Forum Discussion
Testing O365 DLP Policy
- Jan 04, 2019
Hi Suolon,
Not a problem - can understand the anxieties if you haven't done if before. They should not be blocked from sending out the emails unless you choose to block them.
You can find out more about the encryption here
https://docs.microsoft.com/en-us/office365/securitycompliance/email-encryption
And the recipient experience here
https://www.peters.com/office-365-message-encryption-ome/
Encryption is designed for automated encryption of sensitive data; for example school or patient PII data. Most organisation's I have worked with tend to block as they don't want this information going out over email and prefer a different sharing forum such as Microsoft Teams (I.e. guest access)
Best, Chris
Hi Chris,
Thanks again for responding to my post. I'm just checking out your two links now.
I have already created 5 DLP policies for our tenant, all which are in test mode with Policy Tips, but during the test I don't see anywhere to override and it wasn't clear in the setup if we would see the override.
I'm just worried that once I turn on the DLP, that the users will be blocked from sending out the emails, even if I do have the Override feature turned on.
I do have one other question. In the DLP setting, I see that we can either Block the email from being sent, or Encrypt the email before sending, I would like to know what the experience is for the recipient when they get the encrypted email - how would they open and view the email?
Hi Suolon,
Not a problem - can understand the anxieties if you haven't done if before. They should not be blocked from sending out the emails unless you choose to block them.
You can find out more about the encryption here
https://docs.microsoft.com/en-us/office365/securitycompliance/email-encryption
And the recipient experience here
https://www.peters.com/office-365-message-encryption-ome/
Encryption is designed for automated encryption of sensitive data; for example school or patient PII data. Most organisation's I have worked with tend to block as they don't want this information going out over email and prefer a different sharing forum such as Microsoft Teams (I.e. guest access)
Best, Chris
- Suolon HuJan 10, 2019Copper ContributorHi.
So I've turned on DLP policies, but now since of the users emails are being blocked without Outlook allowing them to override it when their email contains an attachment that would trigger the DLP policy. How can use be able to override it off their email contains file attachments??- Jan 10, 2019
Hi Suolon Hu
Please see here about DLP Policies and attachments
I would recommend that if the attachment is triggering the policy then it contains sensitive data which you would not likely want to transmit over email. If it is like an excel, word, pdf file then I would recommend the user sharing them with the recipient from OneDrive, over Microsoft Teams etc.
Best, Chris
- Suolon HuJan 14, 2019Copper Contributor
Hi Chris,
So a few things about that.
We did not enabled External Sharing on our tenant, because we don't have a policy in place for that at the moment (that's a different journey altogether).
As for the files that are triggering the DLP, it's coming from our Professional Services department who regularly correspond with clients.... Which I'm thinking the better option in this case, and given the situation of external sharing being disabled, is probably to create a separate DLP Policy rule for them that will allow them to send attachments - probably but adding an exception on the file types being sent, and/or increase the min count? The problem is, we still want to be able to track those emails with the attachments, is there anyway to do that?
Also, another issue we're having are the GoToMeetings invites are triggering the DLP as well. The only content in those emails are the phone numbers which are triggering them - ie, false positives. In these cases, again, users are not given a prompt to override them and report them as false positives.