Forum Discussion
Sohel68
Mar 20, 2025Copper Contributor
Content Explorer in Insider Risk: Upload files to cloud
I can see file content in IRM content explorer as long they are within M365: however, when file has been uploaded to Google Drive and/or Dropbox I can the activity such as file name, destination doma...
alta94
Mar 22, 2025Copper Contributor
What happen if you try creating a DLP policy that do same ?
When user will violate , irrespective of domain evidence should be able to collect.
Create the DLP policy with "allow some but block rest of all" logic.
Sohel68
Mar 24, 2025Copper Contributor
We do have a DLP policy to block uploads to any external site like Google Drive\DropBox - which currently applied only on 'leavers'. However, if someone uploads the file and then submits the resignation then it will bypass the DLP rule. I believe something like below may work.
https://learn.microsoft.com/en-us/purview/dlp-copy-matched-items-get-started?tabs=purview-portal%2Cpurview