Skip to main content
MIVES
Staff
Staff
January 23, 2026

Troubleshooting tip: FortiDLP Cloud connector policies

  • January 23, 2026
  • 0 replies
  • 185 views
Description This article provides tips for troubleshooting FortiDLP Cloud connector policies.
Scope FortiDLP.
Solution

When configuring cloud connector policies, there are several steps that can be taken in order to troubleshoot why something may not be working as expected.

 

  1. Verify that cloud connector events are associated with the correct user.

The first thing to verify is that the events that are coming through are indeed associated with the correct user. To confirm that this is configured correctly, first find the UUID of the user from the Users page in the FortiDLP console:

 

userUUID.png

 

Then copy this and use it in the API endpoint '/api/v2/users/{uuid}/useruri', to verify the URIs associated with the user. The URIs should include a username URI that matches either the primary email or UPN of the user in Google/Microsoft. If this does not exist, then it can be added either via a cloud sync (found in this document Integrate under 'Microsoft' or 'Google') or manually added using the '/api/v1/admin/users/{id}/useruris' API endpoint.

 

  1. Ensure the policy is correctly scoped to users.

It is important to note that cloud connector policies, as they are associated with a specific user rather than a specific machine, should only be scoped to entities using user labels. If a policy group includes certain entities based on a machine label, then the cloud policies within that group will not be applied to anyone.

 

  1. Verify that audit logging is enabled (Microsoft only).

To configure the Microsoft cloud connector, auditing must be enabled in the Microsoft 365 org. This can be confirmed via the Compliance portal or PowerShell, and full instructions can be found in this document: Enabling the Microsoft SharePoint and OneDrive Connector.

 

  1. Check that the cloud events expected are generated within Microsoft/Google.

If a cloud connector policy is not raising a detection when it is expected to, a worthwhile troubleshooting step is to ensure that the expected triggers (e.g., when a file is shared or deleted) are present in the Microsoft/Google audit log.

 

  1. SharePoint/OneDrive.
  1. Navigate to 'https://purview.microsoft.com'.
  2. Select 'Audit' from the left-hand menu.
                                                  
    m2.png

     

  3. Select a start and end date for the search using the 'Date and time range (UTC) Start' and 'Date and time range (UTC) End' fields.
                                                                        
    m3.png

     

  4. Narrow down the search to the event type using either the 'Activities - friendly name' or 'Activities - operation names' fields. A list of the mappings between the Purview operation names and FortiDLP event names is given at the end of this section.
                                                                         
    m4.png

     

  5. Select 'Search'.
                                                                      
    m5.png

     

  6. A job will appear in the table at the bottom of the page.
                                                                       
    m6.png

     

  7. Wait and select 'Refresh' until the job status progresses to 'Complete'. Depending on the size of the search window and the number of events, this can take up to several minutes.
                                                                           
    m7.png

     

  8. Select the entry in the table for the completed search to view the result of the search.
                                                                 
    m8.png

     

Appendix: Purview operation names to FortiDLP event types.

Operation names are given in bold, with the FortiDLP event types underneath.

m_appendix.png

 

  1. Google Drive.

  1. Navigate to 'https://admin.google.com/'.
  2. From the menu on the left-hand side, select Reporting -> Audit and investigation -> Drive log events.
                                                                            
    g2a.png

     

    g2b.png

     

  3. Add filters to limit the search. To limit to specific events, select 'Add a filter', select 'Event' from the dropdown, and then search for the event type and select the matching option. A list of mappings between Google event names and FortiDLP event names is given at the end of this section.
                                                         
    g3a.png

     

    g3b.png

     

  4. Select 'Search'.
                                                                                
    g4.png

     

  5. A list of matching results will be displayed in the table at the bottom of the page.
                                                            
    g5.png

     

Appendix: Google events to FortiDLP event types.

Google events are given in bold, with the FortiDLP event types underneath.

 

g_appendix.png

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!