Help us improve your experience.

Let us know what you think.

Do you have time for a two-minute survey?

 
 

Create a CASB Profile

You configure Cloud Access Security Broker (CASB) rules to control specific actions on each cloud application to secure your data.

By default, Juniper Secure Edge provides a pre-populated profile called default-casb-profile. You can choose to either modify and use the pre-populated profile, or create your own profile.

Once you create a CASB profile, assign it to a Secure Edge policy. By default, the cloud application groups are selected as shown in Table 1 for the respective CASB-supported cloud applications. You cannot edit these groups on the Secure Edge Policy page as this option is grayed out.

Table 1: Cloud Application Group for CASB-Supported Cloud Applications

CASB-Supported Cloud Applications

Corresponding Cloud Application Group

Amazon EFS

casb-amazonefs-group

Amazon S3

casb-amazons3-group

Box

casb-boxnet-group

Dropbox

casb-dropbox-clear-group

GitHub

casb-github-group

Gmail

casb-gmail-group

Google Docs

casb-google_docs-group

Microsoft OneDrive

casb-onedrive-group

Microsoft OneDrive Personal

casb-onedrive_personal-group

Microsoft Teams

casb-msteams-group

Salesforce

casb-salesforce-group

SharePoint

casb-sharepoint-group

Slack

casb-slack-group

To create a new CASB profile:

  1. Select Secure Edge > Security Subscriptions > CASB > CASB Profiles.

    The CASB Profiles page opens.

  2. Click + to create a CASB profile.

    The Create CASB Profile page opens.

  3. Complete the configuration according to the guidelines provided in Table 2.
  4. Click OK.

    A new CASB profile is created. You can assign the CASB profile to a Secure Edge policy. Ensure to select the cloud application groups for the respective CASB-supported cloud applications. For more information on how to select the cloud application groups, see Security Subscriptions row in the Fields on the Secure Edge Policy Add Page table in Add a Secure Edge Policy Rule.

    For example, if your CASB profile covers Amazon EFS and Amazon S3 applications, choose casb-amazonefs-group and casb-amazons3-group respectively.

Table 2: Fields on the Create CASB Profile Page

Setting

Guideline

Name

Enter a unique string of alphanumeric characters; special characters other than -_!@$&*~:. are not allowed. No spaces are allowed; maximum length is 29 characters.

Activity logging

Define activity logging for the CASB profile. For example, Login, Download, and Chat.

By default, all the options are selected.