Mar 22 2018 05:15 AM
I have a DLP policy to catch financial info from being emailed out by my users.
However we received an alert for an inbound email which had a routing number and account number for an invoice. The email was bounced back to the sender - and to me the security admin.
Is there a way to prevent DLP triggering inbound? The policy was setup in Security and Compliance Center not Exchange Admin.
Mar 22 2018 11:36 AM
DLP does not trigger inbound, and there are no such options to configure. If you previously had DLP rules configured in the Exchange Admin Center, it's possible that some of the corresponding Transport rules are misconfigured to fire on both outgoing/incoming messages, so check for that.
@Tony Redmond might have some additional insights here.
Mar 22 2018 11:51 AM
1. Do you have transport rules configured with DLP?
2. The SCC (Office 365) DLP rules are expanding their coverage of email operations, so it is possible that they might have caught this too.
Impossible to say what happened without looking at the rules. Can you share the logic?
Mar 22 2018 12:07 PM
I'm almost 100% sure that's not caused by the Unified DLP - I just did a test to confirm. Outbound was captured, inbound arrived with no detections.
Mar 26 2018 08:33 AM
Hmm, i'll take a look at at the Exchange admin - but I dont believe I have ever configured anything there - it was all done from Sec & Comp center.
Mar 26 2018 09:32 AM
Mar 26 2018 09:51 AM
OK so its not just me - sounds like you have the same thing.
Is that behavior you want?
Mar 26 2018 10:14 AM
If you can reliably reproduce it, open a support case. It does not work for me via SCC rules.
Mar 26 2018 10:27 AM
Apr 03 2018 10:15 AM
The rules were created in the SCC - nothing has ever been done in Exchange.
The weird thing is that I have checked and there are other emails that were received to the accounts payable address which also contained information which should have triggered the same rule but did not. It appears to have been from 2 email senders that the issue occurred.
Is there a way to prevent DLP from inbound external email?
Sep 14 2021 02:08 PM
Sep 24 2021 04:01 PM