compliance tag
2 TopicsWe never really knew if our Azure followed CAF or Well-Architected — so we built something
For years we ran Azure environments professionally and CAF and WAF reviews were always the same story. A consultant every 12-18 months, a thick PDF, good intentions — and then nothing until the next one. The problem wasn't that we didn't care. It was that there was no lightweight way to track it continuously. Defender had some parts of CIS. WAF had the assessment tool. CAF had... a whitepaper and a spreadsheet we kept meaning to update. We couldn't answer basic questions like: are we getting better or worse? Which subscriptions are drifting? What would an auditor actually see if they looked at our CAF posture today? Eventually we got frustrated enough to build Anubion — it connects agentlessly to your Azure tenant and runs continuous checks across CIS, CAF, and WAF in one place, with findings prioritised and evidence stored over time. Happy to share more if anyone's interested. But also genuinely curious — how are other teams handling CAF and WAF tracking between formal assessments? If anyone is curious about their scores, you can sign up for at 14 day free trial. The setup is short and you only need a read-only service principal. Check out https://anubion.io/#request-accessDLP rule - Document Property is: 'ComplianceTag:\0'
Is an expression like the one below supported by the "Document Property Is" condition when setting a DLP Policy in Purview? I'm trying to set a rule that applies a DLP alert to files in SharePoint that do not have a retention label applied to them. Would using the null character regex work for this? Document Property is: 'ComplianceTag:\0' Alternatively, is it possible to set a rule when a document property does NOT contain something?1.8KViews0likes4Comments