Palo Alto DLP in 2026: What Enterprise DLP Covers, and Why It Fails Open by Default

Palo Alto DLP in 2026: What Enterprise DLP Covers, and Why It Fails Open by Default

Palo Alto Networks Enterprise DLP is the data loss prevention service that plugs into the firewalls and Prisma Access tunnels a lot of security teams already run. If you are a Palo Alto shop, it is the obvious DLP to evaluate, and it has real detection depth. Before you sign, though, read two pages of Palo Alto's own documentation: the license page and the data filtering settings page. They tell you more about your actual coverage than any demo. If you are weighing the broader platform, our roundup of Palo Alto Prisma Access alternatives covers the architecture question. This post goes deep on the DLP.

The short answer

Palo Alto Enterprise DLP is a cloud-delivered DLP service, sold as an add-on subscription with a separate license for each enforcement point, that inspects traffic after your firewall or Prisma Access decrypts it. Its coverage is defined less by the detection engine than by two things you control: how many channels you license and what your fail-safe settings say. Out of the box, Palo Alto's documentation sets every fail-safe action to Allow, so a file that is too large, a scan that takes too long, or an endpoint that is offline passes through uninspected. dope.security takes a different path: Dopamine DLP reads AI prompts and file uploads on the device, and Cloud Application Control separates corporate and personal AI accounts, in one agent and one console.

That is a checkable claim. Open the Enterprise DLP data filtering settings in your tenant and look at each fail-safe default.

What is Palo Alto Enterprise DLP?

Enterprise DLP is Palo Alto's centralized DLP engine: write data profiles once, apply them wherever Palo Alto sits in the traffic path. According to Palo Alto's license documentation (updated September 10, 2026), the service is sold "as an add-on subscription," and you buy "a separate license for each channel (enforcement point)."

The enforcement points Palo Alto lists today:

  • Next-generation firewalls. Policy built in Panorama with the Enterprise DLP plugin, or in Strata Cloud Manager (SCM).
  • Prisma Access. Inline inspection for remote users and branches on Palo Alto's cloud-delivered security service.
  • Prisma Browser. Palo Alto's enterprise browser, with its own license considerations.
  • Email DLP. A separately licensed channel that requires a Data Security, CASB-X, or CASB-PA license.
  • Endpoint DLP. A separately licensed channel delivered through the Prisma Agent that requires Prisma Access 5.1 or later.

Palo Alto also announced an Endpoint DLP add-on for Cortex XDR 5.0 in February 2026, which classifies on the device. That is two endpoint DLP products on two different agents. If you want the platform overview first, start with our explainer on what Prisma Access is.

How Enterprise DLP licensing works

The license menu is where most buyers get surprised. Palo Alto's documentation lists these options:

  • CASB-X. A cross-platform bundle of AI Access Security, Enterprise DLP, and SaaS Security.
  • CASB-PA. A Prisma Access add-on that includes inline Enterprise DLP.
  • AI Access Security. A standalone license for generative AI app visibility and control.
  • Data Security. SaaS Security Inline plus Enterprise DLP.
  • Enterprise DLP Standalone. One, three, or five-year terms.
  • Email DLP and Endpoint DLP. Separate channels with the prerequisites above.

The AI piece has its own wrinkle. Palo Alto's AI Access Security license documentation (August 11, 2026) says that on its own, AI Access Security forwards only generative AI app traffic to Enterprise DLP, and "Traffic containing sensitive data is not forwarded to Enterprise DLP for non-GenAI apps." To inspect everything else, you need Enterprise DLP, CASB-PA, or CASB-X. A Prisma Browser license alone gets you the AI Access dashboard, and network coverage requires buying AI Access-X or CASB-X separately. Without an Enterprise DLP license, the Prisma Browser DLP tenant is read-only, limited to regex patterns and OCR.

None of this is hidden. The DLP you get is simply the sum of the boxes you check.

How Palo Alto DLP inspects traffic

Enterprise DLP sees what the firewall or Prisma Access decrypts, and nothing else. Palo Alto's enablement guide spells out what that requires:

  • SSL Forward Proxy decryption. Inline DLP depends on decrypting the session on the firewall or in Prisma Access.
  • A rule to drop QUIC. Palo Alto's note names Gmail as an app that needs this, so traffic falls back to inspectable TLS.
  • A decryption rule above the Microsoft 365 exclusions. Microsoft 365 is excluded from decryption by default, so your decrypt rule has to sit higher in the list to inspect it.
  • Exclusions for pinned apps. Applications with pinned certificates must be excluded from decryption, which also excludes them from inline DLP.

That last point is structural, not a Palo Alto quirk: every exclusion is a destination your DLP policy no longer applies to. We explain why in certificate pinning and SSL inspection, and the same pattern shows up in our look at Zscaler DLP.

The settings page that decides your coverage

This is the section to read twice. Palo Alto's documentation for editing Enterprise DLP data filtering settings (September 25, 2026) lists the fail-safe actions, and each one defaults to Allow:

  • Max latency reached. If the DLP verdict takes too long, the traffic is allowed.
  • File size over the scan limit. Files larger than the configured maximum are allowed.
  • Scanning error. If inspection errors out, the traffic is allowed.
  • Non-file data over the max size. Text payloads above the limit are allowed.
  • Action on any error. The catch-all defaults to Allow.
  • Endpoint offline. For Endpoint DLP, when the endpoint cannot reach the service, the action defaults to Allow.

Palo Alto also notes that these global settings override the action in the DLP rule itself. So a rule that says Block can still let data through if one of those conditions fires and the global default is Allow.

The limits behind those conditions are documented too. On Panorama, the maximum file size is configurable from 1 to 100 MB, and Palo Alto recommends max latency above 60 seconds for files over 20 MB. Endpoint DLP blocks up to 20 MB and alerts up to 100 MB.

Failing open is a defensible design choice. Nobody wants a DLP hiccup to break the business. But it means your day-one coverage is set by defaults you may never have reviewed.

What Palo Alto DLP does well

Credit where it is due. Enterprise DLP has genuine strengths.

  • One policy engine across Palo Alto enforcement points. If you already run NGFWs and Prisma Access, you can define data profiles once and reuse them.
  • A deep detection toolbox. Palo Alto documents data patterns, trainable custom document types, data dictionaries, exact data matching (EDM), and OCR.
  • Machine learning classification. Palo Alto says it ships more than 100 pretrained deep-learning classifiers and over 250 data patterns enhanced with ML and LLMs, and claims more than a 90% reduction in potential false positives. That is a vendor claim, but it is a serious investment.
  • No extra infrastructure. PeerSpot reviewers praise how easy it is to switch on.

Palo Alto also documents its own gaps, which we respect: floating images are not detected with OCR on NGFW or Prisma Access, and data split across line breaks or cells can be missed.

Where it gets complicated for AI

Corporate vs personal AI accounts

The hardest AI test is not "is this ChatGPT." It is "is this our ChatGPT workspace or someone's personal account on the same domain." Palo Alto documents tenant restrictions for Microsoft 365 through HTTP header insertion in Prisma Access, and Prisma Browser supports tenant-based policy for a list of apps. We did not find Palo Alto documentation for a Prisma Access control that separates a corporate ChatGPT workspace from a personal one. Palo Alto's own blog on Prisma Browser argues that a network tool "can't tell if they logged in with a secure corporate SSO or a personal account." We walk through the test in how to block personal ChatGPT while keeping the corporate account.

Customers report configuration and documentation effort

Review volume is thin, so treat this as directional. Palo Alto Enterprise DLP holds 4.1 out of 5 from seven reviews on PeerSpot and 4.7 from a handful of ratings on Gartner Peer Insights. PeerSpot reviewers praise stability and support, and cite documentation gaps, file classification accuracy, configuration detail, and cost.

Palo Alto Enterprise DLP vs dope.security: the head-to-head

Both aim to stop sensitive data from leaving. Here is the comparison, line by line.

  • Where inspection happens. Palo Alto Enterprise DLP inspects traffic after an NGFW or Prisma Access decrypts it with SSL Forward Proxy. dope.security inspects web traffic on the device with an on-device SSL inspection proxy, so there is no decryption hop in someone else's data center.
  • What happens when inspection cannot finish. Palo Alto documents every fail-safe action, including max latency, oversized files, scan errors, and offline endpoints, as defaulting to Allow. Dopamine DLP runs in Block, Monitor, or Off mode, and you choose which, so enforcement is a decision you make rather than a default you inherit.
  • How content is classified. Palo Alto combines patterns, EDM, dictionaries, OCR, and ML classifiers that your team configures and tunes. Dopamine DLP classifies prompts and uploads with large language models through zero-retention OpenAI APIs, with no rule configuration required, and explains each detection in a plain-language Dopamine Summary.
  • Licensing. Palo Alto sells Enterprise DLP as an add-on with a separate license per enforcement point, plus AI Access Security, CASB-X, or CASB-PA for AI and SaaS coverage. dope.security includes SWG, Cloud Application Control, and Dopamine DLP in one platform with no separate AI license.
  • Corporate vs personal AI accounts. We found no documented Prisma Access control for ChatGPT tenant separation. dope.security Cloud Application Control restricts ChatGPT, Claude, Google, and Microsoft 365 to approved corporate tenants and blocks personal logins on the same domain.
  • AI tool coverage. Palo Alto forwards generative AI app traffic to Enterprise DLP through AI Access Security. Dopamine DLP covers ChatGPT, Claude, Perplexity, Abacus, and Copilot.
  • Endpoints. Palo Alto has two endpoint DLP products, one on the Prisma Agent and one on Cortex XDR. dope.endpoint is a single agent, native on Mac and Windows, using under 100 MB of RAM.
  • Data at rest in the cloud. Palo Alto covers SaaS data through SaaS Security licenses. dope.security CASB Neural scans OneDrive and Google Drive for publicly or externally shared files containing PII, PCI, PHI, or IP, with one-click remediation, in the same console.

Dopamine DLP is protected by US Patent 12,464,023. Read how it works in meet Dopamine DLP.

Keep Palo Alto, or close the gap with dope.security?

You do not have to rip out your firewalls. Close the AI and remote-user gap first.

  • Audit the fail-safe defaults today. Whatever you decide, review every Allow in the data filtering settings and write down why it is there.
  • Keep firewall DLP where it earns its keep. Data center and branch traffic that already flows through a Palo Alto NGFW can stay there.
  • Put AI enforcement on the endpoint. Deploy dope.security on Mac and Windows laptops, turn on Cloud Application Control for your AI tenants, and run Dopamine DLP in Monitor mode to see what sensitive data flows into AI tools before you block anything.
  • Write the policy once. Our guide to building a DLP policy maps policy clauses to controls you can actually enforce.

Deployment is the part teams worry about, and it is the part that moves fastest. A Fortune 100 company scaled dope.security from 900 to more than 18,000 devices in weeks, deployed silently through Intune. For the full DLP landscape, see our ranking of the best data loss prevention tools.

The bottom line on Palo Alto DLP

Put simply: Palo Alto Enterprise DLP has a strong detection engine, but what it actually protects is set by how many channels you license, what your firewall is allowed to decrypt, and a settings page where every fail-safe defaults to Allow. If you want AI prompts and uploads inspected on the laptop itself, with personal AI accounts blocked and corporate ones allowed, that is what dope.security was built to do. Explore Dopamine DLP and the Fly-Direct Secure Web Gateway, or book a 20-minute demo and we will run the personal AI account test live.

Frequently Asked Questions

Is Palo Alto Enterprise DLP included with Prisma Access?

No. Palo Alto sells Enterprise DLP as an add-on subscription with a separate license for each enforcement point. For Prisma Access, the CASB-PA add-on includes inline Enterprise DLP, and the CASB-X bundle combines AI Access Security, Enterprise DLP, and SaaS Security. Email DLP and Endpoint DLP are licensed separately.

Does Palo Alto DLP require SSL decryption?

Yes, for inline inspection. Palo Alto's enablement guide requires SSL Forward Proxy decryption on the firewall or in Prisma Access, a rule to drop QUIC, and a decryption rule placed above the default Microsoft 365 exclusions. Apps with pinned certificates must be excluded from decryption, so inline DLP does not see them.

What happens when Palo Alto DLP cannot finish a scan?

By default, the traffic is allowed. Palo Alto's data filtering settings list max latency reached, file size over the limit, scanning errors, oversized non-file data, any error, and endpoint offline as fail-safe conditions, each defaulting to Allow, and these global settings override the action in the DLP rule. Admins can change them.

Does Palo Alto have endpoint DLP?

Yes, two versions. Endpoint DLP through the Prisma Agent covers USB, printers, network shares, and data at rest, and requires an Endpoint DLP license and Prisma Access 5.1 or later. Palo Alto also announced an Endpoint DLP add-on for Cortex XDR 5.0 in February 2026 that classifies on the device.

Can Palo Alto DLP block personal ChatGPT accounts?

Palo Alto documents Microsoft 365 tenant restrictions in Prisma Access and tenant-based policy in Prisma Browser, but we did not find a documented Prisma Access control for separating a corporate ChatGPT workspace from a personal account. dope.security Cloud Application Control restricts ChatGPT, Claude, Google, and Microsoft 365 to approved tenants on the device.

Can I run dope.security alongside Palo Alto firewalls?

Yes. Many teams keep Palo Alto NGFWs for data center and branch traffic and add dope.security on laptops for AI governance: Cloud Application Control for corporate AI tenants, Dopamine DLP for prompts and uploads, and CASB Neural for overshared files in OneDrive and Google Drive, all in one console.

Data Loss Prevention
Data Loss Prevention
Comparisons & Alternatives
Comparisons & Alternatives
AI Security
AI Security
Endpoint Security
Endpoint Security
← back to blog Home