Netskope LogoNetskope Logo
  • Security Services
  • AI Services
  • Networking Services
  • Analytics Services
  • Integrations
  • getting-started.svgGetting Started
    • Support
    • Community
    • Netskope.com
    © 2026 All Rights Reserved. Netskope Inc.
    Home
    Data Security Posture Management (DSPM)
    Using The DSPM Platform
    Managing Classification and Tagging
    Configure Entity Data Types and Sensitivity Levels

    Configure Entity Data Types and Sensitivity Levels

    Overview

    This article guides you through configuring Entity Data Types (EDT) and Entity Sensitivity Levels (ESL) for your Data Loss Prevention (DLP) entities. These settings enable Netskope DSPM to group data effectively and prioritize risk in your dashboard reporting.

    Understand the DSPM Inventory Approach

    Unlike traditional DLP, Netskope DSPM adopts an “Inventory-First” approach. The goal of configuring EDT and ESL is to build a comprehensive map of your data landscape, not just to trigger violation alerts. Even if no policy is violated, these settings allow you to visualize exactly where your sensitive data resides.

    Prerequisite: You must have the DSPM feature enabled on your tenant to use these settings.

    Access Entity Settings

    To configure the DSPM-specific metadata (EDT and ESL), you must edit the individual DLP entity.

    1. Go to Policies > DLP > DLP Rules > Select Entities.

    2. Click on an existing custom entity name to edit it, or click New Entity to create one.

    Configure the Entity Data Type

    The Entity Data Type (EDT) unifies structured and unstructured rules that detect similar content to simplify reporting and policy creation. For example, instead of selecting every individual rule that looks for a Social Security Number (SSN), you can assign the “National ID” EDT to those entities. This allows you to filter reports or build policies using a single data type rather than managing multiple distinct rules.

    To configure the EDT:

    1. In the entity configuration window, locate the Data Type field.
    2. Select the category that best fits your entity (e.g., select “Address” for any entity related to geographic locations).

    Entity Data Type Display for SaaS Data Stores

    When DSPM classifies data from SaaS applications (such as OneDrive, SharePoint, or Google Drive), each classified item displays an EDT that identifies the category of sensitive data detected.

    In some cases, the classification source may not provide an explicit EDT value. When this occurs, DSPM applies the following fallback logic to determine the displayed value:

    1. Entity name: If the EDT is unavailable, DSPM displays the name of the matched entity (e.g., US-SSN-Name or persons/proper_names/us/last).
    2. Rule name: If neither the EDT nor the entity name is available, DSPM displays the name of the matched DLP rule (e.g., Name-Credit Card (CC)).

    As a result, you may see entity names or rule names in the Entity Data Types column for SaaS data stores on the Classification Management, Data Store Inventory, and Deep Privilege Analysis pages. These values represent valid classification matches and can be used for filtering and policy configuration.

    Set the Entity Sensitivity Level (ESL)

    The Entity Sensitivity Level (ESL) defines the severity of the risk if this specific data is exposed. DSPM uses the ESL to filter incidents and highlight the most critical risks on your dashboard:

    DSPM evaluates the Entity Sensitivity Levels referenced in your rules and automatically picks the highest severity amongst the matching entities.

    To set the ESL:

    1. In the entity configuration window, locate the Sensitivity Level dropdown.
    2. Select Critical, High, Medium, Low, or Not Sensitive based on the risk definitions below.

    Sensitivity Levels Reference

    Level DescriptionDSPM Priorization
    Critical
    Data posing the most severe risk or highest regulatory impact.

    Top priority. Immediate attention required.
    HighData that carries significant risk or regulatory fines (e.g., PHI, SSNs).High priority. Triggers significant alerts.
    Medium (Default)Sensitive data with moderate risk. This is the default if you do not select a level.Standard priority. Standard monitoring.
    LowLow-risk or internal-only data (e.g., internal project codes).Lower priority. Appears in reports but rarely triggers critical alerts.

    Not Sensitive

    Data that does not require security monitoring or is public.
    Excluded from risk prioritization.
    If an entity is used in a Column Classification rule but lacks an Entity Data Type (EDT) or Entity Sensitivity Level (ESL), it will not populate correctly in the DSPM Risk Dashboard. Ensure every entity you plan to use for DSPM has these two fields configured.

    Apply Changes

    After saving any DLP configuration, you must click Apply Changes for your settings to take effect in DSPM. This action pushes your new configurations to the DLP appliance and to DSPM for SaaS Apps.

    You can apply changes at any time; you do not need to wait until a profile is fully configured. For example, you can define a profile, tweak one of its rules, and then apply changes immediately.

    In this Topic
    • Configure Entity Data Types and Sensitivity Levels