{"id":236,"date":"2013-10-28T08:00:00","date_gmt":"2013-10-28T00:00:00","guid":{"rendered":"http:\/\/vm-officeblogs.cloudapp.net\/2013\/10\/28\/office-365-compliance-controls-data-loss-prevention\/"},"modified":"2022-07-22T06:41:29","modified_gmt":"2022-07-22T13:41:29","slug":"office-365-compliance-controls-data-loss-prevention","status":"publish","type":"post","link":"https:\/\/www.microsoft.com\/en-us\/microsoft-365\/blog\/2013\/10\/28\/office-365-compliance-controls-data-loss-prevention\/","title":{"rendered":"Office 365 compliance controls: Data Loss Prevention"},"content":{"rendered":"

Shobhit Sahay is a product marketing manager on the Exchange team.<\/i><\/p>\n

When was the last time you asked your employees to carry your company’s handbook containing all the company policies with them? Do your IT workers know whether a particular email message they’re sending may violate company policy and run the risk of being noncompliant? Are they sure whether an email they’re sending contains sensitive information? Almost every IT worker faces compliance questions like these daily. Learn how you can help your IT workers achieve compliance without disrupting their normal routine or yours.<\/p>\n

A recent blog post<\/a> laid out the two dimensions of Office 365 security, compliance, and privacy: built-in capabilities and customer controls. This post focuses on a key feature under customer controls in compliance: data loss prevention (DLP).<\/p>\n

DLP Policy Tips inform your workers in real time<\/b><\/p>\n

With the new DLP Policy Tips in Office 365, admins can inform email senders that they may be about to pass along sensitive information that is detected by the company’s policies-before they click Send. This helps your organization stay compliant and it educates your employees about custom scenarios based on your organization’s requirements. It accomplishes this by emphasizing in-context policy evaluation. Policy Tips not only analyzes email messages for sensitive content but also determines whether information is sensitive in the context of communication. That means you can target specific scenarios that you associate with risk, external communication for example, and configure custom policy tips for those scenarios. Reading those custom policy tips in email messages keeps your workers aware of your organization’s compliance policies and empowers them to act on them, without interrupting their work.<\/p>\n

DLP Policy Tips is supported only in Outlook 2013, but even if your users don’t have the latest version of Outlook, you are still protected from disclosing sensitive data through back-end processing. Admins can configure rules and take actions by setting up DLP rules in the Exchange Administration Center (EAC). This ensures that a single DLP policy controls both the client and server endpoints, minimizing the admin administrative overhead.<\/p>\n

How do Policy Tips work? Consider a real-life scenario. Contossoplay is a company that has an internal policy to warn its employees any time they include sensitive information like a credit card number in email communications. Sara Davis is a Contossoplay employee composing an email to Dan, who works\u00a0outside her organization. She includes credit card information in the mail, and immediately a DLP policy tip shows up in the message in Outlook.<\/p>\n

<\/p>\n

When you include sensitive information in an email message, a DLP policy tip alerts you before you send the message.<\/i><\/p>\n

At this point Sarah can decide to: send the email message with the credit card information, send the message with the credit card information and click Report<\/b> to report a false positive, or delete the credit card information before sending the message. If she’s unsure what to do, she can click Learn more<\/b> to understand her company’s policy, which her admin may have customized.<\/p>\n

Let’s \u00a0look at another scenario. Contossoplay has recently set up a policy that blocks emails containing multiple credit cards or that need to be overridden with a business justification. Sara starts an email message to book the travel for multiple employees in the company and attaches a document that includes the personal credit card information of the employees. A different policy tip shows up, highlighting the new compliance requirement. In Outlook 2013, the attachment that is the cause of concern is also highlighted, making it easy for her to locate the information being questioned.<\/p>\n

<\/p>\n

A custom DLP policy tip<\/i> alerts you about an attachment that may contain high-count sensitive information<\/em>.<\/p>\n

As these two scenarios show, data loss prevention empowers end users, making them part of the organization’s compliance process and ensuring that the business flow is not interrupted or delayed, because achieving compliance does not get in users’ way. At the same time, data loss prevention simplifies compliance management for admins, because it enables them to maintain control easily through the Exchange Administration Center in the Office 365 admin portal.<\/p>\n

Policy Tips are similar to MailTips, and you can configure them to present a brief note in Outlook 2013 that provides information about your business policies to the person creating a message. You can configure policy tips that will merely warn workers, block their messages, or even allow them to override your block with a justification. Policy tips can also be useful for fine-tuning your DLP policy effectiveness, because they allow end users to easily report false positives. If policy tips are not available to a user in Outlook, admins can still control compliance behavior by setting up rules in the Exchange Administration Center. For example, admins can set up an action to generate incident reports if a particular DLP event occurs. Such incident reports can help tracks events in real time, because a report is generated in real time and sent to a designated mailbox, such as the mailbox for incident manager account. The figure below shows a sample incident report.<\/p>\n

<\/p>\n

You can generate incident reports for specific DLP events in Office 365.<\/i><\/p>\n

<\/b><\/p>\n

What does data loss prevention in Office 365 offer?<\/b><\/p>\n

Data loss prevention in in Office 365 helps you identify, monitor, and protect sensitive information in your organization through deep content analysis. DLP is increasingly important for enterprise message systems, because business-critical email often includes sensitive data that needs to be protected. Worrying about whether financial information, personally identifiable information (PII), or intellectual property data might be accidently sent to unauthorized users can keep a Chief Security Officer (CSO) up all night. Now you can protect sensitive data more easily than ever before, without affecting worker productivity. Admins can easily set up compliance management in email using the Exchange Administration Center (EAC) in the Office 365 admin portal. In the EAC, you can:<\/p>\n