Policies to Detect Threats
Focus
Focus
SaaS Security

Policies to Detect Threats

Table of Contents

Policies to Detect Threats

Learn about the policy rules in Behavior Threats for identifying potential threats.
Where Can I Use This?What Do I Need?
  • Strata Cloud Manager
  • Data Security license
Or any of the following licenses that include the Data Security license:
  • CASB-X
  • CASB-PA
Policies instruct Behavior Threats to detect suspicious user activities, which might represent a threat to your organization. Each policy identifies a specific type of user behavior that might represent a threat, such as a user accessing SaaS apps from an unusual location or performing bulk download operations. When you enable a policy, Behavior Threats detects the suspicious activity and creates a threat incident for that user. Policy violations contribute to a user's overall risk score based on admin-configured weights that you assign to each policy and the ML baseline.
Behavior Threats provides the following types of policies:
  • Dynamic Policies—Policy rules use historical data and machine learning to identify suspicious user activity. For these policy rules, Behavior Threats examines historical user data to determine a baseline for each user in your organization. This baseline is derived from the user's past actions and also from the actions of other users in your organization. From this baseline, Behavior Threats identifies the most anomalous user actions as threat incidents.
  • Static Policies—Policy rules use preconfigured thresholds that Behavior Threats uses to detect suspicious user activity. Behavior Threats does not create a baseline of user activities or use machine learning to detect threat incidents for these policy rules. Instead, Behavior Threats records a threat incident if user actions reach the preconfigured threshold for the policy.
By default, all Behavior Threats policy rules are enabled. When you disable a policy:
  • No new incidents — Behavior Threats stops detecting and generating incidents for that specific behavioral anomaly type.
  • Existing incidents remain — previously generated incidents aren't deleted (they remain in the incident history).
  • No risk score contribution — since no new incidents are created, the policy stops contributing to user risk scores going forward. Existing contributions from prior incidents will decay over time per the decay logic.
  • Audit log entry — disabling a policy is recorded in audit logs.