Forum Discussion

Andrew1's avatar
Andrew1
Copper Contributor
Jan 21, 2020

Sensitivity Label Endpoint data loss prevention does nothing

I'm trying to set up sensitivity labels and Windows Information Protection to prevent employees from accidentally or purposefully leaking sensitive documents to non-corporate environments.

 

Everything with WIP works great, it's configured via Intune, and sensitivity labels appear to be working.

 

However, I'm not sure what the point is of the sensitivity label option for "Endpoint data loss prevention". If I apply a SUPER SECRET sensitivity label to a Word document with the option enabled, users are still able to simply right click and change file ownership to Personal, and then they can email it from their personal gmail account or whatever. So it's not enforcing endpoint DLP at all.

 

The "https://docs.microsoft.com/en-us/windows/security/information-protection/windows-information-protection/how-wip-works-with-labels" link on the settings page says "If endpoint data loss prevention is enabled, the device enforces work protection for any file with the label", but it's not a very detailed section.

 

How can I stop users from changing ownership of files, and is it possible to restrict that ability based on the sensitivity label?

1 Reply

  • JavierCaro's avatar
    JavierCaro
    Copper Contributor

    HI Andrew1 

     

    I am facing similar scenario. You can restrict this capability deleting this registry Key:

     

    HKEY_CLASSES_ROOT\*\shell\UpdateEncryptionSettingsWork

     

    It is not documented by Microsoft; since this is an EFS setting.

Resources