Enable SaaS API Data Loss Prevention for AWS Tenants
To apply DLP SaaS API rules to files in an AWS tenant, you must authorize the tenant using the procedure described below. Once the tenant is authorized, for each file residing in the tenant, when the system finds data in violation of an enabled SaaS API rule it will enforce the action of that rule. To enable this feature:
- Enable CloudTrail Event Logging for S3 Buckets and Objects from the AWS console. (You need only enable this feature once for your account; you need not do it for each AWS tenant you authorize.)
- Authorize an AWS Tenant in Secure Access.
- Create an AWS Stack from the AWS console.
An AWS account can support at most one Cloud Malware tenant and one SaaS API DLP tenant at the same time. You cannot authorize multiple SaaS API DLP tenants for a single AWS account.