#Microsoft Purview | Creating a DLP policy that prevents sensitive data from being shared externally

1 messages · Page 1 of 1 (latest)

hollow rock
#

Hello, I am helping a business set up Microsoft Purview as an intern.

After initial deployment of a couple policies auditing the presence of sensitive data (PII data, credit cards etc), I have proposed only scanning for Credit card information being shared outside of the organisation.

All of the activity was generated from 3 sources, Exchange, OneDrive and SharePoint. The organisation prevents OneDrive and SharePoint links being accessed outside of the organisation so I am focused on Exchange.

Basically my problem atm is when configuring the policy, I can't find an option/exception/condition that will allow me to specify emails sent OUTSIDE of the organisation.

umbral patrol
#

When you are making the policy there are 2 main options. When the information is shared internally and when externally. You are looking for that.

hollow rock
#

These are the conditions

umbral patrol
#

If you go to rules and conditions there are only 2 options

#

"Content contains" and "content is shared from Microsoft 365"

#

You want the second one

hollow rock
#

this is on the Microsoft Purview Compliance portal btw

umbral patrol
#

And what are the locations you have selected ?

hollow rock
#

at the moment, Exchange email and Devices

umbral patrol
#

Remove devices