Skip to main content
Sticky

How to Configure Citrix ShareFile DLP to Prevent Data Movement to Personal Folders

  • September 3, 2026
  • 0 replies
  • 4 views

Objective:

This article provides step-by-step instructions on how to enable the Citrix ShareFile connector and configure Netskope DLP policies to prevent users from moving or uploading sensitive files into personal folders.

Prerequisite:

  • Netskope Tenant with API Data Protection or Real-time Protection enabled.

  • Citrix ShareFile Administrator credentials for initial instance setup.

  • Minimum Version: R100 or later for Next Gen API Data Protection support.

Context:

Organizations often need to ensure that sensitive corporate data remains within managed "Shared Folders" and is not exfiltrated to a user's "Personal Folders" within Citrix ShareFile. Netskope provides visibility and enforcement to block these specific activities.

Configuration:

  1. Enable the Citrix ShareFile Connector

    • Navigate to SettingsConfigure App AccessNext Gen API Data Protection.

    • Click Setup Instance and select Citrix ShareFile.

    • Enter your ShareFile domain and follow the OAuth flow to authorize Netskope.

    • Ensure Audit and DLP are toggled to On.

  2. Define the DLP Profile

    • Go to PoliciesDLP Profiles.

    • Create or select a profile that identifies the sensitive data (e.g., PII, PCI, or Internal Confidential) you wish to protect.

  3. Create the Real-time Protection Policy

    • Go to PoliciesReal-time ProtectionNew Policy.

    • Source: Select the target Users or Groups.

    • Destination:

      • Cloud App: Citrix ShareFile.

      • Activity: Select Upload and Move.

    • Content: Select the DLP Profile created in Step 2.

    • Action: Select Block.

    • Set User Notification: (Optional) Create a custom message: "Upload/Move of sensitive data to Personal Folders is prohibited by corporate policy."

  4. Targeting Personal Folders (Path Filtering)

    • Under the Object section of the policy, add a filter for Folder Path.

    • Specify the path pattern used by ShareFile for personal directories (e.g., containing /Personal Folders/).

Lab Recreate:

  • Login to the ShareFile web interface.

  • Attempt to upload a file containing test sensitive data (e.g., a test credit card number) directly into the "Personal Folders" section.

  • Verify that the Netskope block page is displayed and an alert is generated in SkopeITAlerts.

Conclusion: By combining the Citrix ShareFile API connector with Real-time Protection policies, administrators can effectively segment data movement within the app, ensuring sensitive content stays in authorized shared locations.

Terms and Conditions: All documented information is tested and verified. Updates will be made if platform changes occur.

Notes:

  • Instance Tagging: If users have personal ShareFile accounts, use Instance Tagging to apply different policies to corporate vs. personal instances.

  • Activity Mapping: In some ShareFile versions, a "Move" may be logged as a Delete followed by an Upload. Ensure both activities are monitored.

This topic has been closed for replies.