Configure SASE (Secure Access Service Edge) data protection to monitor outbound transfers of sensitive data in real time, identify data breach risks, and secure your corporate data.
Use cases
-
Sensitive outbound file transfer detection: Prevent employees from transferring sensitive files through instant messaging tools, email, cloud storage services, and other channels.
-
View audit logs: Record and analyze sensitive outbound file transfer activity to identify potential data breach risks.
Prerequisites
-
You have purchased the Data Protection for Internet Access edition of SASE. For more information, see Billing overview of SASE and Getting started.
-
The SASE App installed on your corporate endpoints is version 4.3.1 or later.
Procedure
Step 1: Add an identity source
An identity source authenticates enterprise employees. SASE supports third-party and self-managed identity sources, including LDAP, DingTalk, WeCom, Lark, IDaaS, and custom identity sources. If your business uses multiple identity sources, you can configure them all to use SASE with different identities.
This topic uses a custom identity source as an example.
Log on to the Secure Access Service Edge console.
-
In the left-side navigation pane, choose .
-
Click the Identity synchronization tab, and then click Create IdP.
-
In the Create IdP panel, select Custom IdP, and then click Configure.
-
In the Basic Configurations section, configure the IdP Name and IdP Status parameters as described in the following table. Then, click Next.
Parameter
Description
IdP Name
The name of the custom identity source.
Must be 2 to 100 characters in length and can contain Chinese characters, letters, digits, hyphens (-), and underscores (_).
IdP Status
The status of the identity source. Valid values:
-
Enabled: If no other custom identity source is enabled, you can enable this identity source.
-
Closed: If another custom identity source is already enabled, you can set the status of the new one to Disabled. To enable this new one, you must first disable the other custom identity source.
ImportantIf you disable a custom identity source, end users cannot use the SASE App to access internal applications. Proceed with caution.
-
-
In the Logon Settings section, configure the logon methods.
Parameter
Description
PC Logon Method
Supports Logon with Account and Password and Password-free Logon.
-
When using account and password logon, you can enable Two-factor Authentication. Valid values:
-
OTP-based Authentication: If you enable this option, you must select an OTP Mode. The following modes are supported:
-
Allow the SASE mobile app to display tokens: SASE has a built-in OTP and requires employees to install the SASE mobile app.
-
Allow third-party app tokens: Ensure the OTP client's clock is synchronized. Standard OTP applications, such as the Alibaba Cloud app, are supported.
-
Allow enterprise-owned tokens: To use your in-house OTP solution, contact technical support for assistance with configuration.
-
-
Verification Code-based Authentication: Supports verification codes sent via SMS and email. Ensure that each user in the identity source has a configured mobile phone number or email address.
-
-
When using password-free logon, users must first download and log on to the SASE mobile app, and then scan a QR code to authenticate.
Mobile Device Logon Method
Supports Logon with Account and Password and Fingerprint or Face Recognition.
-
When using account and password logon, you can enable Two-factor Authentication. Valid values:
-
OTP-based Authentication: Before you enable OTP-based Authentication, you must enable OTP authentication for PCs and select either Allow Tokens on Third-party Applications or Allow Enterprise-owned Tokens. The token configuration for mobile devices mirrors the one for PCs.
-
Verification Code-based Authentication: Before you enable Verification Code-based Authentication, ensure that each user in the identity source has a configured mobile phone number or email address.
-
-
When using fingerprint or face recognition, users must still enter their account name and password during their first logon to the SASE App.
-
-
Click OK to save the configuration.
Step 2: Add a user group
Log on to the Secure Access Service Edge console.
-
In the left-side navigation pane, choose .
-
On the User Group Management tab, click Create User Group.
-
In the Create User Group panel, enter the user group information as described in the following table.
Parameter
Description
User Group Name
The name of the user group.
Description
The description of the user group.
Group Scope
The scope of the user group. Valid values:
-
Organizational Structure: When you select Organizational Structure, the existing Organizational Structure information is displayed below. You can select the corresponding structures as needed.
-
Account Name: When you set this to Account Name, the Configure Account Name input box is displayed below.
-
Email Address: When you set this to Email Address, the Configure Email Address input box is displayed below.
-
Mobile Phone Number: When you select Mobile Phone Number, a Configure Mobile Phone Number input box is displayed below.
Configure Relationship
The relationship for the user group. Valid values:
-
Equal To
-
Not Equal To
-
-
Click OK.
Step 3: Review data classification rules
SASE provides built-in identification rules to detect common types of corporate, customer, and personal data. Review these rules to understand their scope. You can also create custom identification rules to detect specific data, such as outbound file transfers that contain personal resumes.
Log on to the Secure Access Service Edge console.
-
In the left-side navigation pane, choose .
-
On the tab, go to the Data Category section on the left to view the details of the built-in identification rule for personal resumes.
Step 4: Configure an outbound file transfer policy
The sensitive file detection feature of SASE identifies sensitive files based on data elements. SASE combines data elements, data types, and sensitivity levels into data templates. These templates, together with response actions, form policies that detect when employees transfer sensitive files.
Log on to the Secure Access Service Edge console.
-
In the left-side navigation pane, choose .
-
On the tab, click Create Policy.
-
In the Create Policy panel, create an outbound file transfer policy as described in the following table. Then, click OK.
Configuration item
Description
Policy Information
Policy Name
The name of the policy.
Policy Description
A description for the policy.
Risk Level
The risk level of the policy. You can set one of the following risk levels:
-
Extremely High: For events such as outbound transfers by departing employee user groups, by extremely high-risk user groups, or of L4 files.
-
High: For events such as outbound transfers by high-risk user groups or of L3 files.
-
Medium: For events such as outbound transfers by medium-risk user groups or of L2 files.
-
Low: For catch-all events for all outbound transfers.
Action
The action taken when the policy is triggered. You can set one of the following actions:
-
Audit Only
-
Audit and Prompt
-
Block and Notify
-
Block Only
If you set the action to block and prompt or block without prompt, you also need to select a blocking type, either block all or intelligent blocking.
-
Block All: The SASE App blocks all outbound file activities in real time and audits them.
-
Intelligently Block: The SASE App blocks files in real time based on sensitive file characteristics defined in data templates. To ensure effective blocking, the SASE App scans files on the endpoint and tags them with sensitivity levels in advance. Before the scanning task is complete, the app defaults to blocking all files, and the blocking policy does not take effect. Scanning and tagging are performed on the endpoint, and no data is uploaded.
Source File Retention
Specifies whether to retain the source file information.
Retain Screenshot File
Specifies whether to retain the screenshot evidence file.
Status
The status of the policy. Valid values:
-
Enabled: The policy is in effect. SASE inspects files based on the policy.
-
Disabled: The policy is inactive.
Data Identification Rule Settings
Data Identification Rule
Select a configured identification rule. For information about how to configure an identification rule, see Configure detection rules for outbound file classification.
Transmission Channel
Select the data transmission channels to monitor. A file transfer through a selected channel triggers sensitive file detection. You can select all or some of the supported channel types.
Instant Messaging (Software), Email (Software), FTP Channel, Network Share, Print, Mobile Storage, Cloud Drive (Software), Cloud Notes (Software), Remote Desktop, Code Hosting (Software), Large Model (Software), Cloud Drive (Web), Email (Web), Code Hosting (Web), Cloud Notes (Web), Cloud Blog, Large Model (Web), Social Media, Instant Messaging (Web), and Others.
Effective Scope
User Group
Select the user group to which the policy applies.
Approval Process Configuration
When there is a risk of an outbound file transfer, specify whether employees can submit the transfer for approval.
If you allow employees to submit transfers for approval, you must select an approval workflow. For more information about how to create an approval workflow, see Configure an approval workflow.
Prompt Display Configuration
Set the notification message that appears when an outbound file transfer is blocked. You can set messages in both Chinese and English.
-
Step 5: View audit logs
After you complete the configuration, view the detection results for sensitive outbound file transfers in the audit logs.
-
In the left-side navigation pane, choose .
-
On the tab, view the audit logs. You can select a time range, such as Last Hour, Last 6 Hours, Last Day, Last 7 Days, or Last Month.
-
In the Actions column of an outbound file transfer event, click Details to view information such as Sensitive Message, Screenshot Evidence, Hit Policy, Office Terminal, Outbound Transfer Channel, and Account Information.
Related topics
-
To add other identity sources, see Identity access.
-
To add code repository operations and specific USB devices to an allowlist, see Configure a channel allowlist.
-
To manage screen and print watermarks for employees, see Manage watermarks to ensure data security.
-
To manage peripheral devices such as USB flash drives and Bluetooth devices for employees, see Manage peripheral devices to ensure data security.