Configure DLP end-to-end
Set up Cortex Data Loss Prevention in Cortex XSIAM, including endpoint settings, browser extensions, applications, and data-in-motion rules.
This section describes how to get up and running with Cortex DLP, including how to define Endpoint DLP settings, add applications and application groups, and define data-in-motion rules.
Onboarding checklist for DLP
We recommend following these steps to ensure all requirements for setting up DLP are met, protecting sensitive data, and maintaining compliance with your organization's standards.
Configure endpoint DLP settings in Cortex XSIAM
Configure the endpoint DLP settings to manage your organization's DLP policies.
In Default Actions & Thresholds, there are two parts.
Data-in-motion default action and threshold configurations:
Select the fallback policy for instances when the DLP process fails or times out:
Allow file movement (fail-open): Allows the file transfer, preventing service interruption.
Block file movement (fail-close): Blocks the file transfer.
Auto disablement of rule threshold
This setting refers to rule suppression. When the number of hits exceeds the set number, the rule is disabled.
Click Reset to revert to the default threshold as configured in the system.
If a rule was suppressed, you can view details in Settings → Management Audit Logs.
For Corporate Account Domain, add the web application resources.
Cortex Data Security Extension (Web DLP Channel): This option lets you manage browser extension installation and removal. Configure Chrome and Edge separately using one of the two modes. By default, MDM deploys the extension to selected endpoints. See the earlier instructions for installing the DLP browser extension.
MDM: This default option distributes and installs the extension using a supported management tool, such as Microsoft Intune for Windows or JAMF for macOS.
After installation, the agent communicates with the extension to activate endpoint DLP.
Forced activation (by XDR): This option installs a missing browser extension automatically. The endpoint must be associated with a domain.
Disable: The extension is disabled.
In the End User Dialog section, add the default pop-up message for these events:
Enable User Interaction
Reporting Mismatch (FP)
Rule Override
For each option, enter the default text to display in the end-user dialog.
In the Title, enter the default dialog name.
In the Body, enter the dialog message. You can use the system default text. This also applies to Reporting Mismatch and Rule Override.
In the Admin Email Link field, enter the default admin email to include in the body.
In the Dialog Main Button Label, enter the text for the button that closes the window.
Install the DLP browser extension on your endpoint
To activate DLP, you must install the CDSx browser extension on your endpoint. This extension works with the DLP agent to monitor and enforce security policies on web-based activities.
Note
Extensions are not enabled in Incognito or InPrivate modes in Chrome and Edge. It is recommended to disable these modes in the organization.
Enabling the extension in Cortex XSIAM
Navigate to Modules → Data Security → Endpoint Data-in-Motion Rules → Endpoint DLP Settings.
For Cortex Data Security Extension (Web DLP Channel), select the browser extension activation mode. See Configure endpoint DLP settings for more information.
Create endpoint applications in Cortex XSIAM
An effective data loss prevention (DLP) system allows an organization to define specific applications as sensitive. This enables the system to monitor and control the transmission of critical information, preventing its unauthorized release.
When creating a data-in-motion rule, you can specify the source of the sensitive data, but you must provide the intended destination. For the source and destination for the data-in-motion rule, you must select the relevant application groups ( custom local application group). The application groups comprise of predefined endpoint applications as defined by Palo Alto (local application).
Predefined applications are indicated by Created by: Palo Alto Networks in the All Applications table. For predefined applications, you do not see details such as URLS/Domains, Process names, or signers. You cannot edit or delete these applications.
The user can only create a Custom Web Application.
Endpoint application type:
After creating the application, you can select it from the application groups.
Predefined local applications: The following apps and services are supported.
FTP, SFTP and FTPS apps:
FileZilla
OpenSSH
WinSCP
SSH and RDP apps:
PuTTY
Custom Web application: In DLP, a web application refers to any software accessed via a web browser (e.g., cloud services, webmail, social media). Web DLP focuses on inspecting and controlling sensitive data as it travels over these internet-based channels, preventing unauthorized sharing or exfiltration. Palo Alto Networks has its own predefined list of applications. The Palo Alto predefined web applications cannot be edited or removed.
Create endpoint application groups in Cortex XSIAM
Data-in-motion rules require defining both a source and a destination, which can be specified using your predefined endpoint application groups.
Choose the relevant application group type.
Custom Local Application Group: Select the available options from the predefined local applications.
For example: Unsanctioned chat apps.
Custom Web Application Group: Select the available options from the custom local applications. You can create a new web application.
For example: AI chatbots.
Create data-in-motion rules in Cortex XSIAM
You can create data-in-motion policies to identify, control, and protect sensitive information as it moves across networks, between systems, or to devices.
Each rule defines an action, Allow, Block, or Report, from a specified source to a web destination. Rule conditions must include the channel destination, data profile, and type of data being accessed or moved. You can also configure responsive user dialogs for enforced events, which can be customized per rule.
To create a data-in-motion rule:
In Modules → Data Security → Endpoint Data-in-Motion Rules → Data-in-Motion Rules, click Create New Rule.
On the General page:
Enter a unique name and description.
Choose the Action to implement when the rule criteria are met, such as blocking the transfer or notifying relevant parties.
Select the Action for Partial Classification to implement when partial classification occurs. Partial classification refers to a situation in which the classification process is incomplete, such as due to a timeout or a classification failure.
Select the Severity of the rule you are creating.
The Informational action enables logging an activity without interfering with the user’s workflow.
Enter a Raised Issue Name to use for the issue resulting from policy breaches.
Select to Disable/Enable Rule as required.
On the Context & Data page:
For Source, select the Custom Web Application Groups.
The source is the origin of the data, whether it resides on a local drive (such as a PDF on a laptop) or within a web application (such as a file in OneDrive).
Without a defined source, this rule applies to every file by default. You can make the policy more targeted by selecting a specific source.
Note
Third-party application behaviour:
When a file upload is blocked, the local application may display its own generic error message in response to the DLP restriction. In similar cases, some third-party applications might still proceed by sending a dummy file or an error placeholder instead of the actual data.
For Destination, select the relevant Application Groups. See the earlier instructions for creating endpoint application groups.
Selecting Allow corporate accounts users to upload lets corporate account users bypass the Block rule action and upload data from the web application.
USB Channel: Select File Write/Copy to USB to enforce the rule on the USB device.
For Data Scope, select the relevant Data Profile.
Note
To maximize data security, if you use Microsoft Purview for extensive manual and automated file classification tagging and are looking to integrate those labels directly with the DLP policies to trigger protective actions based on a file's sensitivity, refer to How to use information protection labels in Cortex Cloud Data Security.
On the Target page:
For Rule Target, select the endpoints to which this rule will apply.
On the User Interaction page, you can add the default pop-up message for each of the following events.
For End User Dialog, toggle ON/OFF to manage whether users see a message when the policy is violated.
In the Title, enter the default name for the dialog.
In the Body, enter the message to display in the dialog. You can choose to use the system's default text. This is also relevant for Reporting Mismatch and Rule Override.
If enabled, the Rule Override allows the user to override the block policy and temporarily retry the operation (to move the file again) to complete the action. The user's response is recorded as part of the Issue.
In the Admin Email Link, enter the default admin email to be included in the body.
In the Dialog Main Button Label, enter the text to use for the button to close the window.
Click Next to create the rule.
From the Data-In-Motion Rules table, click Save or move the rule down to change its priority, then click Save.
Rule priority in Cortex XSIAM
Cortex XSIAM processes these rules sequentially from top to bottom. To ensure the correct outcome, place Allow rules above Block rules.
As soon as a first match is found for a data movement event, that rule's action is applied, and no other rules are evaluated for that specific event. Each matched event creates an Issue, and the total number of issues appears as Hits in the rules table.
Modify rule priority by dragging rules. If a conflict arises while setting a rule's priority, for example, if another user updates the policy simultaneously, Cortex saves the rule as a draft to prevent loss of your work.
Example: Creating a data-in-motion rule
An employee at Company X sends an attachment containing financial information to another employee's personal email address. This action violates the company’s data handling policy.
To help prevent this, you can create a data-in-motion rule with the following configuration:
Rule Name
Provide a descriptive name for easy referencing.
Prevent Financial Data Transfer
Action
Specifies how data movement is controlled. Possible actions are: Block, Allow, or Report.
Block
Partial Classification
Select a fallback action if classification fails or exceeds a time threshold.
Block
Severity
Choose the severity level that the Issue will trigger. Possible options are: Critical, High, Medium, Low, Informational.
High
Raised Issue Name
The name appears on the Issues page when filtering for Endpoint DLP Issues.
Blocked Financial File Transfer
Source
The web application group the data transfer originates from. You can create and manage these custom groups to suit your preferences.
drive.google
Destination
Choose where the data is moving to. Possible options are: None, Any, Specific web application group.
Web Application Group
Local Application Groups
Select apps through which users might transfer sensitive data.
Zoom, Slack, TeamViewer, and WhatsApp.
Data Profile
Data Profiles are templates that define what kind of sensitive data to detect. Select the data profile to which the rule applies.
For more information, see How to create and validate a custom data profile.
PHI, CCN (Credit Card Numbers), Financial, and PII.
Last updated
Was this helpful?
