Forum Discussion
In bound Email triggers DLP Policy
DLP does not trigger inbound, and there are no such options to configure. If you previously had DLP rules configured in the Exchange Admin Center, it's possible that some of the corresponding Transport rules are misconfigured to fire on both outgoing/incoming messages, so check for that.
TonyRedmond might have some additional insights here.
1. Do you have transport rules configured with DLP?
2. The SCC (Office 365) DLP rules are expanding their coverage of email operations, so it is possible that they might have caught this too.
Impossible to say what happened without looking at the rules. Can you share the logic?
- Ian DickerApr 03, 2018Copper Contributor
The rules were created in the SCC - nothing has ever been done in Exchange.
The weird thing is that I have checked and there are other emails that were received to the accounts payable address which also contained information which should have triggered the same rule but did not. It appears to have been from 2 email senders that the issue occurred.
Is there a way to prevent DLP from inbound external email?
- VasilMichevMar 22, 2018MVP
I'm almost 100% sure that's not caused by the Unified DLP - I just did a test to confirm. Outbound was captured, inbound arrived with no detections.
- Ian DickerMar 26, 2018Copper Contributor
Hmm, i'll take a look at at the Exchange admin - but I dont believe I have ever configured anything there - it was all done from Sec & Comp center.
- MooreSecurityMar 26, 2018Brass ContributorI've got a DLP rule in SCC that is set to detect "Any volume of content detected U.S. Financial CC only".. and this setting catches external emails coming in that contains CC data.