{"id":123370,"date":"2022-10-18T09:00:00","date_gmt":"2022-10-18T16:00:00","guid":{"rendered":"https:\/\/www.microsoft.com\/en-us\/security\/blog\/?p=123370"},"modified":"2023-09-18T08:56:11","modified_gmt":"2023-09-18T15:56:11","slug":"how-microsoft-purview-and-priva-help-simplify-data-protection","status":"publish","type":"post","link":"https:\/\/www.microsoft.com\/en-us\/security\/blog\/2022\/10\/18\/how-microsoft-purview-and-priva-help-simplify-data-protection\/","title":{"rendered":"How Microsoft Purview and Priva help simplify data protection"},"content":{"rendered":"\n
At Microsoft Security, we understand how challenging it is to protect your most important asset, your data, in today\u2019s threat landscape. You\u2019re faced with evolving challenges\u2014from empowering employees for greater productivity to eliminating gaps in your infrastructure\u2014all while trying to protect your data across a hybrid work environment. And in the current economic climate, getting maximum value from your existing security investments is paramount. That\u2019s why, in the past year, we\u2019ve further enhanced our data protection and data governance products to better fit your needs. The results include two integrated and powerful solutions: Microsoft Purview<\/a> and Microsoft Priva<\/a>.<\/p>\n\n\n\n At this year\u2019s Microsoft Ignite<\/a> event, I co-hosted a special presentation on how your security and compliance teams can better manage risk, govern your data (wherever it resides), and maintain compliance. We also shared new product updates and insights to help your team get the most from your Microsoft security investments, as well as announced an exciting new capability that integrates Microsoft Purview natively within Adobe Acrobat. This type of extensible, multicloud, and multiplatform protection allows you to get more from the tools you already have. In this blog post, we\u2019ll look at some of those scenarios where Microsoft Purview and Priva can help simplify data governance across your enterprise today.<\/p>\n\n\n\n Microsoft Purview\u2019s mission is to help customers protect their entire data estate: that includes non-Microsoft environments as well. At this year\u2019s Ignite presentation, we demonstrated a new capability that integrates Microsoft Purview Information Protection<\/a> natively within the desktop version of Adobe Acrobat<\/a>\u2014accessible directly from the Protect tool. That means users now have the ability to apply and edit information-protection labels and policies directly to PDF documents<\/strong>. This integration brings the same classification, labeling, and protection already available in Microsoft Office<\/a> file formats to PDF.<\/p>\n\n\n\n Over the next few months, we\u2019ll continue to add new features that enhance support for PDFs in Acrobat add-ins, as well as for Acrobat Export PDF and mobile versions.<\/p>\n\n\n\n Data is the lifeblood of your organization. It provides crucial insights that give your business a competitive advantage and empowers your employees to do more. For that reason, it\u2019s critical to protect your data at every stage\u2014from creation to storage\u2014both from external threats and internal risks. That requires creating a layered defense strategy.<\/p>\n\n\n\n The first layer of defense: Discover and understand the sensitive data within your organization. <\/strong>You need to know where your data is, who\u2019s accessing it, how it\u2019s being shared and stored, and where it\u2019s traveling. Considering that data storage is forecast to increase at a compound annual growth rate of 19.2 percent from 2020 to 2025, gaining complete visibility over your data estate is crucial.1<\/sup> At this first line of defense, Microsoft Purview Information Protection<\/strong> helps you classify and label your data across your entire data estate, both on-premises and in multicloud environments. By providing a single pane of glass to track and manage your data, Microsoft Purview helps to improve your team\u2019s efficiency while tightening data protection.<\/p>\n\n\n\n Recent updates<\/em><\/strong> for Microsoft Purview Information Protection:<\/a><\/em><\/p>\n\n\n\n Data breaches arising from insider actions<\/a> are estimated to cost businesses an average of USD7.5 million annually. For that reason, it’s important to understand all data access and usage patterns within your organization. What does normal activity look like? Which types of activity should be flagged as risky? Understanding internal data usage can help protect against compliance violations and worse, including IP theft, insider trading, confidentiality violations, and other damaging outcomes.<\/p>\n\n\n\n The second layer of defense: Manage data security risks within your organization. <\/strong>Working in tandem with a holistic approach to managing internal risk, Microsoft Purview Insider Risk Management<\/a> identifies potential risks and enables security teams to quickly take action. By bringing together the right people, processes, training, and tools, organizations that approach insider risk holistically are more likely to emphasize user privacy, foster collaboration, and use positive deterrents such as training and feedback loops as part of their data-protection strategy. The one-click analytics report<\/strong> allows you to generate aggregated, de-identified insights on risky activity over the past 48 hours\u2014before you’ve even set up your first policy. Insights include the percentage of users who have performed exfiltration activities, such as downloading sensitive data, with an additional breakdown by activity type. To learn more about potential risks within your own organization, view the new Microsoft insider risk report.<\/a><\/p>\n\n\n\n All names in insider<\/strong> risk<\/strong> alerts are pseudonymized by default<\/strong>. This helps your data security team take a privacy-first approach. By clicking on a specific alert, you\u2019ll be able to see a summary of all of the risk factors. Sequencing allows you to correlate across activities that involve the same files. This correlation can help your security team understand the possible intent behind the activities so you can reduce time to action. For example, you might see that just before a user submitted their resignation, they downloaded and exfiltrated confidential files, then deleted the files from their device to cover their tracks. Understanding this sequence of activities helps your security team decide when and how to take action.<\/p>\n\n\n\n Using sequences as triggers<\/strong> for your policies<\/strong> improves the signal quality of your alerts and focuses policy detection on users who have performed multiple-stage sequences. Priority Content Only Scoring<\/strong>, configurable in the policy wizard, empowers your team to focus policy detection on the most sensitive content. All of these insights help you better understand potential risks, so you can set up policies that meet the unique needs of your organization. With this information, analysts in your organization can take appropriate actions to help make sure users remain in compliance.<\/p>\n\n\n\n Recent updates<\/em><\/strong> for Microsoft Purview Insider Risk Management<\/a>:<\/em><\/p>\n\n\n\n The third layer of defense: Incorporate an integrated, in-depth approach to prevent data loss or unauthorized use.<\/strong> Among business leaders who responded to a 2021 survey, 62 percent felt that their companies should do more to protect customer data.2<\/sup> Microsoft Purview Data Loss Prevention<\/a> (DLP) provides a balance between protection and productivity, ensuring the proper access controls are in place and policies are set to prevent actions such as improperly saving, storing, or printing sensitive data. <\/p>\n\n\n\n Recent updates<\/em><\/strong> for Microsoft Purview Data Loss Prevention<\/a>:<\/em><\/p>\n\n\n\n These three components\u2014Information Protection, Insider Risk Management, and Data Loss Prevention\u2014form an integrated, holistic data-protection strategy that helps keep your organization\u2019s data safe, wherever it lives.<\/p>\n\n\n\n As more countries enact modern General Data Protection Regulation<\/a> (GDPR) type regulations, consumers are demanding better controls over their data. This has spurred more organizations to move from a compliance-driven approach to privacy toward a more human-centric one. Toward that goal, Microsoft Priva<\/strong> currently offers two products to help manage privacy:<\/p>\n\n\n\n Privacy Risk Management<\/a> helps organizations identify personal data and critical privacy risks and empowers employees to make smart data-handling decisions. With Priva, admins can configure a<\/strong> data minimization policy<\/strong>\u2014automatically triggering an email to the data owner\u2014so the person can review and delete unused files right from their Outlook inbox. <\/p>\n\n\n\n Subject Rights Requests<\/a> help organizations manage requests at scale and respond with confidence. With the new pre-configured templates, admins can quickly create a data export request for a former employee. Once the data is collected, Priva can automatically detect files containing co-mingled personal data or confidential information; then admins can review and redact the data to avoid leakage. With the latest update, admins can now import files outside of Microsoft 365 to leverage this powerful review experience. Learn more about these new updates in this Priva Tech Community post<\/a>.<\/p>\n\n\n\n We\u2019re also adding new features and capabilities within other product areas in our Microsoft Purview portfolio. These new features and enhancements will benefit your organization through granular eDiscovery, comprehensive audit controls, more effective data lifecycle management, and easier compliance.<\/p>\n\n\n\n Microsoft Purview Data Lifecycle Management<\/a> helps organizations manage the lifecycle of data. You can automatically retain, delete, and store data and records in a compliant manner. This solution delivers on our vision to protect and govern data wherever it lives. We have four exciting releases to tell you about:<\/p>\n\n\n\n Microsoft Purview Compliance Manager<\/a> helps organizations simplify compliance and reduce risk. It translates complex regulatory requirements into specific controls, allowing organizations to constantly assess, monitor, and improve their compliance posture\u2014all while saving time and money. So, what\u2019s new<\/a> in Compliance Manager?<\/p>\n\n\n\n I\u2019d be remiss to not talk to you about some of the exciting capabilities we have coming up. For Microsoft Purview<\/strong>, you will start to see integrations across Microsoft 365 and Microsoft Azure<\/strong> to help increase the visibility of your data and easily automate data classification. For Microsoft Priva<\/strong>, you\u2019ll soon see more multicloud privacy management capabilities<\/strong> that help you automate privacy controls and strengthen your privacy program. To learn more about potential risks within your own organization, read the new Microsoft insider risk report<\/a>. Also, be sure to read Microsoft Security Corporate Vice President of Compliance, Identity, and Management <\/strong>Vasu Jakkal\u2019s blog<\/strong><\/a> with highlights from her keynote address and insights into her vision for the Microsoft Security family of products and beyond.<\/p>\n\n\n\n Learn more about Microsoft Purview<\/a> and Microsoft Priva<\/a>.<\/p>\n\n\n\n To learn more about Microsoft Security solutions, visit our website<\/a>. Bookmark the Security blog<\/a> to keep up with our expert coverage on security matters. Also, follow us at @MSFTSecurity<\/a> for the latest news and updates on cybersecurity.<\/p>\n\n\n\nNew Adobe and Microsoft Purview integration delivers seamless security<\/h2>\n\n\n\n
Streamlining data protection<\/h2>\n\n\n\n
Lowering insider risk<\/h2>\n\n\n\n
Protecting against data loss<\/h2>\n\n\n\n
Automating privacy<\/h2>\n\n\n\n
Additional product updates<\/h2>\n\n\n\n
Enhanced eDiscovery for the cloud<\/h3>\n\n\n\n
New search experience and security controls for Microsoft Purview Audit<\/h3>\n\n\n\n
Microsoft Graph APIs and Power Automate workflows for Data Lifecycle Management<\/h3>\n\n\n\n
Enhanced compliance and data residency <\/h3>\n\n\n\n
More to come<\/h2>\n\n\n\n
Learn more<\/h2>\n\n\n\n