Senior Member

Hi there,

 

THE REQUIREMENT

Block the upload of sensitive content (defined with Sensitive Information Types - not Labels) to personal cloud storage such as a personal Dropbox account.

 

THE RESEARCH

Endpoint DLP

Based on this requirement, I have come to the conclusion that this can only be achieved through Endpoint DLP (Upload to cloud service) using the Microsoft Compliance Extension and requiring an E5 license for all users.

 

Conditional Access and Defender for Cloud Apps - Session Policy

I also considered using a Session based policy in Defender for Cloud Apps (MCAS) to block the upload of such information, but the policy only relies on Sensitivity Labels (and not Sensitive Information Types which is the requirement)

 

M365 Compliance Centre and Defender for Cloud Apps - DLP Policy

I am also aware that one can add an App Connector for Dropbox as a Cloud App, then using this in M365 Compliance Centre as a location:

 

DirkPrinsloo_1-1636868121664.png

 

But this only works for corporate Dropbox accounts and not personal.

 

I am sure I am missing something here in terms of the requirement and the capability that Microsoft provides throughout the DLP and MIP capabilities.

 

Please help?

 

Dirk

We support Ukraine and condemn war. Push Russian government to act against war. Be brave, vocal and show your support to Ukraine. Follow the latest news HERE