Forum Discussion

Ashish Trivedi's avatar
Ashish Trivedi
Brass Contributor
Jun 19, 2019

Block upload of files to public locations likes gmail, dropbox etc using Microsoft Cloud App Securit

I have created AIP labels. I have applied them via Microsoft Cloud App Security File policy based on DLP rules. Working fine now.

The objective is to stop those file upload to personal storage/email like gmail or dropbox. I looked upon the MCAS session policy which has session control type of control file upload (with DLP). I created one leaving App filter empty, added file filter to match classification labels with inspection method. Now it blocks file upload even to SharePoint Online.

The conditional rule is on SPO and ExO with session control using custom policy for conditional access app control.

How do I just block files to move out of environment rather blocking upload to SPO or other locations?

6 Replies

  • Didi00's avatar
    Didi00
    Copper Contributor

    That is still indeed an unresolved point Ashish Trivedi

    Does anyone have any idea when it will be covered by MDCA? Or will it ever be?

    This is quite a basic capability, what is the point of knowing upload/download traffic if we can not block those actions separately? 

  • Ivan1010's avatar
    Ivan1010
    Copper Contributor
    Hi its 2023 and we are still looking for a solution here. Any leads please?
  • PoojaN's avatar
    PoojaN
    Copper Contributor

    Ashish Trivedi : Can you please explain steps how to block users uploading files (any labels) from sharepoint/any drive to personal drive eg G-dirve/dropbos/ gmail?

    Thank you

    • sanjay_senapati95's avatar
      sanjay_senapati95
      Copper Contributor

      Ashish Trivedi In defender Could you help steps how to block users uploading files (any labels) from sharepoint/any drive to personal drive eg G-dirve/dropbos/ gmail? 

  • Ashish Trivedi Hello, may I ask how you ended up configuring your products to meet your needs? Did you use ATP/MIP as suggested? Thanks in advance.

     

    *edit* For information we have disabled all 'third-party storage providers' just about everywhere. I'm curious though as I would like to manage the data and not necessarily disable all features.

Resources