Forum Discussion

StephaneSmithLowes's avatar
StephaneSmithLowes
Copper Contributor
Dec 18, 2019
Solved

Monitor traffic Teams to outbound Teams site

Good Day,   We are being audited by a Data Leak Prevention teams and the came up with a major leak situation regarding TEAMS.   The screnario is ... On my personnal account at home I create my se...
  • TonyRedmond's avatar
    TonyRedmond
    Dec 19, 2019

    ChrisWebbTech I don't know of any way to trace access for users from a tenant to Teams in other tenants. The general rule is that compliance data is controlled by the tenant that owns the data. Audit data is kept in the tenant where it is generated. In this case, that data includes audit records for guest users signing into Teams, access documents, and so on. I'm unaware of any audit record captured for outbound access by a tenant user to a resource in another tenant.

     

    But this is surely similar to access to other cloud applications, like someone connecting to their personal Gmail or Dropbox account. Office 365 doesn't gather that data either and no one complains. As to using Teams to transfer data out of a tenant, well, that's like people emailing confidential messages and documents to Gmail or Yahoo! mail, or cutting and pasting information from a document into a personal document. Although you could trace the transmission of email to Gmail or Yahoo! mail, you couldn't say what data is sent.

     

    DLP isn't perfect either, nor is encryption. Users can get around technology if they want to. For example, I can spell out a credit card number in letters (six four one three, etc.) and DLP won't catch that pattern. For this reason, technical blocks exist to catch the most obvious cases of data misuse, but the technology must be backed up with employee training and sanctions (where necessary).