Deleted and Unmached files

Copper Contributor

Hello community,

 

We are working with MCAS DLP Feature and want to know if there is any way to identify the alerts with deleted files or where files dont match the policy anymore ? For example, I would like to know for a set of alerts if the user has deleted the file or changed the content.. Thanks in advance.

 

Regards,

Elmo

2 Replies
Hi, I would check the Graph API for MCAS: https://docs.microsoft.com/en-us/cloud-app-security/api-introduction.

Maybe you find something there.

BR

@AElmo15 Yes you can create a custom policy in MCAS for user deleting multiple files within a certain time period. In the policy, the activity type should be selected as 'FileDeleted'.