Securing laptop/desktop Office 365 data from being sent 'off-network' via third party methods?

%3CLINGO-SUB%20id%3D%22lingo-sub-1093285%22%20slang%3D%22en-US%22%3ESecuring%20laptop%2Fdesktop%20Office%20365%20data%20from%20being%20sent%20'off-network'%20via%20third%20party%20methods%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1093285%22%20slang%3D%22en-US%22%3E%3CP%3EWhat%20are%20the%20best%20recommendations%20for%20preventing%20my%20users%20from%20sending%20Office%20365%20documents%20outside%20my%20network%2C%20via%20any%20third%20party%20methods%20(i.e.%20Gmail%2C%20etc%2C.)%3F%3CBR%20%2F%3E%3CBR%20%2F%3E%3C%2FP%3E%3CP%3EMy%20users%20are%20using%20Office%20365%20Business%20Premium%2C%20with%20Office%20Professional%20Plus%202019%20as%20their%20desktop%20productivity%20suite.%3CBR%20%2F%3E%3CBR%20%2F%3E%3C%2FP%3E%3CP%3EI'd%20also%20like%20to%20be%20able%20to%20lock%20down%20their%20mobile%20devices%20(iPhones%20and%20Android)%20to%20either%20prevent%20or%20at%20least%20be%20able%20to%20monitor%20if%20they%20are%20forwarding%20Office%20365%20data%20off-network%20using%20non-Office%20365%20apps.%3C%2FP%3E%3CP%3ESuggestions%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1093285%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3ECompliance%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EOffice%20365%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3ESecurity%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1093858%22%20slang%3D%22en-US%22%3ERe%3A%20Securing%20laptop%2Fdesktop%20Office%20365%20data%20from%20being%20sent%20'off-network'%20via%20third%20party%20methods%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1093858%22%20slang%3D%22en-US%22%3E%3CP%3EThere's%20no%20full%20solution%20to%20this%2C%20sure%20you%20can%20add%20some%20restrictions%20like%20the%20ones%20available%20in%20MCAS%2C%20but%20people%20can%20still%20find%20ways%20around%20it.%20If%20your%20documents%20are%20that%20sensitive%2C%20consider%20encrypting%20them%20via%20RMS%2FAIP%20so%20that%20they%20can%20only%20be%20opened%20by%20designated%20recipients%2C%20even%20if%20shared%20externally.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1093871%22%20slang%3D%22en-US%22%3ERe%3A%20Securing%20laptop%2Fdesktop%20Office%20365%20data%20from%20being%20sent%20'off-network'%20via%20third%20party%20methods%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1093871%22%20slang%3D%22en-US%22%3E%3CP%3EHello%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F86092%22%20target%3D%22_blank%22%3E%40Robert%20Gordon%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThere%20are%20a%20lot%20of%20ways%20to%20prevent%20%2F%20restrict%20document%20and%20data%20sharing%20from%20the%20Office365%20Workloads.%26nbsp%3B%3C%2FP%3E%3CP%3EDepending%20on%20what%20licenses%20you%20have%20then%20you%20might%20have%20access%20to%20different%20tools.%26nbsp%3B%3C%2FP%3E%3CP%3ESome%20Tools%20that%20I%20always%20recommend%20to%20use%20are%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CUL%3E%3CLI%3EDLP%20(%20Data%20Loss%20Prevention%20)%20-%20This%20can%20prevent%20users%20from%20sharing%20PIP%2FGDPR%20related%20data%3C%2FLI%3E%3CLI%3ELabels%2FTags%20-%20Labels%20together%20with%20a%20label%20policy%20can%20automatically%20or%20manually%20add%20labels%20to%20documents%2C%20emails%20and%20other%20data.%20These%20Labels%20have%20different%20levels%20of%20sensitivity%20(%20Public%2C%20Confidential%2C%20Very%20Condidential%20)%20These%20labels%20prevent%20users%20from%20for%20exampel%20forwarding%2C%20printing%20or%20copy%26amp%3BPaste%20data%20from%20emails%20that%20have%20the%20label%2Ftag%20applied%20to%20it%26nbsp%3B%3CBR%20%2F%3E%3CBR%20%2F%3E%3C%2FLI%3E%3CLI%3ESharing%20Policy%20in%20OneDrive%20and%20SharePoint%20-%20Restricting%20your%20users%20to%20only%20share%20data%20from%20OneDrive%20and%20SharePoint%20with%20external%20users%20is%20also%20a%20good%20thing%20to%20do.%26nbsp%3B%3CBR%20%2F%3EYou%20can%20allow%20users%20to%20only%20share%20documents%20with%20external%20users%20that%20are%20already%20in%20your%20Azure%20AD%20(%20AKA%20%2C%20Guest%20users%20in%20your%20Azure%20AD%20)%26nbsp%3B%3CBR%20%2F%3E%3CBR%20%2F%3E%3C%2FLI%3E%3CLI%3EMDM%20(%20Intune%20)%20-%20Set%20up%20security%20and%20compliance%20policies%20in%20Intune%20to%20lock%20down%20how%20your%20mobile%20devices%20are%20accessing%20company%20data%20etc.%26nbsp%3B%3CBR%20%2F%3E%3CBR%20%2F%3E%3C%2FLI%3E%3CLI%3EConditinal%20Access%20Policy%20-%20This%20is%20a%20very%20great%20tool%20in%20Azure%20AD%2C%20Conditional%20Access%20is%20policies%20that%20you%20set%20up%20to%20control%20what%20and%20who%20can%20access%20information%20and%20data%20in%20Office365%20and%20Azure.%26nbsp%3B%3CBR%20%2F%3EYou%20can%20for%20example%20set%20up%20a%20policy%20that%20says%20%22only%20allow%20access%20to%20a%20certain%20SharePoint%20site%20if%20your're%20on%20the%20internal%20network%20or%20on%20a%20Azure%20AD%20joined%20device%22%26nbsp%3B%3C%2FLI%3E%3C%2FUL%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAbove%20I've%20just%20given%20you%20a%20quick%20overlook%20on%20what%20posibilities%20you%20have%20and%20what%20tools%20I%20suggest.%26nbsp%3B%3C%2FP%3E%3CP%3ERead%20up%20on%20them%2C%20mostly%20DLP%20%2C%20MDM%2FIntune%20and%20Conditional%20Access%20in%20your%20scenario.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ELet%20me%20know%20if%20you%20want%20some%20clarification%20in%20any%20of%20the%20mentioned%20tools%20%3A)%3C%2Fimg%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIf%20you%20are%20satisfied%2C%20please%20feel%20free%20to%20mark%20my%20reply%20as%20%22%20Best%20solution%22%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EKind%20RegardsOliwer%20Sj%C3%B6berg%3C%2FP%3E%3C%2FLINGO-BODY%3E
Highlighted
Frequent Contributor

What are the best recommendations for preventing my users from sending Office 365 documents outside my network, via any third party methods (i.e. Gmail, etc,.)?

My users are using Office 365 Business Premium, with Office Professional Plus 2019 as their desktop productivity suite.

I'd also like to be able to lock down their mobile devices (iPhones and Android) to either prevent or at least be able to monitor if they are forwarding Office 365 data off-network using non-Office 365 apps.

Suggestions?

2 Replies
Highlighted

There's no full solution to this, sure you can add some restrictions like the ones available in MCAS, but people can still find ways around it. If your documents are that sensitive, consider encrypting them via RMS/AIP so that they can only be opened by designated recipients, even if shared externally.

Highlighted

Hello@OneTechBeyond 

There are a lot of ways to prevent / restrict document and data sharing from the Office365 Workloads. 

Depending on what licenses you have then you might have access to different tools. 

Some Tools that I always recommend to use are 

 

  • DLP ( Data Loss Prevention ) - This can prevent users from sharing PIP/GDPR related data
  • Labels/Tags - Labels together with a label policy can automatically or manually add labels to documents, emails and other data. These Labels have different levels of sensitivity ( Public, Confidential, Very Condidential ) These labels prevent users from for exampel forwarding, printing or copy&Paste data from emails that have the label/tag applied to it 

  • Sharing Policy in OneDrive and SharePoint - Restricting your users to only share data from OneDrive and SharePoint with external users is also a good thing to do. 
    You can allow users to only share documents with external users that are already in your Azure AD ( AKA , Guest users in your Azure AD ) 

  • MDM ( Intune ) - Set up security and compliance policies in Intune to lock down how your mobile devices are accessing company data etc. 

  • Conditinal Access Policy - This is a very great tool in Azure AD, Conditional Access is policies that you set up to control what and who can access information and data in Office365 and Azure. 
    You can for example set up a policy that says "only allow access to a certain SharePoint site if your're on the internal network or on a Azure AD joined device" 

 

Above I've just given you a quick overlook on what posibilities you have and what tools I suggest. 

Read up on them, mostly DLP , MDM/Intune and Conditional Access in your scenario. 

 

Let me know if you want some clarification in any of the mentioned tools :) 

If you are satisfied, please feel free to mark my reply as " Best solution" 

 

Kind Regards
Oliwer Sjöberg