All Products
Search
Document Center

Secure Access Service Edge:Monitor outbound file transfers to ensure data security

Last Updated:Mar 31, 2026

The Data Loss Prevention (DLP) feature of SASE monitors files that employees send through workplace channels — such as instant messaging, email, and cloud drives — detecting sensitive content in real time and blocking transfers when a policy requires it. This topic explains how to create a detection policy, review sensitive file records, and manage storage settings.

Prerequisites

Before you begin, make sure you have:

How it works

SASE identifies sensitive files based on the characteristics of sensitive data elements. Data templates are built from data elements, data types, and sensitivity levels. Detection policies then apply those templates — along with response actions and scope settings — to flag or block outbound transfers.

SASE includes built-in data templates covering common company data, customer data, and personal data. If those templates don't meet your needs, create custom data elements and build templates from them.

Create a detection policy

  1. Log on to the Secure Access Service Edge console.

  2. In the left navigation pane, choose Data Protection > Policy Center.

  3. On the Outbound Transfer Management tab, click Create Policy.

  4. In the Create Policy panel, configure the following parameters, then click OK.

Policy information

ParameterDescription
Policy nameThe name of the policy.
Policy descriptionA description of the policy.
Risk levelThe severity level of outbound activity this policy targets. Choose one of four levels: Extremely High (resigning-employee groups, extremely high-risk groups, or L4 files), High (high-risk groups or L3 files), Medium (medium-risk groups or L2 files), or Low (all outbound transfers, for audit purposes).
ActionWhat SASE does when the policy is triggered: Audit Only, Audit and Prompt, Block and Notify, or Block Only. If you select Block and Notify or Block Only, also select a block type (see the block types table below).
Source file retentionWhether to retain the source file information.
Retain screenshot fileWhether to retain screenshot evidence.
StatusEnabled puts the policy into effect immediately. Disabled saves the policy without activating it.

Data identification rule settings

ParameterDescription
Data identification ruleSelect a configured identification rule. To create one, see Configure detection rules for outbound file classification and categorization.
Transmission channelThe channels to monitor. A transfer through any selected channel triggers detection. See Supported transmission channels below.

Effective scope

ParameterDescription
User groupThe user group to which the policy applies.

Block types (applies only when Action is Block and Notify or Block Only)

Block typeBehavior
Block allThe SASE app blocks and audits all outbound file transfers in real time.
Intelligently blockThe SASE app scans and labels files on endpoints in advance, then blocks only transfers of files identified as sensitive. Before the endpoint scan completes, all outbound transfers are blocked by default. Scan and labeling results are not reported to the cloud.

Supported transmission channels

The Transmission channel parameter supports the following channel types. Select one or more based on your monitoring requirements.

CategoryChannels
Instant messagingInstant Messaging (Software), Instant Messaging (Web)
EmailEmail (Software), Email (Web)
Cloud storageCloud Drive (Software), Cloud Drive (Web)
Cloud notesCloud Notes (Software), Cloud Notes (Web)
Code hostingCode Hosting (Software), Code Hosting (Web)
AI / LLMLarge Language Model (Software), Large Language Model (Web)
File transferFTP Channel, Network Share
DevicesMobile Storage, Print, Remote Desktop
WebCloud Blog, Social Media
OtherOthers

View sensitive file detection statistics

After you create a policy, SASE automatically detects outbound files and generates statistics. On the Sensitive Behavior Detection page, the Sensitive Behavior Identification area shows outbound transfer data for the last 30 days, last 7 days, or last 24 hours — including the top five types of sensitive files and their proportions.

Sensitive file detection covers files up to 60 MB. Files larger than 60 MB are not scanned for content, but may trigger anomalous activity records (see View anomalous activity records).
  1. In the left navigation pane, go to Data Protection > Sensitive Behavior Detection.

  2. In the Sensitive Behavior Identification area, view sensitive behavior statistics for the selected time period.

image.png

View sensitive file outbound records

SASE records the content of outbound sensitive files up to 30 MB in size. Use these records to verify what data was sent.

  1. On the Sensitive Behavior Detection page, view the list of sensitive files sent by employees.

image.png
  1. In the Details column, click Actions. On the Outbound Transfers of Sensitive Files tab, review the employee's data.

image.png

The tab includes the following sections:

SectionContent
Time period ①Set a custom time range for the query.
Data statistics ②Aggregate counts by file count, transfer channel, and file size.
Sensitive file list ③Per-file details: sensitivity level, data type, matched data template, and number of hits. Filter or sort the list as needed. Click Download to save a file locally. Click Details to open the Details panel, which includes Data Flow, Key Information, Sensitive Message, Screenshot Evidence, Hit Policy, Office Terminal, Outbound Transfer Channel, and Account Information.

View anomalous activity records

SASE creates anomalous activity records for transfers it cannot fully scan. Pay close attention to employees who trigger these events — the files may contain sensitive data that requires manual review.

Anomalous activity typeTrigger condition
Large outbound fileAn employee sends a file larger than 30 MB outbound, online or offline.
File copied to peripheralAn employee copies a file smaller than 30 MB to a peripheral device, online or offline.
Outbound threshold exceededA single user sends files totaling more than 1 GB in an offline session.
  1. On the Sensitive Behavior Detection page, review the anomalous activities triggered by employees.

image.png
  1. Click the value in the Abnormal event column. On the Abnormal events tab, view the anomalous activity records for that user. Alternatively, click Actions in the Details column to open the same Abnormal events tab.

image.png

Configure storage duration

By default, SASE retains detection results for 7 days. To extend retention to 30 days, activate the log storage service. For pricing, see Billing overview.

Manage sensitive file storage space

SASE provides 1 GB of free sensitive file storage by default.

  • To purchase additional storage, click Activate in the upper-right corner. For pricing, see Billing overview.

  • To stop storing new sensitive files, turn off the storage switch in the upper-right corner. Existing files are not deleted.

  • To delete stored files, click Clear in the upper-right corner and choose Clear by time range or Clear all.

For custom storage space (available in the DLP edition), see Configure custom storage settings.

What's next