Skip to main content

Cloud Access Rules on Zenconsole

Published on:
.
2 min read

Zenarmor® provides Cloud Access Security Broker (CASB) capabilities that allow you to control access to supported cloud applications and their individual actions.

Cloud Access rules provide granular control over cloud services by allowing you to:

  • Block or allow an entire cloud application.
  • Block or allow individual actions within an application.
  • Apply cloud access restrictions through matching policies.
  • Reduce the risk of unauthorized data sharing and sensitive information exposure.

For example, you can allow users to access a cloud storage application while blocking specific actions such as uploading, downloading, sharing, or deleting files, depending on the actions supported by the application.

Figure 1. Cloud Access Rules in a Policy

note

The Cloud Access Security Broker (CASB) feature is available only for SSE and higher subscriptions.

To set the policy-based Cloud Access Security Broker (CASB) capability, you may go to Cloud Access page of a policy on your Zenconsole by following the instructions provided in this guide:

  1. Sign in to Zenconsole.
  2. Select the organization you want to manage.
  3. Navigate to Policies > Internet Security Policies.
  4. Select the policy that you want to configure CASB.
  5. Navigate to the Cloud Access tab.

The Cloud Access page displays the cloud applications and application actions supported by Zenarmor.

Here is a video about Zenarmor Cloud Access Security Broker (CASB) feature.

Understanding the Cloud Access Page

The All Applications table provides the following information:

  • Application Name: Displays the name of the supported cloud application.
  • Number of blocked actions: Displays the number of blocked actions compared with the total number of actions available for the application.
  • Status: Displays whether the application is allowed or blocked by default and provides a toggle for changing its application-level status.

The application-level status may display one of the following values:

  • Allowed application by default: Access to the application is allowed. You can expand the application and configure its supported actions individually.
  • Blocked application by default: The entire application is blocked. Individual application actions cannot be configured while the application remains blocked.

Select the arrow next to an application name to expand or collapse its supported actions. Each action has its own status and toggle.

Figure 2. Understanding Cloud Access Page

note

Application-level and action-level controls serve different purposes. Blocking an application prevents access to the entire application. To configure individual actions, the application must first be allowed at the application level.

Searching for a Cloud Application to Filter

The Cloud Access page includes supported cloud applications and their available actions. Use the Search box to locate a specific application or action by entering its name.

Figure 3. Searching Cloud Application

Blocking a Cloud Application

You can block an entire cloud application for traffic that matches the policy by following these steps:

  1. Sign in to Zenconsole.

  2. Navigate to Policies > Internet Security Policies.

  3. Select the policy that you want to configure.

  4. Navigate to the Cloud Access tab.

    Figure 4. Default CASB Rules

  5. Find the cloud application that you want to block. You can use the Search box to locate it.

  6. Enable the toggle in the Status column for the application.

  7. If the policy does not meet the requirements for Cloud Access controls, Zenconsole displays a warning before applying the change. Review the following settings shown in the warning:

    • Full TLS Inspection must be enabled.
    • Category-Based TLS Inspection must include the relevant category, such as Generative AI.
    • QUIC UDP connections must not remain allowed.

    Click Cancel to return to the policy and correct the required settings, or click Proceed to continue with the rule.

    Figure 5. Cloud Access Configuration Warning

  8. After the application is blocked, its status changes to Blocked application by default, and all supported actions for that application are blocked.

    Figure 6. Blocking a Cloud Application

  9. Synchronize the policy via the Sync Now button on the policies list to activate the settings.

  10. To allow the application again, disable its toggle in the Status column.

Blocking a Cloud Application Action

You can allow access to a cloud application while blocking one or more of its supported actions.

To block a cloud application action, follow the steps below:

  1. Sign in to Zenconsole.

  2. Navigate to Policies > Internet Security Policies.

  3. Select the policy that you want to configure.

  4. Navigate to the Cloud Access tab.

  5. Make sure that the application is allowed at the application level.

  6. Click the arrow next to the application name to display its available actions.

  7. Enable the toggle next to each action that you want to block.

    Figure 7. Blocking a Cloud Application Action

  8. If Zenconsole displays the Cloud Access configuration warning, review the listed TLS inspection and QUIC requirements. Click Cancel to correct the policy settings or Proceed to continue.

    Figure 8. Cloud Access Configuration Warning

  9. Synchronize the policy via the Sync Now button on the policies list to activate the settings.

  10. To allow a blocked action again, disable its toggle.

tip

The "Number of blocked actions" column in the application displays the overall count of actions that have been prevented. As seen in the above diagram, 5 out of 16 activities performed on the Dropbox program are blocked.

note

Policy changes are automatically synchronized with associated gateways and endpoints within a maximum of 15 minutes. To apply the changes immediately, click Sync Now on the Internet Security Policies page and confirm the synchronization request.