May 24 2021 09:15 PM - edited May 24 2021 09:18 PM
Hi,
We are trying to setup a DLP Policy that does the following:
- If an email contains more than 10 credit card numbers and is being sent to an external email address, notify the DLPAdmin user, except if the source of the email is "customerservice@ourcompany.com".
@ourcompany.com is our Azure Tenant (in this example).
So, we have created a new DLP Policy, as follows:
Customized DLP Rule:
Turn the Policy on right away.
------------
IMHO the above should work...however, DLPAdmin@ourcompany.com always gets notified when the customerservice@ourcompany.com account send an email externally (and contains 10 or more credit cards). I thought the idea of the 'exceptions' was for the DLP rule to work, except when the exclusion = true.
What are we doing wrong?
Thank you,
SK
May 30 2021 12:17 AM
May 31 2021 02:36 PM
Hi @Joe Stocker,
Thank you for taking the time to respond.
I have attached the DLP Policy screenshots.
Not sure if its useful, but I am using Outlook Web Access, and not the Outlook client for this setup and testing.
Thank you,
Shim