Create a SaaS Security Policy Recommendation to Leverage Enterprise DLP
Focus
Focus
Enterprise DLP

Create a SaaS Security Policy Recommendation to Leverage Enterprise DLP

Table of Contents
Use an Enterprise Data Loss Prevention (E-DLP) data profile in a SaaS Security Policy Recommendation on Strata Cloud Manager.
On May 7, 2025, Palo Alto Networks is introducing new Evidence Storage and Syslog Forwarding service IP addresses to improve performance and expand availability for these services globally.
You must allow these new service IP addresses on your network to avoid disruptions for these services. Review the Enterprise DLP Release Notes for more information.
Where Can I Use This?What Do I Need?
  • NGFW (Managed by Panorama or Strata Cloud Manager)
  • Prisma Access (Managed by Panorama or Strata Cloud Manager)
  • Enterprise Data Loss Prevention (E-DLP) license
    Review the Supported Platforms for details on the required license for each enforcement point.
Or any of the following licenses that include the Enterprise DLP license
  • Prisma Access CASB license
  • Next-Generation CASB for Prisma Access and NGFW (CASB-X) license
  • Data Security license
A SaaS policy rule recommendation is required to leverage the Enterprise Data Loss Prevention (E-DLP) data profile in SaaS Security. In order to scan for and render a verdict on sensitive data you for which you want to prevent exfiltration, you must assign the data profile to the SaaS Security policy rule recommendation.
  1. Log in to Strata Cloud Manager.
  2. Create data patterns and a data profile to define the match criteria for sensitive data you want to detect.
  3. Select ManageConfigurationSecurity ServicesSaaS SecurityDiscovered AppsPolicy Recommendations and Add Policy.
  4. Create the SaaS Security policy rule recommendation.
    1. Configure the policy rule recommendation as needed.
      Review how to create policy rule recommendations for SaaS Security for more details.
      See the Supported Applications for more information on which applications Enterprise DLP supports.
    2. For the Data Profile, select the data profile you created in the previous step.
      Only one data profile can be associated with a policy rule recommendation.
    3. Save.