Create an Application Instance
For CASB, to differentiate between corporate and non-corporate SaaS application instances, administrators need to configure access policies using the instance parameter. To identify an instance, CASB requires instance ID, domain, and/or type. And, to monitor logs, tagging that are mapped with instances is used.
Each application can have its own instance ID. See Table 1.
Application |
Example URL |
Instance ID |
---|---|---|
For the following example URLs, consider a common string acmecorp07 as the instance ID within the application's SaaS URLs. |
||
Box |
|
acmecorp07 |
GitHub |
Organization name is the instance ID |
acmecorp07 |
Microsoft Teams |
|
acmecorp07ms |
Salesforce |
|
acmecopr7 |
Microsoft OneDrive SharePoint |
|
acmecorp07ms |
Slack |
acmecorp-zoy8730.slack.com |
acmecorp-zoy8730 |
AmazonEFS |
Instance ID is Amazon account ID |
392719858104 |
AmazonS3 |
Instance ID is Amazon account ID |
392719858104 |
Generic URLs where instance ID is not applicable |
||
Dropbox |
dropbox.com |
- |
Gmail |
mail.google.com |
- |
Google Docs |
docs.google.com |
- |
Microsoft OneDrive Personal |
No instance |
- |
Use the Create Application Instance Page to configure application instances.
To create a new application instance:
Setting |
Guideline |
---|---|
Cloud application |
Select a cloud application from the list. |
Name |
Enter a new application instance name. For example, dropbox123. The instance name must begin with an alphanumeric character. Spaces and special characters except for - : . are not allowed. The maximum length is 63 characters. |
Application instance ID |
A unique URL to access SaaS services. Instance ID comes in packet data of all SaaS application activities, such as, upload, download, and share. You use this Instance ID to apply in the Security policies. See Table 1 to enter an application instance ID. |
Login Domain |
An email domain. During login activity, you get an email domain in packets, and it is part of instance. Enter the domain address. For example, acmecorp07.com is an organization domain. Then, for all users, CASB-supported cloud applications uses the same domain. Note:
Domain configuration is not required for the Microsoft OneDrive Personal application. |
Type |
Select a value from the list to map a type with an application instance:
Note:
You must configure the type of value for Dropbox. For other applications, this configuration is optional. |
Tag |
Select a value from the list to map a tagging with an application instance:
|