Skip to main content

Lab 8 โ€” In-Browser Protection using Browser-Based DLP

Lab 8โฑ 25 minโš— Lab VM ยท Browser DLP๐Ÿ‘ค Kevin
In-Browser Protection using Browser-Based DLP

Labs 6 and 7 demonstrated network-upload, application file-access, and clipboard controls. Lab 8 uses preconfigured Browser DLP policies to mask sensitive values before submission, block sensitive PDF downloads from a website, and watermark a document viewed in Chrome.

๐Ÿ’ก Positioning โ€” Complementary, Not a Replacement

Browser-Based DLP does not replace Inline Web DLP or Endpoint DLP. Each operates at a different control point and covers a different threat surface:

ControlWhere it operatesWhat it covers
Inline Web DLP (Lab 6)Network proxyData leaving via HTTP/S uploads
Endpoint DLP (Lab 7)OS / agent layerApplication File Access and Clipboard rules scoped to Notepad++
Browser-Based DLP (Lab 8)Inside the browserGenAI prompt masking, sensitive-file download blocking, and browser-viewed document watermarking

These controls complement one another. Coverage depends on supported applications, platforms, inspection settings, and policy scope.

๐Ÿ‘ค
Kevin โ€” End User
Lab VM โ€” Chrome Browser ยท SDC Extension Login
This lab is Kevin's experience only. All three tasks are performed from the lab VM using Chrome with the Zscaler Browser DLP extension installed. There is no admin configuration task in this lab โ€” the policies have been pre-configured by Alex.
VM + Chrome Required

All tasks in this lab must be performed from the lab VM using Google Chrome. The Zscaler Browser DLP Chrome extension must be active. Complete the prerequisite login steps below before starting Task 1.


Prerequisite โ€” Log In to the Chrome Extensionโ€‹

On the same CloudShare VM, authenticate the Chrome extension with the SDC Admin credentials listed in Pre-Requisites for Module 2. This extension login is separate from the Student Admin login used by ZCC. Lab 8 uses preconfigured Browser DLP policies; it does not require the DP Project Code engine you created in the Lab Tenant.

Prereq Step 1 โ€” Open the Extension Sign-In Websiteโ€‹

Open Google Chrome on the lab VM and go to enterprise.onsqrx.com.

Prereq Step 2 โ€” Enter the Tenant Identifierโ€‹

Enter dlpdemo as the tenant identifier and click Continue.

Enter dlpdemo tenant identifier in Chrome extension

Prereq Step 3 โ€” Enter the Lab User IDโ€‹

Enter the Admin Username from CloudShare โ†’ Credentials โ†’ SDC Credentials.

Enter lab user ID in Chrome extension login

Prereq Step 4 โ€” Select Okta SSOโ€‹

Click Okta SDC SSO to proceed to identity provider authentication.

Select Okta SDC SSO for authentication

Prereq Step 5 โ€” Complete IDP Authenticationโ€‹

Complete the identity-provider login with the same SDC Admin Username and its assigned password.

Complete IDP authentication with user ID and password

After signing in with your SDC Admin credentials, you will see the "All set!" confirmation screen. This signs you in to the installed Browser DLP extension. Do not click "Sign in as Admin" โ€” it is not required for this lab. Close this tab and return to the lab guide.

All set confirmation screen โ€” extension login complete, close this tab

Task 1 โ€” Mask Sensitive Values Before GenAI Submissionโ€‹

๐ŸŽฏDemonstrate how Browser-Based DLP intercepts sensitive data typed or pasted into a GenAI prompt and masks it before submission โ€” protecting data that never touches the network layer.

Stepsโ€‹

Kevin opens ChatGPT in Chrome and pastes the following sample customer record. Use this supplied example rather than real customer data:

๐Ÿ“‹ Content to paste into the ChatGPT prompt:

Customer name: Daniel Reeves
Email: daniel.reeves@acme-corp.com
Phone: +1 415-238-7712
SSN: 531-72-8943
Issue: Customer reported duplicate billing for invoice INV-4482 and
wants confirmation once the refund is processed.

As soon as Kevin pastes the content, the Browser-Based DLP extension detects the sensitive values โ€” SSN, email, phone number โ€” and masks them inline before the prompt is submitted. Kevin is notified that sensitive content has been redacted.

Browser DLP masking sensitive values in ChatGPT prompt before submission
๐Ÿ’ก Why This Matters

Browser DLP masks values at the input field before submission. Inline DLP can inspect supported outbound traffic when SSL inspection and policy scope apply, but it does not provide the same in-page masking experience.

Use the application and input surfaces covered by the configured Browser DLP policy.


Task 2 โ€” Block Sensitive File Downloadsโ€‹

๐ŸŽฏAttempt to download a PDF containing sensitive sample data and verify that the browser policy blocks it.

Step 1 โ€” Select the Sample and Download Formatโ€‹

  1. In Chrome on the lab VM, open https://dlptest.com/sample-data/.
  2. Under PII / PCI Test Datasets, select Name + SSN + CCN (callout 1). This dataset contains fabricated names, Social Security numbers, and credit card numbers.
  3. In the dialog, click Download PDF (callout 2).
DLP Test Sample Data Library with Name + SSN + CCN and Download PDF highlighted
1 โ€” Select Name + SSN + CCN. 2 โ€” Click Download PDF.

Step 2 โ€” Verify the Download Is Blockedโ€‹

Confirm that the Download Blocked notification appears (callout 3) with the message:

File Download has been blocked based on policy

The screenshot also shows dlptest-name-ssn-ccn.pdf marked Removed in Chrome's downloads list. The expected outcome is that the PDF is not available as a successful download.

Download Blocked policy notification and dlptest-name-ssn-ccn.pdf marked Removed in Chrome downloads
3 โ€” Verify the policy block message and the unsuccessful PDF download.

Select I UNDERSTAND to dismiss the notification. If the file downloads successfully or only a generic browser error appears, confirm the Browser DLP extension is authenticated and ask your facilitator to check the demo policy.


Task 3 โ€” Dynamic Watermark with Viewer Identityโ€‹

๐ŸŽฏDemonstrate how Browser-Based DLP dynamically watermarks sensitive documents viewed in the browser with the viewer's identity โ€” creating a visual deterrent and forensic trail without altering the source file.

Stepsโ€‹

Kevin opens the following sensitive Dataparity document in Chrome โ€” this document has been tagged for dynamic watermarking by the Browser-Based DLP policy:

As soon as the document renders in the browser, the extension overlays a dynamic watermark containing Kevin's identity โ€” user name, email, and timestamp โ€” across the document view.

Browser DLP dynamic watermark with viewer identity overlaid on sensitive document
๐Ÿ’ก Why This Matters

The watermark is applied to the browser view, not to the source file. It identifies the viewer in the displayed document; this exercise does not establish that a downloaded copy retains the watermark.

Watermarking is a visual deterrent. It is not a replacement for access, download, or data-movement controls.


๐Ÿ’ฌ Discussion โ€” Lab 8
  • Task 1 masked content before submission to ChatGPT. How would you handle a use case where a user legitimately needs to ask an AI assistant about a customer record โ€” for example, a support agent using an internal AI tool?
  • Task 2 blocked a sensitive PDF download. How does preventing data from being saved locally complement the upload and endpoint controls tested in Labs 6 and 7?
  • Task 3 showed a deterrent watermark. Can you think of a scenario where watermarking alone is insufficient and a Block action would be required instead?
  • Browser-Based DLP requires a Chrome extension. How would you handle employees using Firefox, Edge, or Safari โ€” and what does that mean for your coverage model?
๐Ÿ’ก Key Insight โ€” Lab 8

The controls are complementary. Lab 6 tested an inspected web upload, Lab 7 tested file access and clipboard paste into Notepad++, and Lab 8 demonstrated browser masking, sensitive-download blocking, and watermarking with preconfigured policies.

Next, return to the Enterprise Tenant for Lab 9 to review separate pre-populated incidents and existing response workflows.

๐ŸŽ“
Lab Assistant
Zenith Live 2026 ยท Dataparity
Lab 8 โ€” Browser DLP
Browse all topics