Skip to main content

Lab 5 — Detection Logic using DLP Engine

⚠️ STOP — COMPLETE LAB SETUP BEFORE STARTING MODULE 2

Module 2 requires the Lab Tenant and a configured Zscaler Client Connector on the VM. Before proceeding, go to Pre-Requisites for Module 2 and complete:

  • Part 1 — Access Your Lab Environment
  • Part 2 — Configure Zscaler Client Connector (Lab Tenant), including Step 5: verify that SSL inspection uses Inspect for the lab's HTTPS traffic
  • Part 3 — Setup VM and Login to ZCC

📌 Once ZCC is authenticated, its service is ON, all modules are active, and ip.zscaler.com confirms your traffic is tunneled — come back here and start Lab 5.

Lab 5⏱ 15 min⚗ Lab Tenant · Read/Write👤 Alex
Detection Logic using DLP Engine
In the previous lab, you assessed Microsoft Copilot readiness by identifying sensitive data exposure across SharePoint, OneDrive, and Teams. Now Alex needs to build the detection logic that identifies sensitive content in documents — the foundation for the Web and Endpoint enforcement policies in Labs 6 and 7.
🛡
Alex — Security Administrator
Lab Tenant (Read/Write) — Configuration Mode
You are Alex. Before any policy can protect data, the system needs to know what sensitive data looks like. The detection logic you build here will be reused for Web and Endpoint enforcement in Labs 6 and 7.

🔗Dependency: The DLP engine created in this lab combines the custom dictionary with two predefined dictionaries and is referenced in Labs 6 and 7. Lab 8 uses preconfigured browser policies, not this engine. Complete all steps before moving to the next lab.

🎯Build a custom dictionary and a DLP engine for the Web and Endpoint protection policies in Labs 6 and 7.

Step 1: Navigate to DLP Dictionaries and Review Predefined Dictionaries​

Policies → Data Protection → Common Resources → Dictionaries & Engines

Navigating to Policies → Data Protection → Common Resources → Dictionaries & Engines
Policies → Data Protection → Common Resources → Dictionaries & Engines navigation path.

Review the list of predefined dictionaries. Locate and observe the following two dictionaries used in this lab:

  • Credit Cards
  • ABA Bank Routing Number

These predefined dictionaries require no changes — you will add them directly to the DLP engine in Step 3.

💡 Key Insight

These predefined dictionaries provide built-in detection capabilities for commonly regulated data types — no configuration required to get started with standard compliance frameworks.

Step 2: Create a Custom DLP Dictionary​

🎯Build custom detection logic for organization-specific sensitive data.

Click Add DLP Dictionary and configure with the following settings.

FieldValue
Name
DP Project Code
Dictionary TypePatterns & Phrases
Match TypeMatch Any
Enable ProximityEnabled
Proximity Length200

Add the following detection patterns:

DP-PRJ-2025-\d{4}
DAC-\d{7}

Set the action to Count Unique.

Then add the following contextual phrases:

  • Confidential
  • Internal Only
  • Salary
  • Payroll
  • Project Codes
  • Internal

Set the phrases' action to Count All, then click Save to save the custom dictionary.

Edit DLP Dictionary — DP Project Code with Match Any, two patterns set to Count Unique, and six contextual phrases set to Count All
DP Project Code dictionary — Patterns & Phrases type, Match Any, two regex patterns (DP-PRJ-2025 and DAC) set to Count Unique, and six contextual phrases set to Count All.
💡 Key Insight

Custom dictionaries allow organizations to detect proprietary identifiers that are not covered by standard compliance templates — project codes, internal classifications, or domain-specific terminology unique to your business.

Step 3: Create a Detection Logic using a DLP Engine​

🎯Combine multiple detection signals into a single classification rule.

Switch to the DLP Engines tab, then click + Add DLP Engine.

DLP Engines tab selected with Add DLP Engine button highlighted
Switch to the DLP Engines tab (1) and click + Add DLP Engine (2) to begin creating the detection engine.
FieldValue
Name
DP Project Code
OperatorALL

Under Channels, select the following (leave DSPM unchecked):

  • Endpoint DLP
  • Inline Web
  • SaaS Security
  • Outbound Email DLP

Then add the following detection components, each with condition > 0:

  • Credit Cards
  • ABA Bank Routing Number
  • DP Project Code
Add DLP Engine — DP Project Code with four channels selected and ALL operator combining three detection components
Add DLP Engine — Endpoint DLP, Inline Web, SaaS Security, and Outbound Email DLP channels selected; ALL operator combining Credit Cards, ABA Bank Routing Number, and DP Project Code detection.

Review the expression preview. It should display:

((Credit Cards > 0) AND (ABA Bank Routing Number > 0) AND (DP Project Code > 0))

All three dictionaries must match: Credit Cards AND ABA Bank Routing Number AND the custom DP Project Code dictionary. Click Save to save the engine.

Step 4: Understand How Detection Logic Supports Enforcement​

🎯Connect detection logic to future protection scenarios.

This detection logic will be reused in the following labs:

LabChannelAction
Lab 6WebBlock sensitive data uploads
Lab 7EndpointBlock Application File Access (AFA) and Clipboard transfers

Lab 8 separately tests preconfigured browser policies for copy-paste controls; it does not reuse this engine.

💬 Discussion
  • Why is it important to combine multiple detection signals instead of relying on a single identifier?
  • How does proximity detection reduce false positives?
  • What types of organization-specific identifiers should be added to custom dictionaries?
  • How does this detection logic support consistent protection across Web and Endpoint environments?
💡 Key Insight

Detection logic defines what is sensitive. Policies define what to do about it.

The DP Project Code engine combines three dictionaries with AND logic and is reused by the Web policy in Lab 6 and the Endpoint policies in Lab 7. Lab 8 demonstrates separate, preconfigured browser controls.

🎓
Lab Assistant
Zenith Live 2026 · Dataparity
Lab 5 — Detection Logic
Browse all topics