Print
PrivaceraCloud Documentation
Table of Contents
Table of Contents
PrivaceraCloud Documentation
PrivaceraCloud Release 4.5
PrivaceraCloud release 4.5
Privacera Access Manager
What’s new
Enhancements
Privacera Discovery
Enhancements
Privacera Encryption
What's new
PrivaceraCloud UI
What's new
Enhancements
Supported versions of third-party systems
Documentation changelog
Known Issues in PrivaceraCloud 4.5
PrivaceraCloud User Guide
PrivaceraCloud
What is PrivaceraCloud?
Key Features
Basic Concepts
How PrivaceraCloud Works
Getting Started with Privacera Cloud
Create PrivaceraCloud account
First steps in a new account
Data access methods
Data access server
PolicySync
Plug-in connections
Setup wizard
Prerequisites
Connect application
Connect users
Data access Users, Groups, and Roles
UserSync
Portal user LDAP/AD
User Interface
Dashboard
Access Manager
Access Manager
Policies
Data access users
Options in Access Manager
Resource Policies
Service/Service group global actions
Service actions
Policy definition
Configure Hive resource policy
Tag Policies
Example: Tag Assignment via Apache Ranger API
Adding the privacera_tag Service
Tag Policies UI
Example
Scheme Policies
Service Explorer
Reports
Search/Filter Options
View/Edit Reports
Export Policy Reports
Audit
PEG API Accesses
About data access users, groups, and roles resource policies
Users
Groups
Roles
Security zones
Create a security zone
Edit or view a security zone
Delete security zone
Discovery
Classifications via random sampling
Supported JDBC applications for random sampling
Prerequisites for random sampling
Define datasource (application) and configure random sampling
Effects of random sampling
Performance impact
Variations in classifications
Privacera Discovery scan targets
Disable or reenable Privacera Discovery
Connect Applications
Discovery scan targets
Start a scan
View a scan
Propagate Privacera Discovery Tags to Ranger
Propagate Discovery Tags to Ranger
General process for configuring an application
Validate the configuration
Create user
Get Ranger Admin URL
Preview: Scan Generic Records with NER Model
Supported tags
Tags
Usage statistics
Encryption and Masking
Privacera Encryption core ideas and terminology
Graphical view of encryption processes
Encryption architecture and UDF flow
Hierarchy and Types of Encryption Keys
Hierarchy and types of encryption keys
Master Key
Key Encryption Key (KEK)
Data Encryption Key (DEK)
Encrypted Data Encryption Key (EDEK)
Key Security
Encryption Schemes
Encryption Schemes
System Encryption Schemes Enabled by Default
List of System Encryption Schemes
View Encryption Schemes
Formats, Algorithms, and Scopes
Formats
Algorithms
About LITERAL
Scopes
Record the Names of Schemes in Use and Do Not Delete Them
System Encryption Schemes Enabled by Default
List of System Encryption Schemes
Viewing the Encryption Schemes
Formats, Algorithms, and Scopes
Formats
Algorithms
About LITERAL
Scopes
Record the Names of Schemes in Use and Do Not Delete Them
Presentation Schemes
Presentation Schemes
Viewing the System Presentation Schemes and Other Functions
List of System Presentation Schemes
Create a Custom Presentation Scheme
Viewing the System Presentation Schemes and Other Functions
List of System Presentation Schemes
Create a Custom Presentation Scheme
Masking schemes
Masking techniques
Masking with the Encryption REST API
Create custom masking scheme
Prerequisites
Create a masking scheme
Create scheme policies on PrivaceraCloud
Prerequisites for creating a scheme policy
Steps to create scheme policies
Encryption formats, algorithms, and scopes
Encryption formats, algorithms, and scopes
Deprecated encryption schemes
Numeric formats with FPE algorithm: input must be string
Privacera API
Format: Alphanumeric
Format: ASCII
Format: CC
Formats: DATE and Date_DD_MM
Format: Driver License
Format: Email
Format: FPE_ALPHA_NUMERIC
Format: HASHING
Format: Host/Domain
Format: IP
Format: LITERAL
Format: Numeric
Format: SSN
Format: Text
Bouncy Castle API
Date input formats and ranges
Supported date range
Legend for date input formats
Day-first formats
Month-first formats
Year-first formats
Examples of allowable date input formats
Deprecated encryption formats, algorithms, and scopes
Deprecated encryption formats, algorithms, and scopes
Deprecated: IP
Deprecated: Host/Domain
Deprecated: Text
Deprecated: Driver License
Deprecated: LITERAL
Deprecated: Alphanumeric
PEG REST API on PrivaceraCloud
PEG API Endpoint
Request Summary for PrivaceraCloud
Prerequisites
API Key
Scheme policy required for protect and unprotect API endpoints
Anatomy of a PEG API endpoint on PrivaceraCloud
About constructing the datalist for /protect
About deconstructing the response from /unprotect
Example of data transformation with /unprotect and presentation scheme
Example PEG REST API endpoints for PrivaceraCloud
/protect with encryption scheme
/protect with masking scheme
/protect with both encryption and masking
/unprotect without presentation scheme
/unprotect with Presentation Scheme
/unprotect with masking scheme
Audit details for PEG REST API accesses
Make calls on behalf of another user on PrivaceraCloud
Privacera Encryption UDF for masking in Databricks
Syntax of Databricks UDF for masking
Prerequisites for Databricks masking UDF
Define the mask UDF in Databricks
Example query to verify Privacera-supplied mask UDF
Privacera Encryption UDFs for Trino
Syntax of Privacera Encryption UDFs for Trino
Prerequisites for installing Privacera Crypto plug-in for Trino
Variable values to obtain from Privacera
Determine required paths to crypto jar and crypto.properties
Download Privacera Crypto Jar
Set variables in Trino etc/crypto.properties
Restart Trino to register the Privacera Crypto UDFs for Trino
Example queries to verify Privacera-supplied UDFs
Azure AD setup
Create Azure AD application
Configuring SAML in Azure AD
Launch Pad
Scripts for AWS CLI or Azure CLI for managing connected applications
Prerequisites
Generate security token
Download security token and Linux shell script
AWS
Azure
Settings
General functions in PrivaceraCloud settings
Applications
About applications
Terminology
Connect an application
View connection status
Edit application name and description
Delete application
Azure Data Lake Storage Gen 2 (ADLS)
Prerequisites
Connect Azure Data Lake Storage Gen 2 (ADLS) to PrivaceraCloud
Athena
Prerequisites in AWS console
Connect Athena with IAM role and trust relationship
Privacera Discovery with Cassandra
Prerequisites
Connect application
Define scan targets
Databricks
Databricks Spark Fine-Grained Access Control plug-in [FGAC]
Databricks Spark Object-Level Access Control plug-in [OLAC]
Databricks cluster deployment matrix with Privacera plugin
Access AWS S3 using Boto3 from Databricks
Access Azure file using Azure SDK from Databricks
Databricks SQL
Databricks SQL Overview and Configuration
Planning and general process
Prerequisites
Databricks SQL with Privacera Hive
Connect application
Grant Databricks SQL permissions to PrivaceraCloud users
Define a resource policy
Test the policy
Databricks SQL PolicySync fields
Configuring column-level access control
View-based masking functions and row-level filtering
Create an endpoint in Databricks SQL
Databricks SQL Fields
Databricks SQL Hive Service Definition
Hive-to-Databricks SQL Permission Mapping
Databricks SQL Masking Functions
Databricks SQL Encryption
Prerequisites
Grant permission in encryption scheme policy
Configure Databricks
Configure Privacera resource policies
How to use UDFs in SQL to encrypt and decrypt
Dremio
Connect Application
Configure Privacera plugin
RPM
Kubernetes
DynamoDB
Prerequisites in AWS console
Connect application
Enable Privacera Access Management
Elastic MapReduce from Amazon
EMR: Hive, PrestoDB, PrestoSQL
Connect application
Obtain installation script
Configure EMR cluster
EMR Spark (Fine-Grained Access Control)
EMR Spark (Object Level Access Control)
EMRFS S3
Connect application
Files
Connect application
File Explorer for Google Cloud Storage
Connect application
Using File Explorer with GCS
Glue
Prerequisites
Connect application
Enable Privacera Access Management
Google BigQuery
Connect Application
Connector Properties
Kinesis
Prerequisites
Connect application
Enable Privacera Access Management
Lambda
Prerequisites in AWS console
Connect application
Enable Privacera Access Management
Microsoft SQL Server
Connect application
Add data source
MySQL for Discovery
Prerequisites
Connect application
Add data source
Open Source Spark
Obtain installation script
Configure Privacera Plugin on local/virtual machine
FGAC with multiple JWT configurations
Configure Privacera Plugin in an Existing Docker File
FGAC with Multiple JWT Configuration in an Existing Docker File
Configure Privacera Plugin using Privacera Scripts
Deploy Spark on EKS Cluster
Oracle for Discovery
Prerequisites
Connect application
Add data source
PostgreSQL
Prerequisites
Connect application
Accessing PostgreSQL Audits in GCP
Configure AWS RDS PostgreSQL instance for access audits
Update the AWS RDS parameter group for the database
Create an AWS SQS queue
Specify an AWS Lambda function
Create an IAM role for an EC2 instance
Accessing Cross Account SQS Queue for PostgreSQL Audits
Power BI
Connect Application
Connector properties
Presto
Connect application
Connect Presto on Qubole cluster PrivaceraCloud
Redshift
Connect application
Add Data Source
Redshift Spectrum
Redshift Spectrum
Prerequisites
Getting started
Major Security Concern
Limitations
Proposed Solution
Configuration
Kinesis
Prerequisites in AWS console
Connect application
Enable Privacera Access Management
Enable Data Discovery
Snowflake
Prerequisites
Connect application
Enable Privacera Access Management
Object permission mapping
Enable Data Discovery
Add Data Source
Starburst Enterprise with PrivaceraCloud
Prerequisites
Configure Privacera plug-in with Starburst Enterprise
Connect Starburst Enterprise application
Starburst Enterprise Presto
Starburst Enterprise Presto
Create a SEP service user
Get the account specific API URL
Connect application
Configure Starburst Enterprise (SEP) to use your Account PrivaceraCloud Ranger
Synapse
Trino
Connect application
Deploy Privacera plug-In in Trino
Validate Installation
Datasource
LDAP/AD
Add system
Connect application
SAML
Activate Single Sign-On (SSO)
Effects of enabling SSO
Connect IdP (Okta and Azure AD)
Enable only SSO login
SSO URL without login screen
UserSync in PrivaceraCloud
UserSync: Data Access Users
Connect application
Azure Active Directory fields for UserSync
LDAP/AD fields for UserSync
Okta fields for UserSync
SCIM fields for UserSync
SCIM Server fields for UserSync
User Management
Add users
Edit or delete user
Edit user profiles
API Key
User interface
Manage API keys
Generate new API keys
Actions on the Key:
Manage certificates for AWS EMR native Ranger plug-Ins
About Account
Activity
Manage this account
Allowed IP address
Discovery
AWS
Azure ADLS
Privacera Encryption
Authentication settings
Enable Privacera audit access
Statistics
Help
Apache Ranger API
PrivaceraCloud Apache Ranger API Access
Establish access credentials for Basic Auth authentication.
Generate a Ranger Admin API URL
Test and Confirm Access
Example
Reference
Okta Setup for SAML-SSO
Generate an Okta Identity Provider Metadata File and URL
IdP provider metadata
IDP initiated SSO
Azure AD setup
Create Azure AD application
Configuring SAML in Azure AD
SCIM Server User-Provisioning
Enable SCIM Server in PrivaceraCloud
Okta Identity Provider Integration
Prerequisites
Integration Steps
Step 1. Enable SCIM API Integration in Okta
Step 2: Activate application features
Step 3. Verify Email Addresses
Step 4. Push Groups
Step 5. Assign Users to the PrivaceraCloud Application in Okta
Step 6. Write a Policy for Provisioned Users or Groups
Supported Okta SCIM Client Operations
User Operations
Group Operations
SCIM Server API
Supported SCIM REST API Requests
AWS Access with IAM
Access AWS S3 buckets from multiple AWS accounts
Add UserInfo in S3 Requests sent via Dataserver
Steps
EMR Native Ranger Integration with PrivaceraCloud
EMR Native Ranger Integration with PrivaceraCloud
Prerequisite
Configuration
Certificate setup in Secrets Manager
IAM roles setup
Recommended CloudFormation setup
Manually setup IAM roles
Create security configurations
Recommended CloudFormation setup
Manually Setup Security Configurations
Create EMR cluster
Recommended CloudFormation setup
Manually setup EMR cluster
Application usage
Spark
Hive
AWS documentation references
Spark Properties
Fine-grained Access Control
Databricks-related properties
Privacera-related properties
Object-level Access Control
Databricks-related properties
Privacera-related properties
Operational Status
How-to
Create CloudFormation Stack
Enable Real-time Scanning of S3 Buckets
Enable Discovery Realtime Scanning Using IAM Role
Create an IAM role with AWS S3 permissions
Configure AWS S3 access using IAM role
Enable Data Discovery
How to configure multiple JSON Web Tokens (JWTs) for EMR
Validations with JSON Web Tokens (JWTs)
Enable offline scanning on Azure Data Lake Storage Gen 2 (ADLS)
Get Azure Storage account name, account key, and URL prefix
Connect ADLS Gen2 Application for Data Discovery
Enable Real-time Scanning on Azure Data Lake Storage Gen 2 (ADLS)
Prerequisites
Create a Storage Account and Event Subscription for Scanning
Connect ADLS Gen2 Application for Data Discovery
Connect ADLS Gen2 Application for Data Discovery
How to Get Support
Set up a Privacera Support Portal Account
Create Tickets
View Your Tickets
Support Ticket Lifecycle
PrivaceraCloud Support
Permitted Remote Access
Coordinated Vulnerability Disclosure (CVD) Program of Privacera
Security researcher responsibilities
Privacera responsibilities
Shared Security Model
Shared Security Model
Privacera Responsibility
Access, Authentication, and Authorization
Secure development
Information Technology systems
Customer Responsibility
Governance and security teams
Account Administrators and Data Owners
All users
Privacera (SaaS) or Customer (Self-hosted) Responsibility
IaaS Provider Responsibility
PrivaceraCloud Previews
Preview: File Explorer for S3
Prerequisites
Connect S3 Application
Modify Resource Policy
File Explorer
Example
Preview: File Explorer for Azure
Prerequisites and Setup
General Process
Connect ADLS Gen2 application
Modify Resource Policy
File Explorer
Example of Allowing/Deny Access
Preview: File Explorer for GCS
Prerequisites and Setup
General Process
Connect GCS application
Modify Resource Policy
File Explorer
Example of Allowing/Deny Access
Preview: Scan Generic Records with NER Model
Supported tags
Tags
Preview: Scan Electronic Health Records with NER Model
Supported tags
Tags
Preview: OneLogin UserSync
Prerequisites
Privacera UserSync Configuration
OneLogin Configuration
Preview: PingFederate UserSync
Prerequisites
Privacera Usersync - SCIM Server integration
PingFederate configuration steps
Privacera Usersync configuration steps
Privacera Usersync - SCIM integration
PingFederate configuration steps
Privacera Usersync configuration steps
PrivaceraCloud documentation changelog
2022.07.25
2022.05.24
Next
PrivaceraCloud Documentation
Your source of documentation for cloud services & more.
Copyright ©
: