Configure SaaS Security to Inspect for Contextual Secrets
Focus
Focus
Enterprise DLP

Configure SaaS Security to Inspect for Contextual Secrets

Table of Contents

Configure SaaS Security to Inspect for Contextual Secrets

Configure Enterprise Data Loss Prevention (E-DLP) to allow SaaS Security to inspect for contextual secrets.
Where Can I Use This?What Do I Need?
  • NGFW (Managed by Panorama or Strata Cloud Manager)
  • Prisma Access (Managed by Panorama or Strata Cloud Manager)
  • Enterprise Data Loss Prevention (E-DLP) license
    Review the Supported Platforms for details on the required license for each enforcement point.
Or any of the following licenses that include the Enterprise DLP license
  • Prisma Access CASB license
  • Next-Generation CASB for Prisma Access and NGFW (CASB-X) license
  • Data Security license
To configure SaaS Security to inspect for contextual secrets, you must leverage an Enterprise Data Loss Prevention (E-DLP) data profile containing data pattern match criteria that looks for passwords and credentials. After the data profile is enabled, it must be associated with a policy rule recommendation.
  1. Log in to Strata Cloud Manager.
  2. Select ManageConfigurationSaaS SecuritySettingsData Profiles and verify that the predefined Secrets and Credentials data profile is enabled.
    (Optional) Instead of using the predefined data profile, you can create a data profile and add the predefined ML-based Application Credential data pattern. Adding a custom data pattern with regex match criteria to a custom data profile is not supported for inspection for contextual secrets.