Data Loss Prevention (DLP)

DLP integration is available for Cisco Secure Access customers with Secure Email Threat Defense Advantage licenses

Secure Email Threat Defense uses centralized Cisco Secure Access Data Loss Prevention (DLP) services. To access the Data loss prevention settings navigate to Configuration > Global settings.

To integrate Secure Access DLP with Secure Email Threat Defense, there are three tasks:

  1. Generate API keys with a "DLP as A Service" scope from within Cisco Secure Access. For details, see Cisco Secure Access Help: Add API Key.

  2. Use the generated credentials to Enable DLP in Secure Email Threat Defense. For details, see Enable DLP.

  3. Add an email rule to the DLP policy in Secure Access. For details, see Cisco Secure Access Help: Add an Email Rule to the Data Loss Prevention Policy.

Generate Cisco Secure Access DLP API Keys

Before you can enable DLP in Secure Email Threat Defense, generate API keys with a "DLP as A Service" scope from within Cisco Secure Access. For details, see Cisco Secure Access Help: Add API Key.

Enable DLP

Complete the following steps to enable DLP in Secure Email Threat Defense:

  1. Select Configuration > Global settings.

  2. On the Data loss prevention settings panel, enter the Client ID and Secret key that you generated in Generate Cisco Secure Access DLP API Keys.

  3. Click Submit. DLP is now enabled.

    Create URL Rule screenshot

  4. In Cisco Secure Access, add an email rule to the Data Loss Prevention Policy. For details, see Cisco Secure Access Help: Add an Email Rule to the Data Loss Prevention Policy.

Disable DLP

To disable DLP:

  1. Select Configuration > Global settings.

  2. On the Data loss prevention settings panel, click Disable DLP.

  3. A confirmation dialog is displayed. A checkbox provides the option to delete your keys as you disable the feature.

  4. Click OK. DLP is now disabled.

    Create URL Rule screenshot