Monitor outbound files to ensure data security
To prevent business losses caused by sensitive files sent through channels like instant messaging and email, use the Office Data Protection (DLP) feature of SASE. It allows you to detect and control outbound files, monitor sensitive data flow in real time, and mitigate data leakage risks. This topic describes how to configure an outbound file detection policy and review the resulting statistics.
Prerequisites
-
You have purchased the Office Data Protection edition of SASE Internet Access Security. For more information, see Billing overview and Get started.
-
You have added employee and department information. For more information, see Connect to an LDAP source and Configure a user group.
Configure an outbound file detection policy
SASE identifies sensitive files based on the characteristics of sensitive data elements. Data templates are built from data elements, data types, and sensitivity levels. Detection policies then apply these templates, along with response actions and other conditions, to identify sensitive files that employees transfer.
SASE includes built-in data templates that cover common types of company, customer, and personal data. If these templates do not meet your business requirements, you can create new sensitive data elements to build your own data templates.
Log on to the Secure Access Service Edge console.
-
In the left-side navigation pane, choose .
-
On the Outbound Transfer Management tab, click Create Policy.
-
In the Create Policy panel, configure the following parameters. Then, click OK.
Parameter
Description
Policy Information
Policy Name
The name of the policy.
Policy Description
A description for the policy.
Risk Level
The risk level of the policy. You can set one of the following risk levels:
-
Extremely High: For events such as outbound transfers by departing employee user groups, by extremely high-risk user groups, or of L4 files.
-
High: For events such as outbound transfers by high-risk user groups or of L3 files.
-
Medium: For events such as outbound transfers by medium-risk user groups or of L2 files.
-
Low: For catch-all events for all outbound transfers.
Action
The action taken when the policy is triggered. You can set one of the following actions:
-
Audit Only
-
Audit and Prompt
-
Block and Notify
-
Block Only
If you set the action to block and prompt or block without prompt, you also need to select a blocking type, either block all or intelligent blocking.
-
Block All: The SASE App blocks all outbound file activities in real time and audits them.
-
Intelligently Block: The SASE App blocks files in real time based on sensitive file characteristics defined in data templates. To ensure effective blocking, the SASE App scans files on the endpoint and tags them with sensitivity levels in advance. Before the scanning task is complete, the app defaults to blocking all files, and the blocking policy does not take effect. Scanning and tagging are performed on the endpoint, and no data is uploaded.
Source File Retention
Specifies whether to retain the source file information.
Retain Screenshot File
Specifies whether to retain the screenshot evidence file.
Status
The status of the policy. Valid values:
-
Enabled: The policy is in effect. SASE inspects files based on the policy.
-
Disabled: The policy is inactive.
Data Identification Rule Settings
Data Identification Rule
Select a configured identification rule. For information about how to configure an identification rule, see Configure detection rules for outbound file classification.
Transmission Channel
Select the data transmission channels to monitor. A file transfer through a selected channel triggers sensitive file detection. You can select all or some of the supported channel types.
Instant Messaging (Software), Email (Software), FTP Channel, Network Share, Print, Mobile Storage, Cloud Drive (Software), Cloud Notes (Software), Remote Desktop, Code Hosting (Software), Large Model (Software), Cloud Drive (Web), Email (Web), Code Hosting (Web), Cloud Notes (Web), Cloud Blog, Large Model (Web), Social Media, Instant Messaging (Web), and Others.
Effective Scope
User Group
Select the user group to which the policy applies.
Approval Process Configuration
When there is a risk of an outbound file transfer, specify whether employees can submit the transfer for approval.
If you allow employees to submit transfers for approval, you must select an approval workflow. For more information about how to create an approval workflow, see Configure an approval workflow.
Prompt Display Configuration
Set the notification message that appears when an outbound file transfer is blocked. You can set messages in both Chinese and English.
-
View sensitive file detection statistics
After you configure a policy, the Office Data Protection feature automatically inspects files transferred by employees and analyzes sensitive outbound file transfers and anomalous activities from the last 30 days, 7 days, or 24 hours based on detection results.
-
Sensitive file detection helps you inspect outbound sensitive files that are 30 MB or smaller. It also provides statistics on the top five types of sensitive files that trigger policies and their proportions.
-
The anomalous activity feature records events such as employees transferring files larger than 30 MB, copying files to peripheral devices, or a single user's total outbound transfers exceeding 1 GB. The content of these files is not inspected. Pay close attention to anomalous activities and manually check these files for sensitive information. The following table describes the types of anomalous activities.
Anomalous activity type
Description
Large outbound file
Occurs when an employee sends a file 30 MB or larger, either online or offline.
If an offline transfer of a large outbound file occurs, you should pay close attention to the employee's behavior to prevent significant business losses.
File copied to peripheral
Occurs when an employee copies a file smaller than 30 MB to a peripheral device, either online or offline.
If a file is copied to a peripheral device while offline, you should pay close attention to the employee's behavior to prevent significant business losses.
Outbound threshold exceeded
Triggered when a single user's total offline file transfers exceed 1 GB.
If the outbound threshold is exceeded, you should pay close attention to the employee's behavior to prevent significant business losses.
-
In the left-side navigation pane, choose .
-
In the Sensitive Behavior Identification area, view the sensitive behaviors of employees recorded within the specified time period.

View outbound records of sensitive files
SASE can inspect files up to 30 MB that are transferred by employees for sensitive information and records information about outbound sensitive files. You can use these records to review the content of the transferred sensitive files.
-
On the Sensitive Behavior Detection page, view the list of sensitive files sent by employees.
At the top of the list, you can use the Time Range filter (defaults to the last 24 hours), the Username dropdown list, and the search box. The table columns include Username, Department, Anomalous Activity, First Outbound Time, Number of Outbound Sensitive Files, and Total Size of Sensitive Files. Click Details to view detailed outbound records for a user.
-
In the Actions column, click Details. On the Outbound Transfers of Sensitive Files tab, view the data statistics and file list for the outbound sensitive files of the specified employee.
Section
Description
Time Period
Set a custom time range for the query.
Data Statistics
Displays statistics on the number, channels, and sizes of outbound sensitive files within the specified time period.
Sensitive File List
Displays a list of outbound sensitive files, along with their sensitivity levels, data types, matched data templates, and hit counts. You can also filter the data as needed.
-
Click Download to save a sensitive file to your computer.
-
Click Details to open the Details panel. In this panel, you can view information about the sensitive file, including Data Flow, Key Information, Sensitive File (which includes a Download option), Screenshot Evidence, and Hit Policy. You can also view information about the Office Terminal, Outbound Transfer Channel, and Account Information associated with the transfer.
-
View anomalous activity records
SASE records events where employees transfer files larger than 30 MB, copy files to peripheral devices, or a single user's total transfers exceed 1 GB. Pay close attention to employees who trigger anomalous activity alerts to prevent significant business losses. For files larger than 30 MB, you need to manually check whether the file content contains sensitive information.
-
On the Sensitive Behavior Detection page, view the anomalous activities triggered by employees.
-
Click the value in the Abnormal Event column to go to the Abnormal Events tab and view the records for the specified user.
Alternatively, click Actions in the Details column to open the details panel, and then go to the Abnormal Events tab.
On this tab, you can filter records by date range, Event Type, Outbound Channel, and File Name. The table displays fields such as event type, time, device type, outbound information, file information, and endpoint name.
Configure detection result retention
By default, SASE retains detection results for 7 days. If you activate the log storage service, you can extend the retention period to 30 days. For more information, see Billing overview.
Configure storage space for sensitive files
By default, SASE provides 1 GB of free storage for this feature.
-
To purchase additional storage, click Scale Up in the upper-right corner. For pricing details, see Billing overview.
-
To stop storing new sensitive files, turn off the storage switch in the upper-right corner. Existing files are not deleted.
-
To delete stored sensitive files, click Clear in the upper-right corner and choose Clear by Time Range or Clear All.
-
As long as your service is active and you have available storage capacity, the system retains stored sensitive files and does not automatically delete them. For the data retention policy after the service expires, see Billing overview.
Customize storage space for sensitive files
The Office Data Protection edition of SASE Internet Access Security supports custom storage space for sensitive files. For more information, see Configure custom storage.
Related topics
-
To view and trace the log details of outbound sensitive files, see Sensitive file detection logs.
-
To ensure data security by controlling employee access to peripheral devices, see Ensure data security by managing peripheral devices.
-
To ensure data security by controlling screen and print watermarks for employees, see Ensure data security by managing watermarks.