What's New

This section lists the new features, enhancements or fixes added to the current revision.

User Management

User management for App Security is now integrated with the Forcepoint Data Security Cloud platform. Administrators can centrally configure users, assign roles, and manage access rights for App Security features using the platform’s unified Admin controls.

For more details on managing users and roles, see the User management section.

Microsoft OneDrive and SharePoint API Scanning Support

App Security now extends API scanning support to Microsoft OneDrive and Microsoft SharePoint with three new event types — file download, file upload, and file viewed. This expansion gives organizations deeper visibility and stronger policy enforcement across their Microsoft 365 environment.

The following event types are now supported for OneDrive and SharePoint:
  • File download: Detect and enforce actions when a file is downloaded.
  • File upload: Detect and enforce actions when a file is uploaded.
  • File viewed: Generates audit log entries when a file is accessed or viewed. No DPS action is performed for this event type.
The following DPS actions are supported for File download event type:
  • Permit
  • Safe copy
  • Quarantine with a note
To learn more about supported DPS actions per application and event type, see DPS actions Supported for API scanning.
Note: This feature is being rolled out gradually. If you do not see the additional events in CASB API logs, raise a support case with Forcepoint Support.

Google Drive Badge Labels for API Scanning

App Security now supports reading Google Drive classification labels and using them as criteria for API scanning policies. When a file's label is deleted, changed, or shared in violation of its classification, App Security detects the event and evaluates the configured policies automatically without downloading the file.

Administrators can configure API Google Labels policies to enforce the following actions based on label status and file sharing events:
  • Restore the original classification label if it is deleted or changed
  • Remove sharing access based on label sensitivity
  • Notify file owners and actors when a policy is triggered
Note: This feature requires Google Badge Labels to be configured and published in the Google Admin Console before enabling them in App Security. Two additional OAuth scopes must be added to the existing service account in Google Admin Console.
Note: This feature is being rolled out gradually. If you do not see the additional events in CASB API logs, raise a support case with Forcepoint Support.

Google Drive File Attributes for API Scanning

App Security now supports reading Google Drive file attributes as criteria for API scanning policies. The Searchable attribute controls whether a file can be discovered through Google Drive search or is accessible only via a direct link.

Administrators can configure API Google Attributes policies to enforce the following action when a file's searchability setting changes to a less restrictive state:
  • Restrict the file to link-only access, removing it from Google Drive search results
Note: This feature is being rolled out gradually. If you do not see the additional events in CASB API logs, raise a support case with Forcepoint Support.

Dedicated IP address

App Security now supports dedicated IP addresses for Inline CASB proxy traffic. This feature ensures that proxy traffic originates from a consistent, identifiable IP address, enabling organizations to allowlist Forcepoint IP addresses in their cloud application firewall rules with greater precision.

Note: Dedicated IP for CASB is not self-service. There are no customer-side setup steps required. If your organization requires a dedicated IP for CASB, contact your Forcepoint Account team to enable this feature.