Troubleshooting tip: FortiDLP Cloud connector policies
| Description | This article provides tips for troubleshooting FortiDLP Cloud connector policies. |
| Scope | FortiDLP. |
| Solution | When configuring cloud connector policies, there are several steps that can be taken in order to troubleshoot why something may not be working as expected.
The first thing to verify is that the events that are coming through are indeed associated with the correct user. To confirm that this is configured correctly, first find the UUID of the user from the Users page in the FortiDLP console:
Then copy this and use it in the API endpoint '/api/v2/users/{uuid}/useruri', to verify the URIs associated with the user. The URIs should include a username URI that matches either the primary email or UPN of the user in Google/Microsoft. If this does not exist, then it can be added either via a cloud sync (found in this document Integrate under 'Microsoft' or 'Google') or manually added using the '/api/v1/admin/users/{id}/useruris' API endpoint.
It is important to note that cloud connector policies, as they are associated with a specific user rather than a specific machine, should only be scoped to entities using user labels. If a policy group includes certain entities based on a machine label, then the cloud policies within that group will not be applied to anyone.
To configure the Microsoft cloud connector, auditing must be enabled in the Microsoft 365 org. This can be confirmed via the Compliance portal or PowerShell, and full instructions can be found in this document: Enabling the Microsoft SharePoint and OneDrive Connector.
If a cloud connector policy is not raising a detection when it is expected to, a worthwhile troubleshooting step is to ensure that the expected triggers (e.g., when a file is shared or deleted) are present in the Microsoft/Google audit log.
Appendix: Purview operation names to FortiDLP event types. Operation names are given in bold, with the FortiDLP event types underneath.
Appendix: Google events to FortiDLP event types. Google events are given in bold, with the FortiDLP event types underneath.
|
















