Configure YouTube Granular Control for CASB
![]()
For supported software information, click here.
Cloud Access Security Broker (CASB) is on-premises or cloud-based policy enforcement that sits between cloud service users and cloud applications, and monitors all activity and enforces security policies. The Versa Operating SystemTM (VOSTM) CASB functions as inline software to monitor application activity inside a user session, which allows policy enforcement at a granular level.
You can define granular application instances for the YouTube application in which each instance can have one or more channel-name definitions (plain text or regex). These definitions can then be used as match criteria to enforce CASB policies for specific YouTube channels.
To configure YouTube granular control, you do the following:
- Configure application instances for YouTube.
- Reference the application instance in a CASB constraint profile.
- Apply the constraint in a CASB policy rule.
Configure Application Instances for YouTube
- In Director view:
- Select the Administration tab in the top menu bar.
- Select Appliances in the left navigation bar.
- Select an Organization from the drop-down list.
- Select an appliance in the main pane. The view changes to Appliance view.
- Select the Configuration tab in the top menu bar.
- Select Objects & Connectors > Objects > Application Instance in the left menu bar.

- Click the
Add icon. In the Add Application Instance window, enter information for the following fields.

Field Description Application Name (Required) Select youtube. Instance Name (Group of Fields) - Name
Enter a name for the instance name (for example, Games). - Definition
Enter one or more YouTube channel names or regex patterns (for example, "CBS" and "ESPN") that identify the channels this instance should match. Click the
icon to add each definition. - Click OK to create the application instance.
Reference the Application Instance in a CASB Constraint Profile
You can reference the application instance in a CASB constraint profile. CASB constraint profiles allow you to control which users and groups can access the activities configured in CASB.
- In Director view:
- Select the Configuration tab in the top menu bar.
- Select Templates in the horizontal menu bar.
- Select an organization in the left navigation bar.
- Select a template from the dashboard. The view changes to Appliance view.
- Select the Configuration tab in the top menu bar.
- Select Services > Next Gen Firewall > Security > Profiles > CASB Constraint in the left menu bar.

- Click the
Add icon. The Create Constraint window displays. - On the General tab, enter information for the following fields.

Field Description Name (Required) Enter a name for the constraint profile. Application Instance (Group of fields) - Application Name
Select the YouTube application. - Instance
Select the application instance created in the Configure Application Instances for YouTube section, and then click the
Add icon to add the instance to the constraint profile. - Click OK. The saved constraint profile links the YouTube instance and its channel definitions to CASB policy enforcement.
Apply the Constraint in a CASB Rule with YouTube watch_stream Activity
- In Director view:
- Select the Configuration tab in the top menu bar.
- Select Templates in the horizontal menu bar.
- Select an organization in the left navigation bar.
- Select a template from the dashboard. The view changes to Template view.
- Select the Configuration tab in the top menu bar.
- Select Services > Next Gen Firewall > Security > Profiles > CASB.

- If you had previously configured a CASB profile, click the name of the profile to apply the constraint in a CASB rule. Go to Step 6.
- Click the
Add icon. The Add CASB Profile window displays. Enter information for the following fields.

Field Description Name (Required) Enter a name for the CASB profile. Description Enter a text description for the CASB profile. Profile Default Action (Required) Select the default action for the profile. The action can be predefined or user-defined:
- Allow
- Block
- Drop session
- Reject
LEF Profile Select the log export functionality (LEF) profile to use for the CASB profile. The LEF profile is used to generate logs for an external device. For more information, see Configure Log Export Functionality. Default Profile Click to have the selected LEF profile be the default LEF profile. - Click the
Add icon to add a new rule. - In the Add CASB Rule window, enter information for the following fields.

Field Description Name (Required) Enter a name for the rule. Rule Action (Required) Select a rule action. The options are:
- Allow
- Block
- Drop-session
- Reject
Activation Ensure that Application check box is checked. - Select the Predefined Applications tab, then click the
Add icon. In the Add Predefined Applications popup window, enter the following information.

Field Description Name (Required) Select youtube. Activities Click the down arrow and select the watch_stream activity, then click the
Add button to add the activity to the rule. - Click OK to save the new rule.
Supported Software Information
Releases 23.1.2 and later support all content described in this article.
