Forum Discussion

Sankaperera's avatar
Sankaperera
Copper Contributor
Jun 17, 2025

DLP policy to block US SSN

I have created a DLP policy to block US SSN number by targetting Teams & Email as below. It doesn't block the SSN numbers post 24 hrs. Any suggestions

 

3 Replies

    • Sankaperera's avatar
      Sankaperera
      Copper Contributor

      VasilMichev​ I have tried changing it external yet it doesn't understand the number pattern and block the SSN. However, it blocks with SSN word. My requirement is to block sending SSN number either pattern or with SSN and the number pattern

      • vicwingsing's avatar
        vicwingsing
        Iron Contributor

        Don't force everything into 1 rule set. 

        You can create multiple rule sets within the same policy. 

        rule 1: Monitor SSN for Internal only.

        rule 2: Monitor SSN for External only.

        By making these 2 rules, you make it easier for yourself and the policy.