For the complete documentation index, see llms.txt. This page is also available as Markdown.

Scans

Configure and run a scan on any discovered device or service. DISCOVER offers two scans types:

  • One Time, which runs a single, non-recurring scan on selected devices, services, and data types.

  • Ongoing, which runs a repeating, recurring scan on selected devices, services, and data types.

The location of the Scanning Agent determines whether the scan runs using the Local Scanning or Remote Scanning architecture.

Specifics
Local Scanning
Remote Scanning

How it works

Agent is installed on the target device itself

Scanning Agent is installed on a separate host or a virtual machine (Scanning Server).

What it scans

The device's own local files

Other devices, file shares, or cloud services across the network

Best for

Single device coverage

Scanning multiple targets from one central host (Scanning Server).

One Time Scan

Create and run a One Time Scan to investigate a specific device or service, test new data type configurations, perform an ad-hoc compliance check, or scan a newly discovered device before adding it to ongoing monitoring.

1

Select the scan

  1. Navigate to DISCOVER > Scans and click +New Scan.

  2. Select One Time Scan and click Proceed.

  3. Enter a Scan Name that clearly identifies the purpose of the scan (e.g., Finance SharePoint - Credit Card Check).

  4. Add an optional Description for context and click Next.

2

Select data types

  1. From the list, check the boxes next to the data types you want to scan for.

  2. Use the search box and Filter to quickly locate specific data types.

  3. Click Next after selecting the desired data types.

3

Select devices and services

  1. Select the devices and services to scan. You can include multiple device or service types in the same scan job (for example, devices and Exchange mailboxes together), each spread across its own tab.

    Target type
    Displays

    Exchange

    Displays all discovered Exchange Online mailboxes.

    Devices

    Displays all discovered devices (workstations, laptops, file servers).

    SharePoint

    Displays all discovered SharePoint Online sites and document libraries.

    Gmail

    Displays all discovered Gmail mailboxes.

    Google Drive

    Displays all discovered Google Drive hosts and document libraries.

  2. After selecting the desired targets, click Next.

4

Configure file handling options

Configure how DISCOVER processes archives, images, documents, and classification labels during a scan.

  • Archive File Handling: Enable to process compressed files (ZIP, RAR, 7z, etc.). When enabled, DISCOVER extracts and scans the contents of archive files. When disabled, archive files are skipped.

  • File date filter: Limit scanning to files matching a specific date attribute and condition. For example, before decommissioning an old file server, set Attribute to Last accessed date, Condition to Older than, and the date to two years back, to catch every file nobody has touched since and confirm nothing important gets lost before deletion.

    Selecting Between opens a second date field for a start and end date. All other conditions use a single date field.

    Field
    Options

    Date Attributes

    Modification date, Creation date, Last accessed date

    Conditions

    Older than, Newer than, Equal to, Between

  • Fetch MIP Sensitivity labels: Enable to extract the MIP Sensitivity labels from files during scanning.

  • OCR for Images: Enable to extract and scan text from image files (JPG, PNG, GIF). Enable if sensitive data may exist in screenshots or photographed documents.

  • OCR for Documents: Enable to extract text from PDFs, TIFF files, and other supported document formats.

  • Scan and Classify: Enable to automatically apply a classification label to each file based on the most sensitive data detected during a scan.

    • Overwrite Existing Classifications:

      • Select Overwrite to replace the existing file classification label(s).

      • Select Do Not Overwrite to keep the existing label(s) unchanged.

    • Classify Method:

      • Select Classify Using Data Type to apply the label mapped to the matched data type.

      • Select Classify Using to choose whether custom labels or Microsoft Purview-synced labels are applied to all scanned files, regardless of their sensitivity.

  • Select Start Date: For email scans, specify a start date to scan only messages received after that date. Set this to a reasonable timeframe (e.g., the past 90 days) unless historical email coverage is required.

5

Filter directories and file types

This setting allows you to include or exclude specific folders and file types from the scan. You have multiple options for controlling which folders and file types are scanned:

Scan only the selected folders and file types

Limit the scan to specific locations and file formats. Only what you explicitly select is scanned. Use this when you already know where sensitive data is likely to exist and want to focus the scan there instead of scanning everything.

  • Include System Folders (Toggle): Enable to include Windows system folders (C:\Windows, C:\Program Files). This is generally not recommended unless you need to scan system folders.

  • Custom Folder Path: Click +Add to include folders to scan. Enter the full path (e.g., C:\Users\Public\Documents, \\fileserver\HR\Payroll). Add multiple paths as needed. Only these folders are scanned.

  • Include All File Types (Toggle): Enable to scan all supported formats (documents, spreadsheets, presentations, images, archives, emails). Disable it to limit scanning to specific extensions only.

  • Include Custom File Types: Click +Add to specify extensions to scan uncommon or proprietary file extensions not in DISCOVER's file type list. Only files having these extensions will be scanned.

Scan all content except the selected folders and file types

Scan everything except selected folders or file types. Use this when you want broad coverage while skipping known irrelevant areas, such as system folders, logs, or temporary folders.

  • Exclude System Folders (Toggle): Enable to skip all Windows system folders. This is recommended for most scans, as system folders rarely contain user-generated sensitive data.

  • Exclude Custom Folder Path: Click +Add to specify folders to exclude. Enter the full path (e.g., C:\Windows\Temp, \\fileserver\Backups, D:\Logs). These folders are skipped during the scan.

  • Exclude All File Types (Toggle): Enable to skip file content scanning entirely and examine only file metadata, such as filenames and paths. This is rarely used and typically needed only for filename-based data types.

  • Exclude Custom File Types: Click +Add to specify extensions to exclude uncommon or proprietary extensions you don't want scanned (e.g., .backup, .cache).

  1. Click Next to proceed.

6

Review and execute scan

  1. Review the scan configuration summary.

  2. Click Save. The scan starts automatically and appears in the Scans list with a status indicator.

  3. Once the scan is running or complete, use the additional scan controls to pause, resume, delete, or terminate the scan, or to view its results and details.

Ongoing Scan

Use Ongoing Scan when you need continuous, scheduled monitoring rather than a one-off check. It keeps scanning the same targets over time, helps establish a baseline for sensitive-data exposure, tracks changes, and catches newly introduced sensitive files for routine compliance.

1

Select the scan

  1. Navigate to DISCOVER > Scans and click +New Scan.

  2. Select Ongoing Scan and click Proceed.

  3. Select data types and click Next.

2

Select devices and services

  1. Select the devices and services to scan. You can include multiple device or service types in the same scan job (for example, devices and Exchange mailboxes together), each spread across its own tab.

    Target type
    Displays

    Exchange

    Displays all discovered Exchange Online mailboxes.

    Devices

    Displays all discovered devices (workstations, laptops, file servers).

    SharePoint

    Displays all discovered SharePoint Online sites and document libraries.

    Gmail

    Displays all discovered Gmail mailboxes.

    Google Drive

    Displays all discovered Google Drive hosts and document libraries.

  2. By default, all targets are selected. Deselect any unnecessary targets and click Next.

3

Configure file handling options

Configure how DISCOVER processes archives, images, documents, and classification labels during a scan.

  • Archive File Handling: Enable to process compressed files (ZIP, RAR, 7z, etc.). When enabled, DISCOVER extracts and scans the contents of archive files. When disabled, archive files are skipped.

  • File date filter: Limit scanning to files matching a specific date attribute and condition. For example, before decommissioning an old file server, set Attribute to Last accessed date, Condition to Older than, and the date to two years back, to catch every file nobody has touched since and confirm nothing important gets lost before deletion.

    Selecting Between opens a second date field for a start and end date. All other conditions use a single date field.

    Field
    Options

    Date Attributes

    Modification date, Creation date, Last accessed date

    Conditions

    Older than, Newer than, Equal to, Between

  • Fetch MIP Sensitivity labels: Enable to extract the MIP Sensitivity labels from files during scanning.

  • OCR for Images: Enable to extract and scan text from image files (JPG, PNG, GIF). Enable if sensitive data may exist in screenshots or photographed documents.

  • OCR for Documents: Enable to extract text from PDFs, TIFF files, and other supported document formats.

  • Auto Scan Newly Discovered Device: Enable to automatically include devices and services discovered after the scan is created. On each scheduled run, any newly discovered targets are added to the scan automatically.

  • Enable New Files Since Last Scan: Enable this to scan only files that have been created or modified since the last time this target was scanned. This significantly speeds up subsequent scans by skipping unchanged files.

  • Scan and Classify: Enable to automatically apply a classification label to each file based on the most sensitive data detected during a scan.

    • Overwrite Existing Classifications:

      • Select Overwrite to replace the existing file classification label(s).

      • Select Do Not Overwrite to keep the existing label(s) unchanged.

    • Classify Method:

      • Select Classify Using Data Type to apply the label mapped to the matched data type.

      • Select Classify Using to choose whether custom labels or Microsoft Purview-synced labels are applied to all scanned files, regardless of their sensitivity.

  • Select Start Date: For email scans, specify a start date to scan only messages received after that date. Set this to a reasonable timeframe (e.g., the past 90 days) unless historical email coverage is required.

4

Filter directories and file types

This setting allows you to include or exclude specific folders and file types from the scan. You have multiple options for controlling which folders and file types are scanned:

Scan only the selected folders and file types

Limit the scan to specific locations and file formats. Only what you explicitly select is scanned. Use this when you already know where sensitive data is likely to exist and want to focus the scan there instead of scanning everything.

  • Include System Folders (Toggle): Enable to include Windows system folders (C:\Windows, C:\Program Files). This is generally not recommended unless you need to scan system folders.

  • Custom Folder Path: Click +Add to include folders to scan. Enter the full path (e.g., C:\Users\Public\Documents, \\fileserver\HR\Payroll). Add multiple paths as needed. Only these folders are scanned.

  • Include All File Types (Toggle): Enable to scan all supported formats (documents, spreadsheets, presentations, images, archives, emails). Disable it to limit scanning to specific extensions only.

  • Include Custom File Types: Click +Add to specify extensions to scan uncommon or proprietary file extensions not in DISCOVER's file type list. Only files having these extensions will be scanned.

Scan all content except the selected folders and file types

Scan everything except selected folders or file types. Use this when you want broad coverage while skipping known irrelevant areas, such as system folders, logs, or temporary folders.

  • Exclude System Folders (Toggle): Enable to skip all Windows system folders. This is recommended for most scans, as system folders rarely contain user-generated sensitive data.

  • Exclude Custom Folder Path: Click +Add to specify folders to exclude. Enter the full path (e.g., C:\Windows\Temp, \\fileserver\Backups, D:\Logs). These folders are skipped during the scan.

  • Exclude All File Types (Toggle): Enable to skip file content scanning entirely and examine only file metadata, such as filenames and paths. This is rarely used and typically needed only for filename-based data types.

  • Exclude Custom File Types: Click +Add to specify extensions to exclude uncommon or proprietary extensions you don't want scanned (e.g., .backup, .cache).

  1. Click Next to proceed.

5

Set the schedule

Set a schedule to define when and how often the scan runs.

  1. In the Scan Frequency field, enter how frequently the scan should run.

    1. Select an interval: Select the rate at which the scans repeat.

    2. Select a time: Select the time at which the scans start. Example: Selecting 2 Months at 6:00 PM repeats the ongoing scan every 2 months at 6:00 PM.

  2. Choose the Scan Start date

    1. On Date: Select a calendar date when the first scan should run. The scan will start on this date and then repeat according to the interval you set.

    2. Relative Date: Select a specific period and day (Monday, Tuesday, etc.) when scans should run. This is useful for scheduling scans during low-activity periods (e.g., every Sunday).

  3. Ongoing scans can be resource-intensive (high CPU usage, network traffic, disk I/O); it's best to schedule them during off-hours when they won't impact user productivity. Use the Avoid Scans On setting to define periods during which scheduled scans must not run, even if they are due to start.

    1. Click +Add avoid window to add a restriction.

    2. Select the day(s) of the week when scans should be avoided. Select the time range to avoid (e.g., 8:00 AM to 6:00 PM for business hours). You can add multiple avoid time windows to accommodate different schedules.

  4. Beside the schedule, you'll find the Terminate Current Scan toggle.

    1. Enable this option to stop any scan that is currently running when the newly configured ongoing scan starts.

    2. Leave this option disabled if you want the current scan to finish first.

  1. Click Next to continue.

Once configured, the schedule runs automatically until the scan is disabled or deleted.

6

Review and execute scan

  1. Once the schedule is configured, review the scan configuration summary.

  2. Click Save. The scan starts automatically and appears in the Scans list with a status indicator.

  3. Once the scan is running or complete, use the additional scan controls to pause, resume, delete, or terminate the scan, or to view its results and details.

Additional Scan Controls

Manage a running or completed scan directly from the Scans list, including viewing its results and details, pausing, or resuming the scan.

View Scan Results

After the scan completes, click View Result to see the findings.

  1. Navigate to DISCOVER > Scans.

  1. Locate the completed scan and click View Result.

  2. This opens the Results page filtered to show only findings from this specific scan (see the Results section below for detailed information on reviewing scan findings).

View Scan Details
  1. Navigate to DISCOVER > Scans.

  2. Locate the scan and click View .

  3. This displays the complete scan configuration.

Pause a Scan
  1. Navigate to DISCOVER > Scans.

  2. Locate the running scan and click Pause .

  1. The scan immediately pauses and stops processing targets. Targets that have already been scanned retain their results. Targets not yet scanned remain in the queue.

Resume a Scan
  1. Navigate to DISCOVER > Scans.

  2. Locate the paused scan and click Resume .

  3. The scan resumes from where it was paused, continuing to process remaining targets in the queue.

Delete a Scan
  1. Navigate to DISCOVER > Scans.

  2. Locate the scan you want to remove and click Delete .

  3. A confirmation prompt will appear. Click Delete to confirm.

Terminate a Scan
  1. Navigate to DISCOVER > Scans.

  2. Locate the running scan and click Terminate .

  3. A confirmation prompt will appear. Click Terminate to end the scan immediately.

Last updated