> For the complete documentation index, see [llms.txt](https://docs.guardware.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.guardware.com/discover/scan/scans.md).

# Scans

{% embed url="<https://www.youtube.com/watch?t=32s&v=Bc_AQw5nzc0>" %}

The Scans section is where you configure and run scans against discovered devices and services. DISCOVER offers two scan types:

* [**One Time Scan**](#one-time-scan) runs a single, non-recurring scan on selected devices, services, and data types.
* [**Ongoing Scan**](#ongoing-scan) runs repeatedly on a defined schedule, continuously monitoring selected devices and services.

The installed scanning agent's location determines how One Time and Ongoing scans run.

<table><thead><tr><th width="143">Specifics</th><th width="212">Local Scanning</th><th>Agentless Scanning</th></tr></thead><tbody><tr><td><strong>How it works</strong></td><td>The agent is installed on the target device itself</td><td>Agent is installed on a separate host or a virtual machine.</td></tr><tr><td><strong>What it scans</strong></td><td>The device's own local files</td><td>Other devices, file shares, or cloud services across the network</td></tr><tr><td><strong>Best for</strong></td><td>Single device coverage</td><td>Scanning multiple targets from one central host (Scanning Server).</td></tr></tbody></table>

### One Time Scan

Create and run a One Time Scan to investigate a specific device or service, test new data type configurations, perform an ad-hoc compliance check, or scan a newly discovered device before adding it to ongoing monitoring.

{% stepper %}
{% step %}

#### Start the scan

1. Navigate to **DISCOVER** > **Scans** and click **+New Scan**.

   <div align="left"><figure><img src="/files/tbyiY85GMLWT0Yi1QpQl" alt="" width="524"><figcaption></figcaption></figure></div>
2. Select **One Time Scan** and click **Proceed**.<br>

   <div align="left"><figure><img src="/files/HrIzoM3amBvg1vjifTYD" alt="" width="563"><figcaption></figcaption></figure></div>
3. Enter a **Scan Name** that clearly identifies the purpose of the scan (e.g., *Finance SharePoint - Credit Card Check*).
4. Add an optional **Description** for context and click **Next**.<br>

   <div align="left"><figure><img src="/files/684qR1o98Lv1Koxy1KNh" alt="" width="458"><figcaption></figcaption></figure></div>

{% endstep %}

{% step %}

#### Select data types

1. From the list, check the boxes next to the data types you want to scan for.<br>

   <div align="left"><figure><img src="/files/ymEwN8neQOGKE2MbcwNp" alt="" width="543"><figcaption></figcaption></figure></div>
2. Use the search box and **Filter** to quickly locate specific data types.
3. Click **Next** after selecting the desired data types.
   {% endstep %}

{% step %}

#### Select devices and services

1. Select the devices and services to scan. You can include multiple device or service types in the same scan job (for example, devices and Exchange mailboxes together), each spread across its own tab.

   <table><thead><tr><th width="188">Target type</th><th>Displays</th></tr></thead><tbody><tr><td><strong>Exchange</strong></td><td>Displays all discovered Exchange Online mailboxes.</td></tr><tr><td><strong>Devices</strong></td><td>Displays all discovered devices (workstations, laptops, file servers, network storage).</td></tr><tr><td><strong>SharePoint</strong></td><td>Displays all discovered SharePoint Online sites and document libraries.</td></tr><tr><td><strong>Gmail</strong></td><td>Displays all discovered Gmail mailboxes.</td></tr><tr><td><strong>Google Drive</strong></td><td>Displays all discovered Google Drive hosts and document libraries.</td></tr></tbody></table>
2. After selecting the desired targets, click **Next**.<br>

   <figure><img src="/files/z5ilYm5rAw2abQOmw5Pu" alt="" width="563"><figcaption></figcaption></figure>

{% endstep %}

{% step %}

#### Configure file handling options

Configure how DISCOVER processes archives, images, documents, and classification labels during a scan.

* **Archive File Handling:** Enable to process compressed files (ZIP, RAR, 7z, etc.). When enabled, DISCOVER extracts and scans the contents of archive files. When disabled, archive files are skipped.

  <div align="left"><figure><img src="/files/R4LdGCxwstyTRvc8XZbw" alt="" width="317"><figcaption></figcaption></figure></div>
* **File date filter:** Limit scanning to files matching a specific date attribute and condition. For example, before decommissioning an old file server, set Attribute to **Last accessed date**, Condition to **Older than**, and the date to two years back, to catch every file nobody has touched since and confirm nothing important gets lost before deletion.

  <figure><img src="/files/0Vjtv3191JB1tcSpYtHp" alt="" width="563"><figcaption></figcaption></figure>

  \
  Selecting **Between** opens a second date field for a start and end date. All other conditions use a single date field.

  <table><thead><tr><th width="147">Field</th><th>Options</th></tr></thead><tbody><tr><td>Date Attributes</td><td>Modification date, Creation date, Last accessed date</td></tr><tr><td>Conditions</td><td>Older than, Newer than, Equal to, Between</td></tr></tbody></table>
* **Fetch MIP Sensitivity labels:**  &#x20;Enable to extract the MIP Sensitivity labels from files during scanning.<br>

  <div align="left"><figure><img src="/files/1YmR12Nc4wOl9F909Ifs" alt="" width="377"><figcaption></figcaption></figure></div>
* **OCR for Images:** Enable to extract and scan text from image files (JPG, PNG, GIF). Enable if sensitive data may exist in screenshots or photographed documents.

  <div align="left"><figure><img src="/files/L8rH3Kls4j4V5v1ySBM0" alt="" width="333"><figcaption></figcaption></figure></div>
* **OCR for Documents:** Enable to extract text from PDFs, TIFF files, and other supported document formats.

  <div align="left"><figure><img src="/files/rxTX0AiqqexAG9yCoIj5" alt="" width="356"><figcaption></figcaption></figure></div>
* **Scan and Classify:** Enable to automatically apply a classification label to each file based on the most sensitive data detected during a scan.<br>

  <figure><img src="/files/lMsZ4SUOXIXPFUtIInDH" alt="" width="563"><figcaption></figcaption></figure>

  * **Overwrite Existing Classifications:**&#x20;
    * Select **Overwrite** to replace the existing file classification label(s).&#x20;
    * Select **Do Not Overwrite** to keep the existing label(s) unchanged.
  * **Classify Method:**&#x20;
    * Select **Classify Using Data Type** to apply the label mapped to the matched data type.&#x20;
    * Select **Classify Using** to choose whether custom labels or Microsoft Purview-synced labels are applied to all scanned files, regardless of their sensitivity.
  * **Enable New Files Since Last Scan:** Enable this to scan only files that have been created or modified since the last time this target was scanned. This significantly speeds up subsequent scans by skipping unchanged files.
* **Select Exchange Date:** For Exchange scans, specify a start date to scan only emails received from that date forward. Set this to a reasonable timeframe (e.g., the past 90 days) unless historical email coverage is required.
  {% endstep %}

{% step %}

#### Filter directories and file types

This setting allows you to include or exclude specific folders and file types from the scan. If you skip this configuration, DISCOVER **will scan all folders and file types** in every selected target for sensitive data. You have multiple options for controlling which folders and file types are scanned:

#### Scan only the selected folders and file types

Limit the scan to specific locations and file formats. Only what you explicitly select is scanned. Use this when you already know where sensitive data is likely to exist and want to focus the scan there instead of scanning everything.

<div align="left"><figure><img src="/files/d18d2091293a756806c74acaf9a32c720a0bdf41" alt="" width="563"><figcaption></figcaption></figure></div>

* **Include System Folders (Toggle):** Enable to include Windows system folders (`C:\Windows`, `C:\Program Files`). This is generally not recommended unless you need to scan system folders.
* **Custom Folder Paths:** Click **+Add** to include folders to scan. Enter the full path (e.g., `C:\Users\Public\Documents`, `\\fileserver\HR\Payroll`). Add multiple paths as needed. Only these folders are scanned.
* **Include All File Types (Toggle):** Enable to scan all supported formats (documents, spreadsheets, presentations, images, archives, emails). Disable it to limit scanning to specific extensions only.
* **Include Custom File Types:** Click **+Add** to specify extensions to scan uncommon or proprietary file extensions not in DISCOVER's file type list. Only files having these extensions will be scanned.

#### Scan all content except the selected folders and file types

Scan everything except selected folders or file types. Use this when you want broad coverage while skipping known irrelevant areas, such as system folders, logs, or temporary folders.

<div align="left"><figure><img src="/files/c491e6ab76202487ed410367373945097736aa4e" alt="" width="563"><figcaption></figcaption></figure></div>

* **Exclude System Folders (Toggle):** Enable to skip all Windows system folders. This is recommended for most scans, as system folders rarely contain user-generated sensitive data.
* **Exclude Custom Folder Path:** Click **+Add** to specify folders to exclude. Enter the full path (e.g., `C:\Windows\Temp`, `\\fileserver\Backups`, `D:\Logs`). These folders are skipped during the scan.
* **Exclude All File Types (Toggle):** Enable to skip file content scanning entirely and examine only file metadata, such as filenames and paths. This is rarely used and typically needed only for filename-based data types.
* **Exclude Custom File Types:** Click **+Add** to specify extensions to exclude uncommon or proprietary extensions you don't want scanned (e.g., `.backup`, `.cache`).\
  Click **Next** to proceed.
  {% endstep %}

{% step %}

### Review and save the scan

Review the scan configuration summary and click **Save Scan**. The scan initiates automatically and appears in the Scans list with a status indicator.

Once the scan completes, click **View Result** to see the findings.
{% endstep %}
{% endstepper %}

### Ongoing Scan

Use ongoing scans for continuous monitoring required by regulations or policies. Ongoing scans establish a baseline and track sensitive-data exposure. They also monitor devices and services for regular security reporting.

{% stepper %}
{% step %}

### Start the scan

1. Navigate to **DISCOVER** > **Scans** and click **+New Scan**.
2. Select **Ongoing Scan** and click **Proceed**.<br>

   <div align="left"><img src="/files/92600f6dd2743e91d8339abca1694c3848f6c882" alt="" width="563"></div>
3. Select data types and click **Next**.<br>

   <figure><img src="/files/4fa7e469ac7a971a72ad47906ad89020d740bebf" alt=""><figcaption></figcaption></figure>

{% endstep %}

{% step %}

### Select devices and services

1. Select all devices and services you want to monitor continuously and click **Next**.
   {% endstep %}

{% step %} <img src="/files/6c8b3008d6a5aadf2e4911a5ceb77cb2ad2a4b61" alt="" data-size="original">
{% endstep %}

{% step %}

### Configure file handling options

5. Configure file handling options following the same process as a One Time Scan, including one additional option:
   1. **OCR for Documents:** When enabled, you can also configure classification behavior.
   2. **Auto Scan Newly Discovered Device:** Enable to automatically include devices and services discovered after the scan is created. On each scheduled run, any newly discovered targets are added to the scan automatically.
   3. **Enable New Files Since Last Scan:** Enable this to scan only files that have been created or modified since the last time this target was scanned. This significantly speeds up subsequent scans by skipping unchanged files.
   4. **Scan and Classify:** Enable to automatically apply a classification label to each file based on the most sensitive data detected.
      1. **Overwrite Existing Classifications:** Select **Overwrite** to replace an existing label. Select **Do Not Overwrite** to keep the existing label unchanged.
      2. **Classify Method:** Select **Classify Using Data Type** to apply the label mapped to the matched data type. Or select a custom label or a Microsoft Purview-synced label to apply that label instead.
         {% endstep %}

{% step %} <img src="/files/9a5d5cf864961733da63a674ceb3077ad21d7292" alt="" data-size="original">
{% endstep %}

{% step %}

### Filter directories and file types

6. **Filter directories and file types** allows you to include or exclude specific folders and file types from the scan. If you skip this configuration, DISCOVER **will scan all folders and file types** for sensitive data. You have multiple options for controlling which folders and file types are scanned:
   1. **Scan Only the Selected Folders and File Types**\
      Limit the scan to specific locations and file formats. Only what you explicitly select will be scanned. Use this when you know exactly where sensitive data exists and want to focus only on those locations.

      <figure><img src="/files/d18d2091293a756806c74acaf9a32c720a0bdf41" alt="" width="563"><figcaption></figcaption></figure>

      1. **Include System Folders (Toggle):** Enable to include Windows system folders (`C:\Windows`, `C:\Program Files`). This is generally not recommended unless you need to scan system folders.
         1. **Selected Folder Paths:** Click **+Add** to add folders to scan. Enter the full path (e.g., `C:\Users\Public\Documents`, `\\fileserver\HR\Payroll`). Add multiple paths as needed. Only these folders are scanned.
            1. **Include All File Types (Toggle):** Enable to scan all supported formats (documents, spreadsheets, presentations, images, archives, emails). Disable it to limit scanning to specific extensions only.
               1. **Include Custom File Types:** Click **+Add** to specify file type extensions to scan uncommon, proprietary, or file extensions not in DISCOVER's standard list. Only files matching these extensions will be scanned.
               2. **Scan All Content Except the Selected Folders and File Types**\
                  Scan comprehensively while excluding specific folders or file types. Everything is scanned except what you explicitly exclude. Use this when you want broad coverage while skipping known irrelevant areas, such as system folders, logs, or temporary folders.

                  <figure><img src="/files/c491e6ab76202487ed410367373945097736aa4e" alt="" width="563"><figcaption></figcaption></figure>

                  1. **Exclude System Folders (Toggle):** Enable to skip all Windows system folders. This is recommended for most scans, as system folders rarely contain user-generated sensitive data.
                  2. **Exclude Custom Folder Path:** Click **+Add** to specify folders to exclude. Enter the full path (e.g., `C:\Windows\Temp`, `\\fileserver\Backups`, `D:\Logs`). These folders are skipped during the scan.
                  3. **Exclude All File Types (Toggle):** Enable to skip file content scanning entirely and examine only file metadata, such as filenames and paths. This is rarely used and typically needed only for filename-based data types.
                  4. **Exclude Custom File Types:** Click **+Add** to specify extensions to exclude uncommon or proprietary extensions you don't want scanned (e.g., `.backup`, `.cache`).\
                     Click **Next** to proceed.
                     {% endstep %}

{% step %}

### Set the schedule

<figure><img src="/files/5780a8d81e91b30780b0083250bfd883fd4d80ac" alt=""><figcaption></figcaption></figure>

7. Set a Schedule to define when and how often the scan runs.
   1. In the **Repeat Schedule Every** field, enter how frequently the scan should run.
      1. **Select an interval:** Select the rate at which the scans repeat.
      2. **Select a time:** Select the time at which the scans start.\
         Example: Selecting **2** Months at **10:00** repeats the ongoing scan every 2 months at 10:00 AM.
   2. Choose the **Scan Start From** date
      1. **Specific Date:** Select a calendar date when the first scan should run. The scan will start on this date and then repeat according to the interval you set.
      2. **Day of the Week:** Select a specific day (Monday, Tuesday, etc.) when scans should run. This is useful for scheduling scans during low-activity periods (e.g., every Sunday).
   3. Ongoing scans can be resource-intensive (high CPU usage, network traffic, disk I/O); it's best to schedule them during off-hours when they won't impact user productivity. Use the **Avoid Scans** on option to specify when scans should NOT run, even if they're scheduled.
      1. Click **+Avoid Time** to add a restriction. Select the day(s) of the week when scans should be avoided. Select the time range to avoid (e.g., 8:00 AM to 6:00 PM for business hours). You can add multiple avoid time windows to accommodate different schedules.
8. At the bottom of the Scheduling step, you'll find the **Terminate Current Scan** toggle.
   1. Enable this option to stop any scan that is currently running when the newly configured ongoing scan starts.
   2. Leave this option disabled if you want the current scan to finish first.
   3. If the current scan runs past the scheduled start time of the new scan, the new scan will not run for that occurrence. It will wait until the next scheduled slot, whether that is the following week or month.
   4. This can create a gap in scheduled coverage, so keep this in mind when setting scan times.
9. Click **Next** to continue.
   {% endstep %}

{% step %}

### Review and save the scan

10. Once the schedule is configured, review the configuration summary and click **Save Scan**. The scan initiates automatically and appears in the **Scans** list.
    {% endstep %}
    {% endstepper %}

<details>

<summary><strong>View Scan Results</strong></summary>

After the scan completes, click **View Result** to see the findings.

1. Navigate to **DISCOVER** > **Scans**.

<div align="left"><figure><img src="/files/d1v13pM4Smv8mHUFyNqa" alt="" width="563"><figcaption></figcaption></figure></div>

2. Locate the completed scan and click **View Result**.
3. This opens the Results page filtered to show only findings from this specific scan (see the Results section below for detailed information on reviewing scan findings).

</details>

<details>

<summary><strong>View Scan Details</strong></summary>

1. Navigate to **DISCOVER** > **Scans**.
2. Locate the scan and click **View** <i class="fa-eye">:eye:</i> .<br>

   <div align="left"><figure><img src="/files/3nvFBfcmDbbGSfo9WG2U" alt="" width="563"><figcaption></figcaption></figure></div>
3. This displays the complete scan configuration.

</details>

<details>

<summary><strong>Delete a Scan</strong></summary>

1. Navigate to **DISCOVER** > **Scans**.
2. Locate the scan you want to remove and click **Delete** <i class="fa-trash-can">:trash-can:</i>.

   <div align="left"><figure><img src="/files/hi2CDzfrKwbHt7yjwd6S" alt="" width="563"><figcaption></figcaption></figure></div>
3. A confirmation prompt will appear. Click **Delete** to confirm.

   <div align="left"><figure><img src="/files/46c5f10cf56ce7d21f31cf8b4c812895ee2e1163" alt="" width="375"><figcaption></figcaption></figure></div>

</details>

<details>

<summary><strong>Pause a Scan</strong></summary>

1. Navigate to **DISCOVER** > **Scans**.
2. Locate the running scan and click **Pause** <i class="fa-pause">:pause:</i>.<br>

<div align="left"><figure><img src="/files/tWIes7kGuXzfOhebA3Wn" alt="" width="563"><figcaption></figcaption></figure></div>

3. The scan immediately pauses and stops processing targets. Targets that have already been scanned retain their results. Targets not yet scanned remain in the queue.

</details>

<details>

<summary><strong>Resume a Scan</strong></summary>

1. Navigate to **DISCOVER** > **Scans**.
2. Locate the paused scan and click **Resume** <i class="fa-play">:play:</i>.<br>

   <div align="left"><figure><img src="/files/XNUooMqmS3SRsMsNA11k" alt="" width="563"><figcaption></figcaption></figure></div>
3. The scan resumes from where it was paused, continuing to process remaining targets in the queue.

</details>

<details>

<summary><strong>Terminate a Scan</strong></summary>

1. Navigate to **DISCOVER** > **Scans**.
2. Locate the running scan and click **Terminate** <i class="fa-circle-xmark">:circle-xmark:</i>.<br>

   <div align="left"><figure><img src="/files/5tsbgOjZ4hR0IYSM7EYA" alt="" width="563"><figcaption></figcaption></figure></div>
3. A confirmation prompt will appear. Click **Terminate** to end the scan immediately.

   <div align="left"><figure><img src="/files/08db5b8f8f6e002be1871921524bb4de2cdfab83" alt="" width="375"><figcaption></figcaption></figure></div>

</details>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.guardware.com/discover/scan/scans.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
