SlideShare a Scribd company logo
Data Loss Prevention in O365:The Basics
An overview of the data loss prevention offerings from Microsoft to help your
business stay secure in today's challenging digital world.
Don Daubert
Covenant Technology Partners
Twitter @sharepointroxs
ddaubert@mailctp.com
Gold Sponsors
SHAREPOINT SATURDAY ST.LOUIS 2018
Silver Sponsors
Bronze Sponsors
What is Data Loss Prevention?
• Data loss prevention (DLP) is a strategy for
making sure that users do not send sensitive or
critical information outside the enterprise.
• As part of that strategy a softwarecloud solution
is usually implemented that uses policies or
business rules to protect data.
• Data at Rest – File Shares, Archives, Storage,
Backups.
• Data In Motion – Across Network, Email, Sharing.
• Data In Use – CopyPaste, Printing, Faxing, Screen
Capture.
• How? – Data Matching, Rule Matching, Regex,
Metadata.
Who should implement a DLP Strategy?
• Everyone 
• Financial Institutions, Educational Institutions, Health
Care
• Types of information to protect
• HIPPA
• PII
• PHI
• Why - http://focus.forsythe.com/articles/19/10-
Reasons-Why-Your-Organization-Needs-Data-Loss-
Prevention
• Auditing, Compliance, Security, Financial, Prevention
• DLP Deployment Tips -
https://www.csoonline.com/article/2134517/it-
strategy/strategic-planning-erm-7-strategies-for-a-
successful-dlp-strategy.html
45%
DLP vs RMS + SharingIntune
• Together - Both provides a comprehensive way in which customers can protect their data in during the
lifecycle of that data including data in motion, at rest and in use.
• DLP – Files and sensitive types must match rules.
• DLP – Prevent accidentalintentional sharing and email communication.
• Some sharing features assist with this
• Intune Conditional Access policies assist with MDM
• RMS - Prevent sensitive information from being printed, forwarded, or copied by unauthorized people.
• Access and permissions stored in file
• OneDrive For Business and SharePoint Sharing Security -
https://techcommunity.microsoft.com/t5/OneDrive-Blog/Introducing-a-new-secure-external-sharing-
experience/ba-p/112624
• Intune – Secure Devices, Access policies
• Microsoft 365 – O365, Windows 10, EMS (Enterprise Mobility & Security) - https://www.microsoft.com/en-
us/microsoft-365/enterprise/home
What is Data Loss Prevention in O365?
• Discovery and protection of sensitive data in the enterprise.
• Risk Mitigation.
• An automated process to simplify security.
• Common policies across the enterprise.
• File protection during lifecycle for data at rest and in motion.
• In use (Other methods ie RMS, Windows Policies, Internet Policies)- Copy to
USB, Screeenshot sharing, Exposure to Dropbox, GoogleDrive
• Must have E3 or E5 Plan - https://technet.microsoft.com/en-
us/library/office-365-plan-options.aspx
Deeper Dive…O365
• Identify sensitive information across many locations.
• Exchange Online
• SharePoint Online
• OneDrive For Business
• Policies apply to each or across all
• Prevent accidental or intentional sharing of
sensitive data
• Works in the Desktop versions of Word 2016, Excel
2016, Outlook 2016, PowerPoint 2016.
• Works in Mobile versions of Office Products – OD4B,
Outlook, SharePoint.
• Help users stay compliant – Policy tips.
• Reporting of incidents.
• Implement in “test” or “monitor” mode to watch
false +- and ensure actions are accurate before
deployment.
• Works hand in hand with O365 Message Encryption.
Under The Hood…Information Sensitive Types
• Manage from Office 365 Security & Compliance
Center.
• Exchange Online Transport rules and DLP can be created
in EXO Admin but will not appear in Security &
Compliance.
• Policies for all (SPO, EXO, OD4B) must be created here.
• Out Of The Box
• Information Sensitive Types Definitions
• SSN, Phone, Drivers License, Credit Card #, Bank Account #.
• Can create Custom Sensitive Types with .xml and
Powershell.
• Customization - https://support.office.com/en-
us/article/create-a-custom-sensitive-information-type-
82c382a5-b6db-44fd-995d-b333b3c7fc30
... Policies
• Policies contain rules.
• Where – Location of content to protect. SharePoint Online, Exchange Online,
OneDrive For Business.
• SPO - All or select
• OD4B – All or Select
• EXO – All (Cannot chose individual MB’s yet)
• Rules – These enforce your business requirements.
• Conditions – The content must match before the rule is enforced -- for example, look
only for content containing Social Security numbers that's been shared with people
outside your organization.
• Actions - that you want the rule to take automatically when content matching the
conditions is found -- for example, block access to the document and send both the
user and compliance officer an email notification.
• Out Of The Box Templates
• Simple and Advanced Settings
• User Notification and Overrides – Business Justification.
• Policy Tips – User education and compliance.
Outlook 2013 + and Outlook Web
SPO & OD4B
Excel 2016, Word 2016. Powerpoint 2016 stored on site included in DLP
policy
Can create and upload custom policies with Powershell.
• Grouping and Logical Operators
• Group sensitive information types.
• Choose the logical operator between the sensitive information types
within a group and between the groups themselves.
• Examples – And, Or, Any Of These
• Rule Priority
• Set in order of creation
• Rule Tuning
• Adjust for false + or false –
• Match Accuracy - Percentage of accuracy
• Labels
• Can use Labels as a condition for rule matching
• Publish – Users manually apply Labels
• Auto-Apply
• Deployment - If you’re creating DLP policies with a large potential
impact, this sequence is recommended:
• Start in test mode without Policy Tips and then use the DLP reports and
any incident reports to assess the impact. You can use DLP reports to
view the number, location, type, and severity of policy matches. Based
on the results, you can fine tune the rules as needed. In test mode, DLP
policies will not impact the productivity of people working in your
organization.
• Move to Test mode with notifications and Policy Tips so that you can
begin to teach users about your compliance policies and prepare them
for the rules that are going to be applied. At this stage, you can also ask
users to report false positives so that you can further refine the rules.
• Start full enforcement on the policies so that the actions in the rules
are applied and the content’s protected. Continue to monitor the DLP
reports and any incident reports or notifications to make sure that the
results are what you intend.
• Reporting
• Focus on specific time periods and understand the reasons for spikes and trends.
• Discover business processes that violate your organization’s compliance policies.
• Understand any business impact of the DLP policies
• Fine tuning policies and rules
How it Works?
• That’s Level 200 
• EXO - Once created, syncs to EXO, Outlook Web, Desktop
• SPO & OD4B – Search
Questions?Time For Demo?

More Related Content

What's hot

Microsoft 365 Compliance
Microsoft 365 ComplianceMicrosoft 365 Compliance
Microsoft 365 Compliance
David J Rosenthal
 
Communication Compliance in Microsoft 365
Communication Compliance in Microsoft 365Communication Compliance in Microsoft 365
Communication Compliance in Microsoft 365
Joanne Klein
 
IRMS UG Principles of Retention in Microsoft 365
IRMS UG Principles of Retention in Microsoft 365IRMS UG Principles of Retention in Microsoft 365
IRMS UG Principles of Retention in Microsoft 365
Joanne Klein
 
Office365 security in depth
Office365 security in depthOffice365 security in depth
Office365 security in depth
Alberto Pascual
 
M365 Virtual Marathon: Retention in Office 365 - the Where What and How
M365 Virtual Marathon: Retention in Office 365 - the Where What and HowM365 Virtual Marathon: Retention in Office 365 - the Where What and How
M365 Virtual Marathon: Retention in Office 365 - the Where What and How
Joanne Klein
 
SPFest Chicago - Information Management and Data Governance in Office 365
SPFest Chicago - Information Management and Data Governance in Office 365SPFest Chicago - Information Management and Data Governance in Office 365
SPFest Chicago - Information Management and Data Governance in Office 365
Joanne Klein
 
M365 Records Management Community Webinar
M365 Records Management Community WebinarM365 Records Management Community Webinar
M365 Records Management Community Webinar
Drew Madelung
 
Best Practices for Implementing Data Loss Prevention (DLP)
Best Practices for Implementing Data Loss Prevention (DLP)Best Practices for Implementing Data Loss Prevention (DLP)
Best Practices for Implementing Data Loss Prevention (DLP)
Sarfaraz Chougule
 
Kyle Taylor – increasing your security posture using mc afee epo
Kyle Taylor – increasing your security posture using mc afee epoKyle Taylor – increasing your security posture using mc afee epo
Kyle Taylor – increasing your security posture using mc afee epo
Kyle Taylor
 
Microsoft Teams in the Modern Workplace
Microsoft Teams in the Modern WorkplaceMicrosoft Teams in the Modern Workplace
Microsoft Teams in the Modern Workplace
Joanne Klein
 
Information management and data governance in Office 365
Information management and data governance in Office 365Information management and data governance in Office 365
Information management and data governance in Office 365
Joanne Klein
 
Azure Information Protection - Taking a Team Approach - SPS Montreal
Azure Information Protection - Taking a Team Approach - SPS MontrealAzure Information Protection - Taking a Team Approach - SPS Montreal
Azure Information Protection - Taking a Team Approach - SPS Montreal
Joanne Klein
 
Microsoft 365 | Modern workplace
Microsoft 365 | Modern workplaceMicrosoft 365 | Modern workplace
Microsoft 365 | Modern workplace
Siddick Elaheebocus
 
One name unify them all
One name unify them allOne name unify them all
One name unify them all
BizTalk360
 
Top 10 Best Practices for Implementing Data Classification
Top 10 Best Practices for Implementing Data ClassificationTop 10 Best Practices for Implementing Data Classification
Top 10 Best Practices for Implementing Data Classification
Watchful Software
 
Empowering the business for eDiscovery in Office 365 - BRK2112
Empowering the business for eDiscovery in Office 365 - BRK2112Empowering the business for eDiscovery in Office 365 - BRK2112
Empowering the business for eDiscovery in Office 365 - BRK2112
Joanne Klein
 
Rencore Webinar: Understanding EU GDPR from an Office 365 perspective with Pa...
Rencore Webinar: Understanding EU GDPR from an Office 365 perspective with Pa...Rencore Webinar: Understanding EU GDPR from an Office 365 perspective with Pa...
Rencore Webinar: Understanding EU GDPR from an Office 365 perspective with Pa...
Rencore
 
Microsoft Information Protection: Your Security and Compliance Framework
Microsoft Information Protection: Your Security and Compliance FrameworkMicrosoft Information Protection: Your Security and Compliance Framework
Microsoft Information Protection: Your Security and Compliance Framework
Alistair Pugin
 
Governance in o365 share point online. yes, you can and yes, you should
Governance in o365 share point online. yes, you can and yes, you shouldGovernance in o365 share point online. yes, you can and yes, you should
Governance in o365 share point online. yes, you can and yes, you should
Don Daubert
 
CollabDaysBenelux2020 - Building a remarkable onboarding experience for new e...
CollabDaysBenelux2020 - Building a remarkable onboarding experience for new e...CollabDaysBenelux2020 - Building a remarkable onboarding experience for new e...
CollabDaysBenelux2020 - Building a remarkable onboarding experience for new e...
Corinna Lins
 

What's hot (20)

Microsoft 365 Compliance
Microsoft 365 ComplianceMicrosoft 365 Compliance
Microsoft 365 Compliance
 
Communication Compliance in Microsoft 365
Communication Compliance in Microsoft 365Communication Compliance in Microsoft 365
Communication Compliance in Microsoft 365
 
IRMS UG Principles of Retention in Microsoft 365
IRMS UG Principles of Retention in Microsoft 365IRMS UG Principles of Retention in Microsoft 365
IRMS UG Principles of Retention in Microsoft 365
 
Office365 security in depth
Office365 security in depthOffice365 security in depth
Office365 security in depth
 
M365 Virtual Marathon: Retention in Office 365 - the Where What and How
M365 Virtual Marathon: Retention in Office 365 - the Where What and HowM365 Virtual Marathon: Retention in Office 365 - the Where What and How
M365 Virtual Marathon: Retention in Office 365 - the Where What and How
 
SPFest Chicago - Information Management and Data Governance in Office 365
SPFest Chicago - Information Management and Data Governance in Office 365SPFest Chicago - Information Management and Data Governance in Office 365
SPFest Chicago - Information Management and Data Governance in Office 365
 
M365 Records Management Community Webinar
M365 Records Management Community WebinarM365 Records Management Community Webinar
M365 Records Management Community Webinar
 
Best Practices for Implementing Data Loss Prevention (DLP)
Best Practices for Implementing Data Loss Prevention (DLP)Best Practices for Implementing Data Loss Prevention (DLP)
Best Practices for Implementing Data Loss Prevention (DLP)
 
Kyle Taylor – increasing your security posture using mc afee epo
Kyle Taylor – increasing your security posture using mc afee epoKyle Taylor – increasing your security posture using mc afee epo
Kyle Taylor – increasing your security posture using mc afee epo
 
Microsoft Teams in the Modern Workplace
Microsoft Teams in the Modern WorkplaceMicrosoft Teams in the Modern Workplace
Microsoft Teams in the Modern Workplace
 
Information management and data governance in Office 365
Information management and data governance in Office 365Information management and data governance in Office 365
Information management and data governance in Office 365
 
Azure Information Protection - Taking a Team Approach - SPS Montreal
Azure Information Protection - Taking a Team Approach - SPS MontrealAzure Information Protection - Taking a Team Approach - SPS Montreal
Azure Information Protection - Taking a Team Approach - SPS Montreal
 
Microsoft 365 | Modern workplace
Microsoft 365 | Modern workplaceMicrosoft 365 | Modern workplace
Microsoft 365 | Modern workplace
 
One name unify them all
One name unify them allOne name unify them all
One name unify them all
 
Top 10 Best Practices for Implementing Data Classification
Top 10 Best Practices for Implementing Data ClassificationTop 10 Best Practices for Implementing Data Classification
Top 10 Best Practices for Implementing Data Classification
 
Empowering the business for eDiscovery in Office 365 - BRK2112
Empowering the business for eDiscovery in Office 365 - BRK2112Empowering the business for eDiscovery in Office 365 - BRK2112
Empowering the business for eDiscovery in Office 365 - BRK2112
 
Rencore Webinar: Understanding EU GDPR from an Office 365 perspective with Pa...
Rencore Webinar: Understanding EU GDPR from an Office 365 perspective with Pa...Rencore Webinar: Understanding EU GDPR from an Office 365 perspective with Pa...
Rencore Webinar: Understanding EU GDPR from an Office 365 perspective with Pa...
 
Microsoft Information Protection: Your Security and Compliance Framework
Microsoft Information Protection: Your Security and Compliance FrameworkMicrosoft Information Protection: Your Security and Compliance Framework
Microsoft Information Protection: Your Security and Compliance Framework
 
Governance in o365 share point online. yes, you can and yes, you should
Governance in o365 share point online. yes, you can and yes, you shouldGovernance in o365 share point online. yes, you can and yes, you should
Governance in o365 share point online. yes, you can and yes, you should
 
CollabDaysBenelux2020 - Building a remarkable onboarding experience for new e...
CollabDaysBenelux2020 - Building a remarkable onboarding experience for new e...CollabDaysBenelux2020 - Building a remarkable onboarding experience for new e...
CollabDaysBenelux2020 - Building a remarkable onboarding experience for new e...
 

Similar to Data Loss Prevention in O365

Deep dive into Microsoft Purview Data Loss Prevention
Deep dive into Microsoft Purview Data Loss PreventionDeep dive into Microsoft Purview Data Loss Prevention
Deep dive into Microsoft Purview Data Loss Prevention
Drew Madelung
 
March 2023 CIAOPS Need to Know Webinar
March 2023 CIAOPS Need to Know WebinarMarch 2023 CIAOPS Need to Know Webinar
March 2023 CIAOPS Need to Know Webinar
Robert Crane
 
SC-900 Capabilities of Microsoft Compliance Solutions
SC-900 Capabilities of Microsoft Compliance SolutionsSC-900 Capabilities of Microsoft Compliance Solutions
SC-900 Capabilities of Microsoft Compliance Solutions
FredBrandonAuthorMCP
 
Microsoft Cloud GDPR Compliance Options (SUGUK)
Microsoft Cloud GDPR Compliance Options (SUGUK)Microsoft Cloud GDPR Compliance Options (SUGUK)
Microsoft Cloud GDPR Compliance Options (SUGUK)
Andy Talbot
 
Breakdown of Microsoft Purview Solutions
Breakdown of Microsoft Purview SolutionsBreakdown of Microsoft Purview Solutions
Breakdown of Microsoft Purview Solutions
Drew Madelung
 
Intro to Data Loss Prevention in SharePoint 2016
Intro to Data Loss Prevention in SharePoint 2016Intro to Data Loss Prevention in SharePoint 2016
Intro to Data Loss Prevention in SharePoint 2016
Craig Jahnke
 
HSPUG presentation - Advanced Data Governance
HSPUG presentation - Advanced Data GovernanceHSPUG presentation - Advanced Data Governance
HSPUG presentation - Advanced Data Governance
David Broussard
 
Securing your digital world - Cybersecurity for SBEs
Securing your digital world - Cybersecurity for SBEsSecuring your digital world - Cybersecurity for SBEs
Securing your digital world - Cybersecurity for SBEsSonny Hashmi
 
Securing your digital world cybersecurity for sb es
Securing your digital world   cybersecurity for sb esSecuring your digital world   cybersecurity for sb es
Securing your digital world cybersecurity for sb es
Sonny Hashmi
 
SPSTC18 Laying Down the Law - Governing Your Data in O365
SPSTC18  Laying Down the Law - Governing Your Data in O365SPSTC18  Laying Down the Law - Governing Your Data in O365
SPSTC18 Laying Down the Law - Governing Your Data in O365
David Broussard
 
espc2023-protectandgovernyoursensitivedatawithmicrosoftpurviewinmicrosoftteam...
espc2023-protectandgovernyoursensitivedatawithmicrosoftpurviewinmicrosoftteam...espc2023-protectandgovernyoursensitivedatawithmicrosoftpurviewinmicrosoftteam...
espc2023-protectandgovernyoursensitivedatawithmicrosoftpurviewinmicrosoftteam...
zoheirop
 
ESPC 2023 - Protect and Govern your Sensitive Data with Microsoft Purview in ...
ESPC 2023 - Protect and Govern your Sensitive Data with Microsoft Purview in ...ESPC 2023 - Protect and Govern your Sensitive Data with Microsoft Purview in ...
ESPC 2023 - Protect and Govern your Sensitive Data with Microsoft Purview in ...
Jasper Oosterveld
 
Privacies are coming
Privacies are comingPrivacies are coming
Privacies are coming
Ernest Staats
 
Tuga it 2018 advanced data governance
Tuga it 2018   advanced data governanceTuga it 2018   advanced data governance
Tuga it 2018 advanced data governance
Albert Hoitingh
 
Webinar - Compliance with the Microsoft Cloud- 2017-04-19
Webinar - Compliance with the Microsoft Cloud- 2017-04-19Webinar - Compliance with the Microsoft Cloud- 2017-04-19
Webinar - Compliance with the Microsoft Cloud- 2017-04-19
TechSoup
 
Ensure your compliance in Microsoft Teams with Information Protection and Gov...
Ensure your compliance in Microsoft Teams with Information Protection and Gov...Ensure your compliance in Microsoft Teams with Information Protection and Gov...
Ensure your compliance in Microsoft Teams with Information Protection and Gov...
Jasper Oosterveld
 
Office 365 smb guidelines for pure bookkeeping (slideshare)
Office 365 smb guidelines for pure bookkeeping (slideshare)Office 365 smb guidelines for pure bookkeeping (slideshare)
Office 365 smb guidelines for pure bookkeeping (slideshare)
DavidNicholls52
 
aMS SouthEast Asia 2021 - Microsoft 365 Data Loss Prevention
aMS SouthEast Asia 2021 - Microsoft 365 Data Loss PreventionaMS SouthEast Asia 2021 - Microsoft 365 Data Loss Prevention
aMS SouthEast Asia 2021 - Microsoft 365 Data Loss Prevention
Albert Hoitingh
 
Privacies are Coming
Privacies are ComingPrivacies are Coming
Privacies are Coming
Ernest Staats
 
Information Governance in office 365 records management and retention
Information Governance in office 365 records management and retentionInformation Governance in office 365 records management and retention
Information Governance in office 365 records management and retention
John P. Collins | Information Governance
 

Similar to Data Loss Prevention in O365 (20)

Deep dive into Microsoft Purview Data Loss Prevention
Deep dive into Microsoft Purview Data Loss PreventionDeep dive into Microsoft Purview Data Loss Prevention
Deep dive into Microsoft Purview Data Loss Prevention
 
March 2023 CIAOPS Need to Know Webinar
March 2023 CIAOPS Need to Know WebinarMarch 2023 CIAOPS Need to Know Webinar
March 2023 CIAOPS Need to Know Webinar
 
SC-900 Capabilities of Microsoft Compliance Solutions
SC-900 Capabilities of Microsoft Compliance SolutionsSC-900 Capabilities of Microsoft Compliance Solutions
SC-900 Capabilities of Microsoft Compliance Solutions
 
Microsoft Cloud GDPR Compliance Options (SUGUK)
Microsoft Cloud GDPR Compliance Options (SUGUK)Microsoft Cloud GDPR Compliance Options (SUGUK)
Microsoft Cloud GDPR Compliance Options (SUGUK)
 
Breakdown of Microsoft Purview Solutions
Breakdown of Microsoft Purview SolutionsBreakdown of Microsoft Purview Solutions
Breakdown of Microsoft Purview Solutions
 
Intro to Data Loss Prevention in SharePoint 2016
Intro to Data Loss Prevention in SharePoint 2016Intro to Data Loss Prevention in SharePoint 2016
Intro to Data Loss Prevention in SharePoint 2016
 
HSPUG presentation - Advanced Data Governance
HSPUG presentation - Advanced Data GovernanceHSPUG presentation - Advanced Data Governance
HSPUG presentation - Advanced Data Governance
 
Securing your digital world - Cybersecurity for SBEs
Securing your digital world - Cybersecurity for SBEsSecuring your digital world - Cybersecurity for SBEs
Securing your digital world - Cybersecurity for SBEs
 
Securing your digital world cybersecurity for sb es
Securing your digital world   cybersecurity for sb esSecuring your digital world   cybersecurity for sb es
Securing your digital world cybersecurity for sb es
 
SPSTC18 Laying Down the Law - Governing Your Data in O365
SPSTC18  Laying Down the Law - Governing Your Data in O365SPSTC18  Laying Down the Law - Governing Your Data in O365
SPSTC18 Laying Down the Law - Governing Your Data in O365
 
espc2023-protectandgovernyoursensitivedatawithmicrosoftpurviewinmicrosoftteam...
espc2023-protectandgovernyoursensitivedatawithmicrosoftpurviewinmicrosoftteam...espc2023-protectandgovernyoursensitivedatawithmicrosoftpurviewinmicrosoftteam...
espc2023-protectandgovernyoursensitivedatawithmicrosoftpurviewinmicrosoftteam...
 
ESPC 2023 - Protect and Govern your Sensitive Data with Microsoft Purview in ...
ESPC 2023 - Protect and Govern your Sensitive Data with Microsoft Purview in ...ESPC 2023 - Protect and Govern your Sensitive Data with Microsoft Purview in ...
ESPC 2023 - Protect and Govern your Sensitive Data with Microsoft Purview in ...
 
Privacies are coming
Privacies are comingPrivacies are coming
Privacies are coming
 
Tuga it 2018 advanced data governance
Tuga it 2018   advanced data governanceTuga it 2018   advanced data governance
Tuga it 2018 advanced data governance
 
Webinar - Compliance with the Microsoft Cloud- 2017-04-19
Webinar - Compliance with the Microsoft Cloud- 2017-04-19Webinar - Compliance with the Microsoft Cloud- 2017-04-19
Webinar - Compliance with the Microsoft Cloud- 2017-04-19
 
Ensure your compliance in Microsoft Teams with Information Protection and Gov...
Ensure your compliance in Microsoft Teams with Information Protection and Gov...Ensure your compliance in Microsoft Teams with Information Protection and Gov...
Ensure your compliance in Microsoft Teams with Information Protection and Gov...
 
Office 365 smb guidelines for pure bookkeeping (slideshare)
Office 365 smb guidelines for pure bookkeeping (slideshare)Office 365 smb guidelines for pure bookkeeping (slideshare)
Office 365 smb guidelines for pure bookkeeping (slideshare)
 
aMS SouthEast Asia 2021 - Microsoft 365 Data Loss Prevention
aMS SouthEast Asia 2021 - Microsoft 365 Data Loss PreventionaMS SouthEast Asia 2021 - Microsoft 365 Data Loss Prevention
aMS SouthEast Asia 2021 - Microsoft 365 Data Loss Prevention
 
Privacies are Coming
Privacies are ComingPrivacies are Coming
Privacies are Coming
 
Information Governance in office 365 records management and retention
Information Governance in office 365 records management and retentionInformation Governance in office 365 records management and retention
Information Governance in office 365 records management and retention
 

Recently uploaded

Bonzo subscription_hjjjjjjjj5hhhhhhh_2024.pdf
Bonzo subscription_hjjjjjjjj5hhhhhhh_2024.pdfBonzo subscription_hjjjjjjjj5hhhhhhh_2024.pdf
Bonzo subscription_hjjjjjjjj5hhhhhhh_2024.pdf
khadija278284
 
0x01 - Newton's Third Law: Static vs. Dynamic Abusers
0x01 - Newton's Third Law:  Static vs. Dynamic Abusers0x01 - Newton's Third Law:  Static vs. Dynamic Abusers
0x01 - Newton's Third Law: Static vs. Dynamic Abusers
OWASP Beja
 
Bitcoin Lightning wallet and tic-tac-toe game XOXO
Bitcoin Lightning wallet and tic-tac-toe game XOXOBitcoin Lightning wallet and tic-tac-toe game XOXO
Bitcoin Lightning wallet and tic-tac-toe game XOXO
Matjaž Lipuš
 
somanykidsbutsofewfathers-140705000023-phpapp02.pptx
somanykidsbutsofewfathers-140705000023-phpapp02.pptxsomanykidsbutsofewfathers-140705000023-phpapp02.pptx
somanykidsbutsofewfathers-140705000023-phpapp02.pptx
Howard Spence
 
Acorn Recovery: Restore IT infra within minutes
Acorn Recovery: Restore IT infra within minutesAcorn Recovery: Restore IT infra within minutes
Acorn Recovery: Restore IT infra within minutes
IP ServerOne
 
Getting started with Amazon Bedrock Studio and Control Tower
Getting started with Amazon Bedrock Studio and Control TowerGetting started with Amazon Bedrock Studio and Control Tower
Getting started with Amazon Bedrock Studio and Control Tower
Vladimir Samoylov
 
Announcement of 18th IEEE International Conference on Software Testing, Verif...
Announcement of 18th IEEE International Conference on Software Testing, Verif...Announcement of 18th IEEE International Conference on Software Testing, Verif...
Announcement of 18th IEEE International Conference on Software Testing, Verif...
Sebastiano Panichella
 
Sharpen existing tools or get a new toolbox? Contemporary cluster initiatives...
Sharpen existing tools or get a new toolbox? Contemporary cluster initiatives...Sharpen existing tools or get a new toolbox? Contemporary cluster initiatives...
Sharpen existing tools or get a new toolbox? Contemporary cluster initiatives...
Orkestra
 
Obesity causes and management and associated medical conditions
Obesity causes and management and associated medical conditionsObesity causes and management and associated medical conditions
Obesity causes and management and associated medical conditions
Faculty of Medicine And Health Sciences
 
Eureka, I found it! - Special Libraries Association 2021 Presentation
Eureka, I found it! - Special Libraries Association 2021 PresentationEureka, I found it! - Special Libraries Association 2021 Presentation
Eureka, I found it! - Special Libraries Association 2021 Presentation
Access Innovations, Inc.
 
Doctoral Symposium at the 17th IEEE International Conference on Software Test...
Doctoral Symposium at the 17th IEEE International Conference on Software Test...Doctoral Symposium at the 17th IEEE International Conference on Software Test...
Doctoral Symposium at the 17th IEEE International Conference on Software Test...
Sebastiano Panichella
 
Competition and Regulation in Professional Services – KLEINER – June 2024 OEC...
Competition and Regulation in Professional Services – KLEINER – June 2024 OEC...Competition and Regulation in Professional Services – KLEINER – June 2024 OEC...
Competition and Regulation in Professional Services – KLEINER – June 2024 OEC...
OECD Directorate for Financial and Enterprise Affairs
 
International Workshop on Artificial Intelligence in Software Testing
International Workshop on Artificial Intelligence in Software TestingInternational Workshop on Artificial Intelligence in Software Testing
International Workshop on Artificial Intelligence in Software Testing
Sebastiano Panichella
 

Recently uploaded (13)

Bonzo subscription_hjjjjjjjj5hhhhhhh_2024.pdf
Bonzo subscription_hjjjjjjjj5hhhhhhh_2024.pdfBonzo subscription_hjjjjjjjj5hhhhhhh_2024.pdf
Bonzo subscription_hjjjjjjjj5hhhhhhh_2024.pdf
 
0x01 - Newton's Third Law: Static vs. Dynamic Abusers
0x01 - Newton's Third Law:  Static vs. Dynamic Abusers0x01 - Newton's Third Law:  Static vs. Dynamic Abusers
0x01 - Newton's Third Law: Static vs. Dynamic Abusers
 
Bitcoin Lightning wallet and tic-tac-toe game XOXO
Bitcoin Lightning wallet and tic-tac-toe game XOXOBitcoin Lightning wallet and tic-tac-toe game XOXO
Bitcoin Lightning wallet and tic-tac-toe game XOXO
 
somanykidsbutsofewfathers-140705000023-phpapp02.pptx
somanykidsbutsofewfathers-140705000023-phpapp02.pptxsomanykidsbutsofewfathers-140705000023-phpapp02.pptx
somanykidsbutsofewfathers-140705000023-phpapp02.pptx
 
Acorn Recovery: Restore IT infra within minutes
Acorn Recovery: Restore IT infra within minutesAcorn Recovery: Restore IT infra within minutes
Acorn Recovery: Restore IT infra within minutes
 
Getting started with Amazon Bedrock Studio and Control Tower
Getting started with Amazon Bedrock Studio and Control TowerGetting started with Amazon Bedrock Studio and Control Tower
Getting started with Amazon Bedrock Studio and Control Tower
 
Announcement of 18th IEEE International Conference on Software Testing, Verif...
Announcement of 18th IEEE International Conference on Software Testing, Verif...Announcement of 18th IEEE International Conference on Software Testing, Verif...
Announcement of 18th IEEE International Conference on Software Testing, Verif...
 
Sharpen existing tools or get a new toolbox? Contemporary cluster initiatives...
Sharpen existing tools or get a new toolbox? Contemporary cluster initiatives...Sharpen existing tools or get a new toolbox? Contemporary cluster initiatives...
Sharpen existing tools or get a new toolbox? Contemporary cluster initiatives...
 
Obesity causes and management and associated medical conditions
Obesity causes and management and associated medical conditionsObesity causes and management and associated medical conditions
Obesity causes and management and associated medical conditions
 
Eureka, I found it! - Special Libraries Association 2021 Presentation
Eureka, I found it! - Special Libraries Association 2021 PresentationEureka, I found it! - Special Libraries Association 2021 Presentation
Eureka, I found it! - Special Libraries Association 2021 Presentation
 
Doctoral Symposium at the 17th IEEE International Conference on Software Test...
Doctoral Symposium at the 17th IEEE International Conference on Software Test...Doctoral Symposium at the 17th IEEE International Conference on Software Test...
Doctoral Symposium at the 17th IEEE International Conference on Software Test...
 
Competition and Regulation in Professional Services – KLEINER – June 2024 OEC...
Competition and Regulation in Professional Services – KLEINER – June 2024 OEC...Competition and Regulation in Professional Services – KLEINER – June 2024 OEC...
Competition and Regulation in Professional Services – KLEINER – June 2024 OEC...
 
International Workshop on Artificial Intelligence in Software Testing
International Workshop on Artificial Intelligence in Software TestingInternational Workshop on Artificial Intelligence in Software Testing
International Workshop on Artificial Intelligence in Software Testing
 

Data Loss Prevention in O365

  • 1. Data Loss Prevention in O365:The Basics An overview of the data loss prevention offerings from Microsoft to help your business stay secure in today's challenging digital world. Don Daubert Covenant Technology Partners Twitter @sharepointroxs ddaubert@mailctp.com
  • 2. Gold Sponsors SHAREPOINT SATURDAY ST.LOUIS 2018 Silver Sponsors Bronze Sponsors
  • 3. What is Data Loss Prevention? • Data loss prevention (DLP) is a strategy for making sure that users do not send sensitive or critical information outside the enterprise. • As part of that strategy a softwarecloud solution is usually implemented that uses policies or business rules to protect data. • Data at Rest – File Shares, Archives, Storage, Backups. • Data In Motion – Across Network, Email, Sharing. • Data In Use – CopyPaste, Printing, Faxing, Screen Capture. • How? – Data Matching, Rule Matching, Regex, Metadata.
  • 4. Who should implement a DLP Strategy? • Everyone  • Financial Institutions, Educational Institutions, Health Care • Types of information to protect • HIPPA • PII • PHI • Why - http://focus.forsythe.com/articles/19/10- Reasons-Why-Your-Organization-Needs-Data-Loss- Prevention • Auditing, Compliance, Security, Financial, Prevention • DLP Deployment Tips - https://www.csoonline.com/article/2134517/it- strategy/strategic-planning-erm-7-strategies-for-a- successful-dlp-strategy.html 45%
  • 5. DLP vs RMS + SharingIntune • Together - Both provides a comprehensive way in which customers can protect their data in during the lifecycle of that data including data in motion, at rest and in use. • DLP – Files and sensitive types must match rules. • DLP – Prevent accidentalintentional sharing and email communication. • Some sharing features assist with this • Intune Conditional Access policies assist with MDM • RMS - Prevent sensitive information from being printed, forwarded, or copied by unauthorized people. • Access and permissions stored in file • OneDrive For Business and SharePoint Sharing Security - https://techcommunity.microsoft.com/t5/OneDrive-Blog/Introducing-a-new-secure-external-sharing- experience/ba-p/112624 • Intune – Secure Devices, Access policies • Microsoft 365 – O365, Windows 10, EMS (Enterprise Mobility & Security) - https://www.microsoft.com/en- us/microsoft-365/enterprise/home
  • 6. What is Data Loss Prevention in O365? • Discovery and protection of sensitive data in the enterprise. • Risk Mitigation. • An automated process to simplify security. • Common policies across the enterprise. • File protection during lifecycle for data at rest and in motion. • In use (Other methods ie RMS, Windows Policies, Internet Policies)- Copy to USB, Screeenshot sharing, Exposure to Dropbox, GoogleDrive • Must have E3 or E5 Plan - https://technet.microsoft.com/en- us/library/office-365-plan-options.aspx
  • 7. Deeper Dive…O365 • Identify sensitive information across many locations. • Exchange Online • SharePoint Online • OneDrive For Business • Policies apply to each or across all • Prevent accidental or intentional sharing of sensitive data • Works in the Desktop versions of Word 2016, Excel 2016, Outlook 2016, PowerPoint 2016. • Works in Mobile versions of Office Products – OD4B, Outlook, SharePoint. • Help users stay compliant – Policy tips. • Reporting of incidents. • Implement in “test” or “monitor” mode to watch false +- and ensure actions are accurate before deployment. • Works hand in hand with O365 Message Encryption.
  • 8. Under The Hood…Information Sensitive Types • Manage from Office 365 Security & Compliance Center. • Exchange Online Transport rules and DLP can be created in EXO Admin but will not appear in Security & Compliance. • Policies for all (SPO, EXO, OD4B) must be created here. • Out Of The Box • Information Sensitive Types Definitions • SSN, Phone, Drivers License, Credit Card #, Bank Account #. • Can create Custom Sensitive Types with .xml and Powershell. • Customization - https://support.office.com/en- us/article/create-a-custom-sensitive-information-type- 82c382a5-b6db-44fd-995d-b333b3c7fc30
  • 9. ... Policies • Policies contain rules. • Where – Location of content to protect. SharePoint Online, Exchange Online, OneDrive For Business. • SPO - All or select • OD4B – All or Select • EXO – All (Cannot chose individual MB’s yet) • Rules – These enforce your business requirements. • Conditions – The content must match before the rule is enforced -- for example, look only for content containing Social Security numbers that's been shared with people outside your organization. • Actions - that you want the rule to take automatically when content matching the conditions is found -- for example, block access to the document and send both the user and compliance officer an email notification. • Out Of The Box Templates • Simple and Advanced Settings • User Notification and Overrides – Business Justification.
  • 10. • Policy Tips – User education and compliance. Outlook 2013 + and Outlook Web SPO & OD4B Excel 2016, Word 2016. Powerpoint 2016 stored on site included in DLP policy Can create and upload custom policies with Powershell. • Grouping and Logical Operators • Group sensitive information types. • Choose the logical operator between the sensitive information types within a group and between the groups themselves. • Examples – And, Or, Any Of These • Rule Priority • Set in order of creation • Rule Tuning • Adjust for false + or false – • Match Accuracy - Percentage of accuracy • Labels • Can use Labels as a condition for rule matching • Publish – Users manually apply Labels • Auto-Apply
  • 11. • Deployment - If you’re creating DLP policies with a large potential impact, this sequence is recommended: • Start in test mode without Policy Tips and then use the DLP reports and any incident reports to assess the impact. You can use DLP reports to view the number, location, type, and severity of policy matches. Based on the results, you can fine tune the rules as needed. In test mode, DLP policies will not impact the productivity of people working in your organization. • Move to Test mode with notifications and Policy Tips so that you can begin to teach users about your compliance policies and prepare them for the rules that are going to be applied. At this stage, you can also ask users to report false positives so that you can further refine the rules. • Start full enforcement on the policies so that the actions in the rules are applied and the content’s protected. Continue to monitor the DLP reports and any incident reports or notifications to make sure that the results are what you intend. • Reporting • Focus on specific time periods and understand the reasons for spikes and trends. • Discover business processes that violate your organization’s compliance policies. • Understand any business impact of the DLP policies • Fine tuning policies and rules
  • 12. How it Works? • That’s Level 200  • EXO - Once created, syncs to EXO, Outlook Web, Desktop • SPO & OD4B – Search