SOLVED

Office 365 DLP on Premise and Cloud same time...

%3CLINGO-SUB%20id%3D%22lingo-sub-159652%22%20slang%3D%22en-US%22%3EOffice%20365%20DLP%20on%20Premise%20and%20Cloud%20same%20time...%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-159652%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20All%2C%3C%2FP%3E%0A%3CP%3EIs%20it%20possible%20for%20those%20who%20have%20on%20Premise%20SharePoint%20and%20Exchange%20and%20are%20looking%20at%20going%20to%20the%20Microsoft%20cloud%20to%20apply%20DLP%20to%20both%3F%20We%20do%20not%20want%20the%20Business%20and%20Security%20to%20have%20multiple%20tools%20for%20DLP%20with%20multiple%20interfaces.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EAlso%20I%20see%20nothing%20about%20Office%20365%20DLP%20that%20indicates%20it%20can%26nbsp%3BAudit%20SQL%20Server%20for%20Sensitive%20data.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EThanks%2C%3C%2FP%3E%0A%3CP%3E-Tony%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-162131%22%20slang%3D%22en-US%22%3ERe%3A%20Office%20365%20DLP%20on%20Premise%20and%20Cloud%20same%20time...%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-162131%22%20slang%3D%22en-US%22%3E%3CP%3EDLP%20policies%20are%20matched%20by%20examining%20the%20cloud%20search%20index.%20So%20if%20you%20can%20get%20something%20into%20the%20search%20index%20then%20potentially%20it%20can%20be%20examined%20for%20DLP.%20To%20get%20on%20premise%20SharePoint%20content%20into%20the%20cloud%20search%20index%20you%20need%20to%20set%20up%20cloudSSA%20hybrid%20search%20which%20can%20be%20done%20relatively%20easily%20if%20you're%20SP2013%20or%20SP2016%20on%20premise%20(not%20Exchange%20on%20premise).%20eDiscovery%20and%20content%20search%20in%20Security%20%26amp%3B%20Compliance%20centre%20definitely%20picks%20up%20this%20on%20prem%20content%20so%20don't%20see%20why%20DLP%20policies%20would%20not%20too.%20This%20would%20then%20give%20you%20one%20portal%20at%20least%20for%20all%20the%20SharePoint%20content.%20See%20attached%20image%20for%20a%20conceptual%20view%20of%20he%20crawl%20process.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-161638%22%20slang%3D%22en-US%22%3ERe%3A%20Office%20365%20DLP%20on%20Premise%20and%20Cloud%20same%20time...%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-161638%22%20slang%3D%22en-US%22%3E%3CP%3EThere%20is%20no%20such%20thing%20as%20%22Office%20365%20on-premises%22.%20Are%20you%20perhaps%20referring%20to%20the%20desktop%20Office%20applications%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-161469%22%20slang%3D%22en-US%22%3ERe%3A%20Office%20365%20DLP%20on%20Premise%20and%20Cloud%20same%20time...%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-161469%22%20slang%3D%22en-US%22%3E%3CP%3EHi%2C%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EThanks%20for%20the%20quick%20reply.%20So%20are%20you%20saying%20the%20online%20Office%20365%20is%20very%20different%20from%20the%20Office%20365%20on%20premise%3F%3C%2FP%3E%0A%3CP%3EAlso%2C%20what%20connects%20to%20SharePoint%20and%20Exchange%20to%20do%20the%20audit%20and%20protection%3F%20Is%20that%20Office%20365%20client%20or%20is%20that%20something%20else%3F%20I%20am%20trying%20to%20understand%20all%20the%20components%20for%20DLP%20from%20Microsoft%20that%20would%20need%20upgrading%20on%20site%26nbsp%3Bto%20support%20your%20DLP%20capabilities.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EThanks%2C%3C%2FP%3E%0A%3CP%3E-Tony%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-160606%22%20slang%3D%22en-US%22%3ERe%3A%20Office%20365%20DLP%20on%20Premise%20and%20Cloud%20same%20time...%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-160606%22%20slang%3D%22en-US%22%3E%3CP%3EIn%20a%20single%20word%26nbsp%3B-%20No.%20The%20DLP%20controls%20Office%20365%20offers%20are%20way%20ahead%20of%20the%20on-premises%20ones%2C%20so%20even%20if%20there%20was%20a%20single%20policy%20that%20spans%20cloud%20and%20on-premises%20resources%2C%20it%20would%20be%20limited%20in%20some%20features.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EAnd%20no%20on%20the%20SQL%20question%2C%20none%20of%20the%20Microsoft%20offerings%20covers%20DLP%20for%20that%20scenario.%3C%2FP%3E%3C%2FLINGO-BODY%3E
New Contributor

Hi All,

Is it possible for those who have on Premise SharePoint and Exchange and are looking at going to the Microsoft cloud to apply DLP to both? We do not want the Business and Security to have multiple tools for DLP with multiple interfaces.

 

Also I see nothing about Office 365 DLP that indicates it can Audit SQL Server for Sensitive data.

 

Thanks,

-Tony

4 Replies
best response confirmed by Deleted
Solution

In a single word - No. The DLP controls Office 365 offers are way ahead of the on-premises ones, so even if there was a single policy that spans cloud and on-premises resources, it would be limited in some features.

 

And no on the SQL question, none of the Microsoft offerings covers DLP for that scenario.

Hi,

 

Thanks for the quick reply. So are you saying the online Office 365 is very different from the Office 365 on premise?

Also, what connects to SharePoint and Exchange to do the audit and protection? Is that Office 365 client or is that something else? I am trying to understand all the components for DLP from Microsoft that would need upgrading on site to support your DLP capabilities.

 

Thanks,

-Tony

 

There is no such thing as "Office 365 on-premises". Are you perhaps referring to the desktop Office applications?

DLP policies are matched by examining the cloud search index. So if you can get something into the search index then potentially it can be examined for DLP. To get on premise SharePoint content into the cloud search index you need to set up cloudSSA hybrid search which can be done relatively easily if you're SP2013 or SP2016 on premise (not Exchange on premise). eDiscovery and content search in Security & Compliance centre definitely picks up this on prem content so don't see why DLP policies would not too. This would then give you one portal at least for all the SharePoint content. See attached image for a conceptual view of he crawl process.