Data Loss Prevention with Office365 Exchange Online
One of the new features that Office365 Exchange Online Plan 2 brings us is the Data Loss Prevention (DLP) feature. This helps us keep our organizations important information like credit cards numbers, social security ids, banking accounts, etc out of any leaks, either they´re going out intentionally or even accidentally.
DLP is done with the help of Exchange Online Transport Rules, with the use of conditions and actions based on policies we configure through the Office365 portal and be able to classify both incoming and outgoing messages. In order to help us, DLP includes a list of predefined templates we can use fast and easy to configure DLP succesfully
So let´s stop talking and get hands on configuring this great feature:
- First of all, access our Office365 Portal with our Admin credentials.
- Click on the upper right side where it says «Admin» and then click on «Exchange«.
- On the left side where it says «Compliance Management» and then on the upper side «Data Loss Prevention«.
- Click on the «+» symbol to add a new policy and select any of the three available options: New DLP Policy from template, Import DLP Policy, or New custom Policy. In our case we´ll select the first option.
- Give it a name, a description and select a predefined template from the list (i.e. U.K. Financial Data).
- Click on «More options» and select the Enforce option. Then click on Save.
- You should be able to see the recently created policy. Click on the Little pencil icon in order to edit.
- Here we can create and customize with rules the policy to treat the data and take actions like forwarding the message for the sending approval to the person on charge of the Data Treatment.
It´s very important to highlight that the Policy tips appeared when a user accomplishes a DLP policy when writing a new E-mail, will only appear if the message is being written using Microsoft Outlook 2013, because OWA and the lower versions of Microsoft Outlook are not compatible with Policy Tips as they cannot proccess them. But this doesn´t mean that DLP cannot be implemmented nor even work, DLP policys will still be working on the background thanks to the transport rules.
The advantage of Policy tips that Outlook 2013 uses, is that enables the user to specify the designated moderator a motive why he needs to send that Info to the recipient as shown on the following image:
I hope you find this usefull.