Objective:
This article provides step-by-step instructions on how to enable the Citrix ShareFile connector and configure Netskope DLP policies to prevent users from moving or uploading sensitive files into personal folders.
Prerequisite:
-
Netskope Tenant with API Data Protection or Real-time Protection enabled.
-
Citrix ShareFile Administrator credentials for initial instance setup.
-
Minimum Version: R100 or later for Next Gen API Data Protection support.
Context:
Organizations often need to ensure that sensitive corporate data remains within managed "Shared Folders" and is not exfiltrated to a user's "Personal Folders" within Citrix ShareFile. Netskope provides visibility and enforcement to block these specific activities.
Configuration:
-
Enable the Citrix ShareFile Connector
-
Navigate to Settings → Configure App Access → Next Gen API Data Protection.
-
Click Setup Instance and select Citrix ShareFile.
-
Enter your ShareFile domain and follow the OAuth flow to authorize Netskope.
-
Ensure Audit and DLP are toggled to On.
-
-
Define the DLP Profile
-
Go to Policies → DLP Profiles.
-
Create or select a profile that identifies the sensitive data (e.g., PII, PCI, or Internal Confidential) you wish to protect.
-
-
Create the Real-time Protection Policy
-
Go to Policies → Real-time Protection → New Policy.
-
Source: Select the target Users or Groups.
-
Destination:
-
Cloud App: Citrix ShareFile.
-
Activity: Select
UploadandMove.
-
-
Content: Select the DLP Profile created in Step 2.
-
Action: Select
Block. -
Set User Notification: (Optional) Create a custom message: "Upload/Move of sensitive data to Personal Folders is prohibited by corporate policy."
-
-
Targeting Personal Folders (Path Filtering)
-
Under the Object section of the policy, add a filter for Folder Path.
-
Specify the path pattern used by ShareFile for personal directories (e.g., containing
/Personal Folders/).
-
Lab Recreate:
-
Login to the ShareFile web interface.
-
Attempt to upload a file containing test sensitive data (e.g., a test credit card number) directly into the "Personal Folders" section.
-
Verify that the Netskope block page is displayed and an alert is generated in SkopeIT → Alerts.
Conclusion: By combining the Citrix ShareFile API connector with Real-time Protection policies, administrators can effectively segment data movement within the app, ensuring sensitive content stays in authorized shared locations.
Terms and Conditions: All documented information is tested and verified. Updates will be made if platform changes occur.
Notes:
-
Instance Tagging: If users have personal ShareFile accounts, use Instance Tagging to apply different policies to corporate vs. personal instances.
-
Activity Mapping: In some ShareFile versions, a "Move" may be logged as a
Deletefollowed by anUpload. Ensure both activities are monitored.



