Describes Discovery Scan in Cisco Secure Access. Discovery Scan inspects the content of all files in the tenant that are modified over the selected date range.
Discovery Scan inspects the content of all files in the tenant that are modified over the selected date range. As files in the selected tenant are scanned upon content change and context (sharing) change, Secure Access assesses the file. If Secure Access detects a violation, the offending file is listed in the Data Loss Prevention Report.
This topic walks you through how to initiate a scan and how to cancel an ongoing scan.
A discovery scan must be triggered around 24 hours after tenant authorization as the system evaluates and enumerates the users in the organization. Any triggering beforehand might not include all users. Secure Access performs discovery scans on files of up to 50 MB. For each file, the scan extracts up to the first 5 MB of plain text from the file, and scans that data for violations.
Prerequisites
-
You must authenticate a tenant for at least one of the platforms Secure Access supports for SaaS API Data Loss Prevention. For more information, see Manage SaaS API Data Loss Prevention.