Can DLP Endpoint prevent / discover monitor sftp traffic
search cancel

Can DLP Endpoint prevent / discover monitor sftp traffic

book

Article ID: 169957

calendar_today

Updated On:

Products

Data Loss Prevention Endpoint Prevent Data Loss Prevention Enforce

Issue/Introduction

Customer is using DLP Endpoint prevent / discover and would like to know how sftp is covered. 

Environment

15.x

16.x

Resolution

DLP Agent is unable to detect the secure file transfer while it is crossing the wire but it is able to detect the SFTP application accessing the file and trigger an incident (and block if configured).

In order for endpoint to monitor sftp activity the user will need to have application monitoring setup for the ftp client. The application monitoring settings will need to be configured to include application file access (AFA) so that endpoint can detect when the user selects a document to upload so it can be scanned accordingly.

Configure the sftp application here:

Ensure the agent configuration has Application File Access enabled as well: