Enterprise DLP
Create a Service Account for EDM Dataset Uploads
Table of Contents
Expand All
|
Collapse All
Enterprise DLP Docs
Create a Service Account for EDM Dataset Uploads
Create a service account for Enterprise Data Loss Prevention (E-DLP) on Strata Cloud Manager to
securely upload your EDM datasets to Enterprise DLP.
| Where Can I Use This? | What Do I Need? |
|---|---|
|
Or any of the following licenses that include the Enterprise DLP license
|
Before you configure connectivity between the EDM CLI app and Enterprise Data Loss Prevention (E-DLP), you must create an Enterprise DLP service account on Strata Cloud Manager.
- Access the Common Services Identity and & Access settings and add a Service Account to generate the Client ID and Client Secret.
- New Service Account
- Enterprise DLP uses the Client ID and Client Secret to authenticate and connect the EDM CLI app.When you create the Service Account, the Client ID and Client Secret are displayed in the Client Credentials. You can manually copy the Client Credentials or Download CSV File to download the Client Credentials in plaintext locally to your device.
- Assign a role to the service account to upload EDM datasets to Enterprise DLP. EDM dataset uploads fail if the service account does not have a role assigned with write access privileges to Enterprise DLP.You can assign any predefined role on Strata Cloud Manager or a predefined or custom role specific to Enterprise DLP on Strata Cloud Manager.If you're creating a service account only for EDM dataset uploads, Palo Alto Networks recommends assigning the DLP Policy Administrator role for the Enterprise DLP app. The service account uploading EDM datasets to Enterprise DLP requires write privileges to successfully upload.
- Existing Service AccountYou can reset the Client Secret for an existing service account if it's been lost.Skip this step if you have the Client ID and Secret pair for an existing service account.Resetting the Client Secret for an existing service accounts impacts all existing services using the old Client Secret. You must reconfigure any applications, integrations, and authentication mechanism that use the previous Client ID and Secret pair for this service account if you reset the Client Secret.
- Log in to Strata Cloud Manager.
- Select System SettingsIdentity & Access Management.
- Select All IdentitiesAll Service Accounts to sort the Access Management list by service account.
- Locate the service account and click the edit icon in the Action column.
- Click Back in the Assign Roles screen.
- Reset Client Secret. You're prompted to confirm that resetting the client secret impacts all currently configured applications, integrations, and authentications using the current Client Secret.
- Strata Cloud Manager generates a new Client Secret. You can manually copy the Client Credentials or Download CSV File to download the Client Credentials in plaintext locally to your device.
- Edit the Role for the service account if needed.
- Submit.
Continue based on the mode you plan to use to upload EDM datasets:- Uploads Using a Config File—Configure EDM CLI App Connectivity to Enterprise DLP
- Uploads Using Interactive Mode—Create and Upload an Encrypted EDM Data to Enterprise DLP in Interactive Mode