Forum Discussion
Testing O365 DLP Policy
- Jan 04, 2019
Hi Suolon,
Not a problem - can understand the anxieties if you haven't done if before. They should not be blocked from sending out the emails unless you choose to block them.
You can find out more about the encryption here
https://docs.microsoft.com/en-us/office365/securitycompliance/email-encryption
And the recipient experience here
https://www.peters.com/office-365-message-encryption-ome/
Encryption is designed for automated encryption of sensitive data; for example school or patient PII data. Most organisation's I have worked with tend to block as they don't want this information going out over email and prefer a different sharing forum such as Microsoft Teams (I.e. guest access)
Best, Chris
Yes, that is correct, and is confirmed in the following article which should also provide some guidance and what to expect
https://docs.microsoft.com/en-us/office365/securitycompliance/create-test-tune-dlp-policy
There is also a string I would recommend here on the Community which also discusses setting up notifications for overrides and actions to take when users have performed an override of the DLP policy
https://techcommunity.microsoft.com/t5/Security-Privacy-Compliance/Overrides-and-false-positives-in-DLP-policy-end-user-experience/td-p/202790
Hope I have answered your question. If I have, please like and set as the solution. If not, please let me know what more I can do to help. Thanks for raising this to the Tech Community.
Best, Chris
Hi Chris,
Thanks again for responding to my post. I'm just checking out your two links now.
I have already created 5 DLP policies for our tenant, all which are in test mode with Policy Tips, but during the test I don't see anywhere to override and it wasn't clear in the setup if we would see the override.
I'm just worried that once I turn on the DLP, that the users will be blocked from sending out the emails, even if I do have the Override feature turned on.
I do have one other question. In the DLP setting, I see that we can either Block the email from being sent, or Encrypt the email before sending, I would like to know what the experience is for the recipient when they get the encrypted email - how would they open and view the email?
- Jan 04, 2019
Hi Suolon,
Not a problem - can understand the anxieties if you haven't done if before. They should not be blocked from sending out the emails unless you choose to block them.
You can find out more about the encryption here
https://docs.microsoft.com/en-us/office365/securitycompliance/email-encryption
And the recipient experience here
https://www.peters.com/office-365-message-encryption-ome/
Encryption is designed for automated encryption of sensitive data; for example school or patient PII data. Most organisation's I have worked with tend to block as they don't want this information going out over email and prefer a different sharing forum such as Microsoft Teams (I.e. guest access)
Best, Chris- Suolon HuJan 10, 2019Copper ContributorHi.
So I've turned on DLP policies, but now since of the users emails are being blocked without Outlook allowing them to override it when their email contains an attachment that would trigger the DLP policy. How can use be able to override it off their email contains file attachments??- Jan 10, 2019
Hi Suolon Hu
Please see here about DLP Policies and attachments
I would recommend that if the attachment is triggering the policy then it contains sensitive data which you would not likely want to transmit over email. If it is like an excel, word, pdf file then I would recommend the user sharing them with the recipient from OneDrive, over Microsoft Teams etc.
Best, Chris