Skip to main content

Check out Interactive Visual Stories to gain hands-on experience with the SSE product features. Click here

Skyhigh Security

Create Data Jurisdictions for Shadow IT

Shadow Data Jurisdictions are the second layer of access control for Skyhigh CASB users. Data Jurisdictions for Shadow IT are based on Active Directory Attributes or Cloud Connector Tags.  

  1. Go to Settings > User Management > Data Jurisdiction
  2. On the Data Jurisdictions page, click New Jurisdiction
    clipboard_e752ab7c811535e7ee7ce9e94947814c7.png
  3. Click Shadow IT
    clipboard_e82e235dc1627ec49da27787dad0a0b9f.png
  4. On the New Shadow IT Data Jurisdiction page, configure the following details:
    • Name. Enter a name for your Data Jurisdiction. 
      clipboard_e9bde180cb43de6a617fd27e60d145d54.png
    • AD Attribute. Define your Data Jurisdiction by selecting one or more AD custom attributes and/or attribute values to associate it with. 
    • Cloud Connector Tag. Define your Data Jurisdiction by selecting one or more Cloud Connector Tags to associate it with. 
  5. Click Save

Once your Data Jurisdiction is defined, you can find Shadow Data Jurisdictions in the Settings > User Management > Users page. Here you can assign users to limit access to the selected Shadow IT data. For more details on users, see About the Users Page.

Edit a Data Jurisdiction

To edit a data jurisdiction:

  1. Go to Settings > User Management > Data Jurisdiction
  2. On the Shadow IT Jurisdictions tab, select the pencil icon to edit. 
    clipboard_e42b17d6788bef1ee4b89ad0b03041c68.png
  3.  Edit the criteria of the Data Jurisdiction by selecting new AD Attributes or Cloud Connector Tags
    clipboard_e338afabf7911b5bddec8a116b8e2823f.png
  4. Click Save
  • Was this article helpful?