What you are evaluating
This profile covers the documented DLP channels, including Zscaler Internet Access, endpoint and SaaS data at rest. Endpoint functions require the applicable Client Connector configuration; broad database or data-lake inventory is a separate evaluation question.
A useful evaluation context
A team using Zscaler access services can evaluate how DLP fits its traffic routing, managed endpoints and selected SaaS applications.
Documented capabilities
The vendor describes these capabilities in the linked sources. Availability depends on the product edition and supported environment.
- Inline DLP examines supported web and email paths, subject to configured routing and inspection.
- Documented matching options include exact data matching, indexed document matching and optical character recognition.
- Endpoint and SaaS data-at-rest capabilities add channel-specific controls, with repository actions varying by supported application.
Where it fits in the work
- Diagram the lab traffic route and decide where encrypted traffic can be inspected under the approved policy.
- Configure a synthetic data detector, then test an inline transfer separately from an endpoint action and a SaaS scan.
- Compare incident records and user experience across those channels, documenting any application that requires a different enforcement approach.
APPLY THE IDEA / ILLUSTRATIVE EXERCISE
Make the outcome observable.
Use synthetic sensitive content in a controlled web upload and a supported SaaS repository, applying separate audit policies to each path.
Evidence to look for
The event records distinguish inline and at-rest detection, and an approved remediation changes only the intended lab object or transfer.
Use synthetic data and an authorized test environment. Agree the scope and recovery steps before enabling enforcement.
Questions for your evaluation
- Which encrypted flows are actually inspected and which are excluded or technically unsupported?
- Which endpoint operations are covered by the chosen Client Connector version and policy?
- For each SaaS repository, can the integration quarantine, label or restrict collaboration, and what permissions does that action require?