In the Cloud SWG policy, when in Portal mode, policy is applied to block actions like Download Files, Download Video, Upload Files, etc. for the Whatsapp domains (*.whatsapp.com, *.whatsapp.net) or for the Destination category "Chat (IM)/SMS".
After saving the policy, the restricted actions still can be executed in Whatsapp.
The cause of this issue is a limitation in the Cloud SWG policy when in portal mode for the application control. Whatsapp is not one of the applications that is supported for Content and Limits condition.
Please see below steps to see what applications are supported in Cloud SWG for the Content and Limits control field:
Whatsapp is not in the Filter list of the applications. If the application isn't there, Cloud SWG cannot apply application control policy for actions to it.
Another site where we can see what applications support the different control actions is the below site. By clicking in the control operation desired, in the "Used By" list we will see the applications that support such control:
https://sitereview.bluecoat.com/#/application-operations
Application control to Whatsapp can be achieved from the CASB portal after the Cloud SWG tenant has been integrated with the CASB product. Information on the integration process below:
Integrate Cloud SWG With CloudSOC (CASB)
A second option is to change the policy mode of the Cloud SWG tenant from Portal Mode to UPE mode. For that, Management Center is required to control the policy and knowledge of CPL policy code. Policy must be re-done after the change.