Microsoft Purview Data Loss Prevention (DLP) helps users make the right decisions and take the right actions while using sensitive data, helping balance security and productivity. It helps your organization to move away from a disparate set of DLP tools and benefit from a unified solution that helps detect the use of sensitive data, remediates policy violations, and educates users on how best to handle sensitive data at the endpoint, on-premises, and in the cloud.
DLP is easy to turn on with protection built-in to Microsoft 365 cloud services, Office apps, Microsoft Edge (on Windows and Mac), and on endpoint devices. DLP controls can also be extended to the Chrome browser through the Microsoft Purview extension for Chrome and to various non-Microsoft cloud apps such as Dropbox, Box, Google Drive, and others through the integration with Microsoft Defender for Cloud Apps.
In the past few months, we introduced several capabilities designed to provide new ways of protecting data across a wider variety of use cases and workloads and greater visibility into how sensitive content is used, stored, and shared. These include the general availability of:
Since we launched DLP Alerts management experience in the Microsoft Purview compliance portal, customers have highlighted the need for a unified incident management dashboard for a comprehensive view into incidents across Microsoft solutions to avoid manual correlation and navigation through different portals.
Today we are excited to announce the public preview of DLP alert management experience within the Microsoft 365 Defender portal enabling a unified approach to incident management across your Microsoft Defender and Microsoft Purview compliance portals. The integration with the Microsoft 365 Defender portal is native and easy to set up. Additionally, you can import all DLP incidents into Sentinel to extend correlation, detection, and investigation across additional Microsoft and non-Microsoft data sources and extend automated orchestration flows using Sentinel’s native SOAR capabilities. This feature will be available in the coming weeks.
With this capability you will be able to:
The current DLP Alerts dashboard in the Microsoft Purview compliance portal will remain unchanged. With this capability we are enriching the incident management experience with DLP alerts within the Defender portal.
Steps to manage DLP alerts in Microsoft 365 Defender portal
Figure 1: Steps for DLP incident management in Microsoft 365 Defender portal
You can also import all incidents including DLP alerts into Microsoft Sentinel by leveraging Sentinel’s Microsoft 365 Defender connector. Enable CloudAppEvents event connector as well to pull all Office 365 audit logs into Sentinel. Learn more here.
Figure 2: DLP Alerts in Microsoft Sentinel
We are also excited to announce the general availability of controls that are designed to give you the flexibility to scope different access restrictions to sensitive files when they are accessed by different applications. This will allow you to create groups of sanctioned or unsanctioned applications and scope policies to control access of sensitive information by individual applications in the application groups. Learn more here.
We are happy to share that there is now an easier way for you to try Microsoft Purview solutions directly in the Microsoft Purview compliance portal with a free trial. By enabling the trial in the compliance portal, you can quickly start using all capabilities of Microsoft Purview, including Insider Risk Management, Records Management, Audit, eDiscovery, Communication Compliance, Information Protection, Data Loss Prevention, and Compliance Manager.
Visit your Microsoft Purview compliance portal for more details or check out the Microsoft Purview solutions trial (an active Microsoft 365 E3 subscription is required as a prerequisite).
We look forward to your feedback!
Thank you,
The Microsoft Purview Information Protection Team
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.