- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
Nov 13 2021 09:37 PM - edited Nov 13 2021 09:38 PM
Hi there,
THE REQUIREMENT
Block the upload of sensitive content (defined with Sensitive Information Types - not Labels) to personal cloud storage such as a personal Dropbox account.
THE RESEARCH
Endpoint DLP
Based on this requirement, I have come to the conclusion that this can only be achieved through Endpoint DLP (Upload to cloud service) using the Microsoft Compliance Extension and requiring an E5 license for all users.
Conditional Access and Defender for Cloud Apps - Session Policy
I also considered using a Session based policy in Defender for Cloud Apps (MCAS) to block the upload of such information, but the policy only relies on Sensitivity Labels (and not Sensitive Information Types which is the requirement)
M365 Compliance Centre and Defender for Cloud Apps - DLP Policy
I am also aware that one can add an App Connector for Dropbox as a Cloud App, then using this in M365 Compliance Centre as a location:
But this only works for corporate Dropbox accounts and not personal.
I am sure I am missing something here in terms of the requirement and the capability that Microsoft provides throughout the DLP and MIP capabilities.
Please help?
Dirk
- Labels:
-
DLP
-
Dropbox
-
MCAS Policy
-
Sensitive Information
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
Nov 29 2021 09:52 AM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
Dec 03 2021 06:50 AM
SolutionCAAC session policies are limited to SSO-enabled (sanctioned) apps and they also only support browser-based access, not client apps.
With MDE integration, MDCA can block access to the SaaS app entirely, which also includes blocking uploads, but is typically not what customers with this requirement are looking for.
Cu