Settings
-
Select Users whose files are included or excluded from scanning for this rule
-
Configure Exposure Settings for processing the files to search for data violations
-
Enable and configure an Email Notifications to be sent to users when a violation occurs




