Forum Discussion
neilcarden
Apr 28, 2020Brass Contributor
Acting on policy alert - Data Exfiltration
Hi we have recently enabled CAS and we have had a "Data Exfiltration to unsanctioned app" alert. One of our users has uploaded a substantial amount of data to Facebook. How do we look into this to ...
neilcarden
Apr 28, 2020Brass Contributor
rajatm Thanks for your reply.
I am assuming there is no way we can correlate the alert with any Defender ATP info and find out what was uploaded, or at least whether it was corporate data?
rajatm
Apr 28, 2020Former Employee
I do not think that's possible but my knowledge of MDATP is limited. Apologies.