Manage discovery scan configurations

This page describes how to create, view, pause, resume, edit, and delete anexistingdiscovery scanconfiguration.

Adiscovery scan configuration (sometimes calleddiscovery configuration orscan configuration) specifies how Sensitive Data Protection should profileyour data. For more information, seeDiscovery scanconfiguration.

Create a scan configuration

For information about how to create an organization-level or project-leveldiscovery scan configuration, see the following pages:

Discovery typeCreate an organization-level scan configurationCreate a project-level scan configuration1
Discovery for BigQuery dataProfile BigQuery data in an organization or folderProfile BigQuery data in a single project
Discovery for Cloud SQL dataProfile Cloud SQL data in an organization or folderProfile Cloud SQL data in a single project
Discovery for Cloud Storage dataProfile Cloud Storage data in an organization or folderProfile Cloud Storage data in a single project
Discovery for Vertex AI dataProfile Vertex AI data in an organization or folderProfile Vertex AI data in a single project
Discovery for Amazon S3 dataDiscovery for Amazon S3 dataNot applicable
Discovery for Azure Blob Storage dataDiscovery for Azure Blob Storage dataNot applicable
Secrets discovery (no profiles generated)Configure secrets discovery at the organization levelConfigure secrets discovery at the project level

1 Not suitable for customers who have an organization-level discoverysubscription, such as one provided through Security Command Center

View a scan configuration

  1. Go to the discovery scan configurations list.

    Go to discovery scan configurations

  2. Make sure you're viewing the correct organization or project:

    • To manage a discovery scan configuration that you created at theorganization or folder level, view the organization.
    • To manage a discovery scan configuration that you created at the projectlevel, view the project.
    • To manage a discovery scan configuration for single data resource, view theproject that contains the resource.

    To switch to a different view, on the toolbar, click the project selector.Select the organization or project that you want to view.

  3. To open theScan configuration details page, click the name of theresource associated with the scan configuration.

Pause a scan configuration

  1. Go to the discovery scan configurations list.

    Go to discovery scan configurations

  2. Make sure you're viewing the correct organization or project:

    • To manage a discovery scan configuration that you created at theorganization or folder level, view the organization.
    • To manage a discovery scan configuration that you created at the projectlevel, view the project.
    • To manage a discovery scan configuration for single data resource, view theproject that contains the resource.

    To switch to a different view, on the toolbar, click the project selector.Select the organization or project that you want to view.

  3. ClickActions,and then clickPause scan.

    As long as a scan configuration is paused, Sensitive Data Protection doesn'tgenerate any new profiles under that configuration.

Resume a scan configuration

  1. Go to the discovery scan configurations list.

    Go to discovery scan configurations

  2. Make sure you're viewing the correct organization or project:

    • To manage a discovery scan configuration that you created at theorganization or folder level, view the organization.
    • To manage a discovery scan configuration that you created at the projectlevel, view the project.
    • To manage a discovery scan configuration for single data resource, view theproject that contains the resource.

    To switch to a different view, on the toolbar, click the project selector.Select the organization or project that you want to view.

  3. ClickActions,and then clickResume scan.

Edit a scan configuration

If you edit a scan configuration that has already been used to profiletables, you might end up having different tables scanned according todifferent configurations.

To edit a scan configuration, follow these steps:

  1. Go to the discovery scan configurations list.

    Go to discovery scan configurations

  2. Make sure you're viewing the correct organization or project:

    • To manage a discovery scan configuration that you created at theorganization or folder level, view the organization.
    • To manage a discovery scan configuration that you created at the projectlevel, view the project.
    • To manage a discovery scan configuration for single data resource, view theproject that contains the resource.

    To switch to a different view, on the toolbar, click the project selector.Select the organization or project that you want to view.

  3. ClickActions,and then clickEdit.

  4. Edit the configuration as needed. For more information, see the documentslisted inCreate a scan configuration on this page.

  5. ClickSave.

Delete a scan configuration

Deleting a scan configuration doesn't delete the data profiles that havebeen generated through it. In addition, deleting a scan configuration andcreating a new one doesn't cause a reprofile operation on tables that are in thescope of the new scan configuration.

Sensitive Data Protection reprofiles data as described inFrequency of data profilegeneration. You can customize the profiling frequency in your scan configuration bycreating a schedule.To force the discovery service to reprofile your data, seeForce a reprofileoperation.

For information on how long Sensitive Data Protectionretains data profiles, seeRetention of data profiles.

To delete a scan configuration, follow these steps:

  1. Go to the discovery scan configurations list.

    Go to discovery scan configurations

  2. Make sure you're viewing the correct organization or project:

    • To manage a discovery scan configuration that you created at theorganization or folder level, view the organization.
    • To manage a discovery scan configuration that you created at the projectlevel, view the project.
    • To manage a discovery scan configuration for single data resource, view theproject that contains the resource.

    To switch to a different view, on the toolbar, click the project selector.Select the organization or project that you want to view.

  3. ClickActions,and then clickDelete.

  4. To confirm the deletion, in the dialog that appears, clickDelete.

View configuration errors

  1. Go to the discovery scan configurations list.

    Go to discovery scan configurations

  2. Make sure you're viewing the correct organization or project:

    • To manage a discovery scan configuration that you created at theorganization or folder level, view the organization.
    • To manage a discovery scan configuration that you created at the projectlevel, view the project.
    • To manage a discovery scan configuration for single data resource, view theproject that contains the resource.

    To switch to a different view, on the toolbar, click the project selector.Select the organization or project that you want to view.

  3. Click the name of the resource associated with the scan configuration. TheScan configuration details page appears.

    If there are errors in your configuration, theScan status field showsView errors.

    View errors button in the scan configuration details

  4. ClickView errors. TheErrors pane appears. For each error, thefollowing details are provided:

    • Date and time the error was detected
    • Error code
    • Detailed error message

    For certain types of errors, aRepair button might be available.

  5. If aRepair button is available and if you have resolved the cause of theerror, clickRepair. Sensitive Data Protection retries processing thescan configuration and resolves the error if all requirements are met.

What's next

Except as otherwise noted, the content of this page is licensed under theCreative Commons Attribution 4.0 License, and code samples are licensed under theApache 2.0 License. For details, see theGoogle Developers Site Policies. Java is a registered trademark of Oracle and/or its affiliates.

Last updated 2025-12-17 UTC.