Forum Widgets
Latest Discussions
Purview -> DLP -> Settings -> Endpoint DLP Settings
I have configured Browser and Domain Restrictions to sensitive data, with a condition as a sensitivity label. I used the Allow for a whitelist for sites, and all others should be blocked. I created and assigned a DLP. I assigned the DLP to sharepoint/Onedrive/devices, allsites/all users&groups/all users&groups. The sensitivity label is published\assigned. But it is not blocking the web sites. What am I missing? My understanding is that DLP policies should inherit the DLP settings by default. I cannot seem to 'on-board' devices in Purview. As it is greyed out. I have MS Business Premium, which includes MS Defender for Business, MS InTune.learnazure_adFeb 18, 2025Brass Contributor1.6KViews2likes17CommentsIssues with AutoSave and Sensitivity Labels – Need Advice on Best Practices
Hello everyone, I'm currently facing an issue with implementing Sensitivity Labels in Microsoft 365, and I was hoping to get some insights from others who might have encountered similar challenges. The Setup: We’ve implemented Sensitivity Labels with encryption in our organization to ensure external users are always authenticated when accessing our files. Our files are primarily stored on our on-premises servers. We’ve configured the labels to restrict access to authenticated users, with different permissions based on user roles (e.g., Co-Owners for internal users and restricted permissions for external users). The Problem: While the labeling process is working as expected, one significant issue we've run into is that AutoSave no longer functions correctly after applying the labels, particularly for documents that are encrypted when using the client app. The documents are not saving automatically, which can lead to information loss and angry employees. 🥺 I can live with the limitation that the label can only be applied in the client application (i.e., not through the web interface). However, the AutoSave problem is a significant hurdle. Questions for the Community: Has anyone else encountered issues with AutoSave after applying Sensitivity Labels with encryption? How did you work around this? Are there any best practices or configuration adjustments I should consider to resolve this issue? How have other organizations handled the authentication requirement for external users while still ensuring a smooth workflow? Looking forward to hearing your thoughts and experiences! Thanks in advance!SolvedSophie_BruehlJan 07, 2025Iron Contributor840Views0likes2CommentsHow to use Microsoft Purview to scan data in Fabric Lake House
We are exploring Microsoft Fabric for our data analytics and reporting. Some concerns relate to the protection and security of sensitive data (e.g., PII). I've connected my Microsoft Fabric to Purview and have all assets in my Fabric tenant scanned. They don't seem to give me any data. Instead, the scanned list contains Lake House, Pipeline, and Power BI datasets. How can I scan data in my Fabric Lakehouse and/or Power BI dataset?thuanssJan 30, 2025Copper Contributor499Views0likes1CommentCustom colors for Sensitivity Label's content marking in Purview
We have implemented Sensitivity labels at our org, which also contains content markings for each label. But Microsoft Purview Compliance Portal only allows us to choose from Black, Yellow, Blue, Green and Red. But I want to choose Amber or Orange as color for content marking. How do I do that?SolvedKavishJan 27, 2025Copper Contributor433Views1like2CommentsLockdown owerApps HTTP Conector
I have been asked to apply data security control over the PowerApps HTTP connector by either whitelisting the URI that it can access or applying block control based on content inspection. Can that be done using Defender for Cloud Apps, Purview Compliance DLP or another product? thanks GrahamGrahamP67Dec 04, 2024Copper Contributor335Views0likes0Comments"Purview DLP policy is not working as expected."
I am creating a DLP policy with the following configurations: A new policy applied to devices was generated. --SCOPE Devices --USERS DLP_TEST --A rule is created: DLP_TEST_APPSBLOCK --THE FOLLOWING CONDITIONS ARE ADDED Document could not be scanned Document did not complete analysis File type is: Word Processing Spreadsheet Presentation Archive Mail File extension is: py txt HTML --THE FOLLOWING ACTIONS ARE ADDED Application groups: DLP_TEST_APPS Copy to clipboard: Block Print: Block Copy to USB: Block Copy to shared network resource: Block --APPLICATIONS NOT IN THE SHARED APPLICATION GROUPS Configuration: Block with override --NOTIFICATIONS Use notifications to inform users and properly teach them about sensitive information: Enabled ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ In restricted applications, even though I have blocked everything, it still allows me to attach documents from WhatsApp. Although it prevents copying or dragging, I can always upload documents, which should not happen. This is just a test, but I would like to know what is happening and how I can solve itMelvin_Maldonado03Mar 31, 2025Copper Contributor304Views0likes1CommentSuppress Alerting to Endpoint DLP Printing on "Print to PDF".
Is there a way to configure an Endpoint DLP policy for Printing to NOT alert on "Print to File" events primarily Print to PDf's. For example print events where the target name are "Microsoft Print to PDF" or "Adobe PDF"? I understand you can create Printer groups, but there is no way to use as a condition when creating DLP rule.Dalesh07Mar 31, 2025Copper Contributor287Views0likes5CommentsHow do I exclude certain part of email from being scanned?
Hi there, I have enabled client-side auto Sensitivity labelling for emails in a tenant for PII detection using pre-built SIT & Trainable Classifiers. However, the issue is that the Email signature automatically makes the check true and applies the label automatically, which I want to avoid. Is there a way for me to exclude the signature part of the email from being excluded?Rohit YadavFeb 17, 2025Bronze Contributor272Views0likes3CommentsDLP Policy Rule "U.S. Physical Address" exclusion
We have the built in Sensitive Info Type "U.S. Physical Address" in our Default HR & Privacy Info Protection Policy in simulation. This is set to the location of just Exchange Email only. Everyone in the company has our physical address in their email signature. This combination keeps triggering alerts even if I set the instance count to something like 3. I've asked Co-Pilot for instructions to create an exclusion where I can enter our physical address to be ignored but the instructions always mention options that don't exist in the rule edit screen. I see online people asking for signatures to be ignored but the response is they can't be. Am I doomed to ask all staff to remove their signature, remove this SIT altogether, or just let the Action of "encrypt email messages" proceed and have our organization look the fool for encrypting every email sent outside the organization? Anyone know how to tell Purview to ignore your own physical address?ENMRSHMay 13, 2025Copper Contributor266Views0likes8CommentsHow Can We Extend Data Protection Beyond Microsoft 365?
Hey everyone, I am running into a bit of a roadblock. I am trying to find a way to ensure consistent data classification and protection across our diverse IT landscape. While Microsoft Protection Policies are greeat for Microsoft Solutions, I'm struggling to extend that coverage to systems like SAP and our HR solution. Has anyone else faced a similar challenge? I'd love to hear any tips or solutions ou've come up with.Solved237Views1like4Comments
Resources
Tags
- sensitivit label4 Topics
- sensitivity label2 Topics
- dlp2 Topics
- purview2 Topics
- PowerApps Connector1 Topic
- Defender XDR1 Topic
- dlp block1 Topic
- protection policy1 Topic
- Information Protection1 Topic
- encryption1 Topic