Use Case: Prevent data from being leaked to the web from your cloud-based applications

Prev Next

Your organization wants to block all content from leaking to the web from cloud services, such as Dropbox and Google Drive. The Sales team needs access and copy rights to their shared folder on Google Drive.

An administrator needs to perform these tasks.

  1. Block Dropbox and Google Drive services with the Cloud Protection Rule.

    1. In ePO - On-prem, select MenuData Protection DLP Policy Manager.

    2. On the Rule Sets tab, select or create a rule set. For new rule sets, you must assign a policy.

    3. On the Data Protection tab, select ActionsNew Rule Cloud Protection Rule.

    4. Enter a name for the rule and select StateEnabled.

    5. On the Condition tab, in the Classification field, select the classification you created for your confidential content.

    6. In the Cloud Services field, select Dropbox and GoogleDrive.

  2. Specify the user group and folder that you want to exclude from the rule.

    1. Select Exceptions, click ActionsAdd Rule Exception, and name it Sales.

    2. Set the State to Enabled.

    3. In Classification of, select contains any data (ALL).

    4. In End-User, select Belongs to one of end-user groups (OR).

    5. Select New Item, and create an end-user group called Sales team.

    6. Click the add group button, select Sales team, and click OK.

    7. In the top-level Subfolder name, select equals, and type the name of the folder (for example, Sales pitch).

  3. Add the Google Drive URL you want to block content from leaking.

    1. Select MenuData Protection DLP Policy Manager. Definitions.

    2. In the left pane, select URL List, then select ActionsNew.

    3. Name the URL Google Drive URL.

    4. Enter the Host details, and optionally, the Protocol, Port, and Path, then click Add.

    5. Click Save.

  4. Block Dropbox and Google Drive from leaking to the web with the Web Protection Rule.

    1. On the Data Protection tab of your rule set, select ActionsNew Rule Web Protection Rule.

    2. Enter a name for the rule and select StateEnabled.

    3. On the Condition tab, in the Classification field, select the classification you created for your confidential content. This must be the same classification selected for the Cloud Protection Rule.

    4. In the Web address (URL) field, select is one of (OR) and choose Dropbox (built-in) and Google Drive URL, created in previous step.

    5. On the Reaction tab, set the Action to Block.

    6. In the User Notification field, select Default web protection user notification.

    7. Click OK, then Save.