All Products
Search
Document Center

Secure Access Service Edge:Create an asset mapping task

Last Updated:Mar 31, 2026

Asset mapping scans files on employee terminals, classifies them by sensitivity level, and reports the results to the SASE console. Run an asset mapping task before configuring Data Loss Prevention (DLP) policies—the scan results let you understand what sensitive data exists across your fleet and generate identification rules automatically using foundation model-based intelligent learning.

Prerequisites

Before you begin, ensure that you have:

How it works

When you start an asset mapping task, the SASE client on each targeted terminal scans files according to the scan mode and performance settings you configure. Files that match the specified sensitivity level are reported to the console, where you can preview their content and use them to generate identification rules.

SASE supports two task types:

  • Immediate task — starts scanning right away. The task is valid for 72 hours. If a user doesn't log on to the SASE client during that window, their terminal isn't scanned.

  • Scheduled task — runs on a recurring schedule you define, scanning terminals on a regular basis.

Step 1: Create an asset mapping task

Create an immediate task

  1. Log on to the SASE console.

  2. In the left-side navigation pane, choose Data Loss Prevention > Asset Map.

  3. On the Asset Map page, click Start Asset Mapping.

  4. In the Start Asset Mapping panel, configure the parameters described in the following table, and then click OK.

ParameterDescription
Task NameA name for the task.
Report by Sensitivity LevelThe sensitivity level of files to report. The system classifies files using identification rules and reports only files at the level you select.
Scan ModeThe scope of files to scan. See Choose a scan mode for guidance.
Performance PreferenceHow the task balances resource consumption against scanning thoroughness. See Choose a performance preference for guidance.
Applicable UserThe terminals to scan: All Users (all terminals with the SASE client installed) or Some Users (specific user groups you select).
Exception UserUsers to exclude from the task. Enter multiple usernames separated by commas (,).

Create a scheduled task

  1. Log on to the SASE console.

  2. In the left-side navigation pane, choose Data Loss Prevention > Asset Map.

  3. On the Asset Map page, click Asset Mapping Tasks.

  4. On the Asset Mapping Tasks page, click Create Asset Mapping Task.

  5. In the Create Scheduled Asset Mapping Task panel, configure the parameters described in the following table, and then click OK.

ParameterDescription
Task NameA name for the task.
PriorityThe task priority. Valid values: 1–100. A lower value means higher priority.
Report by Sensitivity LevelThe sensitivity level of files to report. For details about identification rules, see Configure identification rules for files transferred outbound.
StatusWhether to enable the task immediately after creation.
Scan ModeThe scope of files to scan. See Choose a scan mode for guidance.
FrequencyHow often the task runs.
Performance PreferenceHow the task balances resource consumption against scanning thoroughness. See Choose a performance preference for guidance.
Applicable UserThe terminals to scan: All Users or Some Users (specific user groups).
Exception UserUsers to exclude from the task. Separate multiple usernames with commas (,).

Choose a scan mode

Scan modeWhat it scansWhen to use
Quick ScanKey system paths: services, drivers, startup items, running processes, downloads, desktop, and documents directoriesFirst scan of a new deployment, or when you want minimal impact on terminal performance
Custom ScanPaths you specify (files, folders, drive letters, or Windows environment variables)When sensitive data is concentrated in known directories
Full Disk ScanAll files on the terminalWhen you need complete coverage and can tolerate longer scan times

Custom Scan path formats:

Path typeExample
File pathC:\scan_dir\scan_file.exe
Folder (all files in directory)C:\scan_dir
Drive (all files on disk)C:\
Windows environment variable%APPDATA%

For Custom Scan, use Excluded Scan Path to specify paths to skip.

Choose a performance preference

ModeResource usageScan behaviorWhen to use
Experience FirstMinimalScan may be paused or canceled if system resources are neededTerminals actively used during work hours
Balanced ModeModerateScan completes without noticeably affecting the user experienceMost deployments
Security FirstHighScan runs at highest priorityTerminals under investigation or with suspected data leaks

Step 2: View asset mapping tasks

  1. Log on to the SASE console.

  2. In the left-side navigation pane, choose Data Loss Prevention > Asset Map.

  3. On the Asset Map page, click Task Management.

image
  1. On the Task Management page, view all immediate and scheduled tasks.

    • Filter tasks by Scan Mode, Performance Preference Mode, or Task Status.

    • Click Cancel Task in the Actions column to cancel a running task.

image

Step 3: View reported files

After a task completes, the system reports files that match the sensitivity level you configured.

  1. Log on to the SASE console.

  2. In the left-side navigation pane, choose Data Loss Prevention > Asset Map.

  3. On the Asset Map page, review the file list.

    • Filter files by time range, sensitivity level, file name, username, department, device name, device IP address, or device Media Access Control (MAC) address.

    • Click Preview in the Actions column to view file content.

Run an intelligent learning task to generate rules

After an asset mapping task completes, select the files with the most reliable data and run an intelligent learning task. SASE uses a foundation model to analyze the selected files and generate identification rules, which are added to the intelligent recommendation library for use in DLP policy configuration. For details on configuring the library, see Configure identification rules for files transferred outbound.

Important

SASE gives first-time users of intelligent learning 3 free sessions. After those are used, you receive 1 additional free session per month.

  1. Log on to the SASE console.

  2. In the left-side navigation pane, choose Data Loss Prevention > Asset Map.

  3. On the Asset Map page, click Intelligently Generate Rule.

image
  1. In the Intelligently Generate Rule panel, click Start New Learning Task. Configure the parameters described in the following table, and then click Start.

ParameterDescription
Files for LearningThe number of files to use for learning. For effective and precise rules, include at least 5,000 files.
Detected AtThe detection time range. The system uses files reported within this period.
File SizeFilter by file size. Only files 10 KB or larger can be included.
File FormatThe file formats to include. Supported formats: .ppt, .pptx, .pptm, .keynote, .key, .pages, .page, .dps, .xls, .xlsx, .xlsm, .xlam, .xlsb, .csv, .numbers, .lbx, .et, .doc, .docx, .docm, .dotm, .wps, .pdf, .ofd

What's next