Skip to main content

Lab 3 โ€” Endpoint Data Visibility

Lab 3โฑ 15 min๐Ÿข Enterprise Tenant ยท Read-Only๐Ÿ‘ค Alex
Endpoint Data Visibility
After reviewing SaaS visibility in Labs 1 and 2, Alex turns to the endpoint: what sensitive data is stored locally, which applications are present, and what devices have been connected?
๐Ÿ”
Alex โ€” Security Analyst
Enterprise Tenant (Read-Only) โ€” Observation Mode
You are Alex. Connect endpoint data, applications, devices, and user activity to understand what is happening on the endpoint.
Explore beyond the steps

The steps are a starting point. Explore available filters, tabs, linked records, information icons, and View All options. Try other users, departments, application categories, and device types.

1. Open the Endpoint Data Scan Dashboardโ€‹

Step 1 โ€” Launch Zscaler Internet Accessโ€‹

Log in to the Solution Demo Centre portal at sdc.zslogin.net/portal, then select Zscaler Internet Access.

Solution Demo Centre portal with the Zscaler Internet Access tile selected
Solution Demo Centre โ†’ Zscaler Internet Access.

Step 2 โ€” Navigate to Endpoint Data Scanโ€‹

In the ZIA console, open Dashboard and select Endpoint Data Scan under Reports.

ZIA Dashboard menu with Endpoint Data Scan selected under Reports
Dashboard โ†’ Reports โ†’ Endpoint Data Scan.

Step 3 โ€” Review the Dashboard Layoutโ€‹

Locate the summary tiles, Top Users with Sensitive Data, and Sensitive File Range Distribution.

Endpoint Data Scan dashboard showing summary tiles, top users table, and file range distribution
Endpoint Data Scan โ€” โ‘  summary tiles, โ‘ก top users, โ‘ข file range distribution.

2. Review the Endpoint Data Postureโ€‹

Step 4 โ€” Review the Summary Tilesโ€‹

Review the three summary tiles at the top of the dashboard. Numbers may vary on your dashboard. Values shown below are screenshot examples, not expected results.

Summary tiles showing users with sensitive data, total files scanned, and files with sensitive data
Summary tiles โ€” users, scanned files, and sensitive files.
TileScreenshot exampleWhat it shows
Users with Sensitive Data374 of 375 usersUsers with sensitive files on their endpoints
Total Files Scanned3.2M ยท 509.7 GBScanned file count and size
Files with Sensitive Data1.8M ยท 147.7 GBFiles containing classified sensitive data

Compare the proportion of users with sensitive data and the proportion of scanned files classified as sensitive.

3. Review Users and Endpointsโ€‹

Review Top Users with Sensitive Data in the dashboard overview.

ColumnWhat it shows
UserAssociated user account
DepartmentUser's department
User Risk ProfileRisk profile calculated in ZIA
Endpoint NameAssociated endpoint and platform
Sensitive Files DiscoveredNumber of sensitive files discovered

User Risk Profile is calculated in ZIA, not from the sensitive-file count shown here. Review it alongside the endpoint data findings.

Explore the Department, User Group, and Sensitive Data selectors to compare results.

4. Review Data Classificationsโ€‹

Step 5 โ€” Explore the Classification Widgetsโ€‹

Scroll down to the classification widgets.

Top DLP Engines, Top AI and ML Categories, Top Departments, Sensitive Data Trend, and Sensitive Data by File Type
Classification widgets โ€” engines, categories, departments, trends, and file types.
WidgetWhat to review
Top DLP EnginesLeading engine matches, such as SourceCode, Medical, and Driver's License
Top AI & ML CategoriesContent categories such as Source Code, Technical, and Financial Documents
Top DepartmentsDepartment breakdown
Sensitive Data TrendChanges over the reporting window
Sensitive Data by File TypeFile extensions associated with sensitive data

Use View All where available. Compare classifications, departments, and file types; a file can match more than one classification.

5. Review the Sensitive File Range Distributionโ€‹

Review Sensitive File Range Distribution in the dashboard overview. The example groups users into:

  • More than 100 files
  • 25 โ€“ 100 files
  • Less than 25 files

Check whether sensitive data is concentrated among a few users or spread across the user population.

6. Investigate a User's Endpoint Dataโ€‹

Step 6 โ€” Open User Investigationโ€‹

Select User Investigation using the people icon in the left navigation. Use the User filter to locate 2305990-sales@thezerotrustlab.com and open the user. You can also sort by Incidents to explore other users.

User Investigation list with the navigation icon, Incidents column, and Sales user highlighted
User Investigation โ€” locate 2305990-sales@thezerotrustlab.com.
Dashboard and incident differences

Exact incident numbers and types of incidents may vary in your tenant. Dates, file counts, and other dashboard values may also differ from the screenshots. Use the available records to explore the same fields and views.

Step 7 โ€” Review the User Overviewโ€‹

Confirm the selected user is 2305990-sales@thezerotrustlab.com, then review Overview.

Sales user Overview showing inventory, data at rest, and exfiltration data alongside a Low risk profile
User Overview โ€” user details, device inventory, data at rest, and incidents.
AreaWhat to review
User detailsDepartment, group, ZIA-calculated risk profile, and last-updated time
InventoryEndpoints, printers, removable storage, and portable devices
Data at RestLocally stored files and their classifications
Exfiltration DataSensitive activities, incidents, and associated DLP engines

Step 8 โ€” Inspect Data at Restโ€‹

Open Data at Rest to review scan results and individual files.

User Data at Rest tab showing scan totals, sensitive data classifications, file types, and discovered file paths
Data at Rest โ€” scan results, classifications, file types, and local paths.

Review Total Files Scanned, Last Scan Time, Files with Sensitive Data, Top Sensitive Data, and Sensitive Data by File Type.

In Top Sensitive Files Discovered, locate Customer Credit Cards.xlsx if present, or choose another file. Review its File Size, DLP Engines, AI & ML Categories, and Path. Explore View All and additional classification matches where available.

Step 9 โ€” Review the User Timelineโ€‹

Open Timeline and select an incident. The screenshot uses PCI High Print Block from August 27, 2026 at 20:11; if it is not available, select another incident and review the same fields. Incident numbers and types may vary.

User Timeline with a PCI High Print Block event selected, showing the blocked print flow and Customer Credit Cards.xlsx file details
Timeline โ€” review an incident's action, application, destination, detection, and file details.
DetailWhat to review
Action and severityRecorded outcome and severity
Endpoint and applicationSource endpoint and application
Channel and destinationHow and where the action was attempted
Policy & DetectionRule, DLP engines, and dictionary matches
File DetailsFilename, size, type, extension, and hash
SourceSource device and location

Compare other events and use the available Timeline filters. A Block action records a prevented attempt; an Allow device event does not establish that a sensitive-file transfer succeeded.

7. Explore Endpoint Applications and Connected Devicesโ€‹

Step 10 โ€” Explore Application Investigationโ€‹

Select Application Investigation in the left navigation and open Overview.

Application Investigation Overview showing detected applications, certificate status, threats, vulnerabilities, and the AI Assistance category
Application Investigation โ€” application posture and the AI Assistance category.
WidgetWhat to explore
Detected ApplicationsApplications and applications with CVEs across macOS and Windows
Instances by Code Signing Certificate StatusSignature and certificate status
Instances by Threat TypeReported threat classifications
Top Applications Versions with VulnerabilitiesApplication versions and instance counts
Top Applications by CategorySelect AI Assistance, then try other categories
Top Applications with ThreatsUse Select Threat and View All

Open the Inventory tab and explore available application details. Compare categories and versions rather than stopping at the screenshot example.

Step 11 โ€” Explore Connected-Device Inventoryโ€‹

Select Inventory in the left navigation, then Removable Storage.

Inventory Removable Storage view showing usage by department and action, filters, and devices associated with endpoints and users
Inventory โ†’ Removable Storage โ€” devices, associated endpoints, users, and actions.

Review Usage Distribution by Department, Usage Distribution by Action, and these device fields:

  • Device-Friendly Name, Serial Number, VID, and PID
  • Endpoint Name and User
  • Action

Use the User filter to explore devices associated with 2305990-sales@thezerotrustlab.com. The screenshot includes a TOSHIBA TransMemory USB Device associated with Demo1-Prevent.

Open linked device names and explore Portable Device, Printer, CD/DVD, and Floppy Disk where available. Inventory shows recorded device associations, not necessarily devices connected right now.

8. Summarise the Complete Endpoint Pictureโ€‹

Questions that you can find answers to:

  • How many users and files contain sensitive data?
  • Which classifications, departments, and file types appear most often?
  • What data and devices are associated with the investigation user?
  • What application, channel, destination, rule, and action appear in an incident?
  • Which endpoint applications or versions warrant further investigation?
  • Which connected-device records can you associate with an endpoint and user?
  • What else did you discover through filters, tabs, or drill-downs?
Key Takeaway

With Endpoint Data Scan and its related views, you gain visibility into sensitive data, endpoint applications, and devices that have been connected. Together with user activity, these views build a complete picture of what is happening on the endpoint.

Keep exploring beyond the steps. Use the available filters, tabs, linked records, and View All options to connect findings across views.

Proceed to Lab 4

You have completed Lab 3 โ€“ Endpoint Data Visibility. Continue to Lab 4 โ€“ Microsoft Copilot Readiness.

๐ŸŽ“
Lab Assistant
Zenith Live 2026 ยท Dataparity
Lab 3 โ€” Endpoint Data Visibility
Browse all topics