A Microsoft 365 administrator is implementing a new security policy that requires all sensitive documents shared externally via Microsoft SharePoint Online to be automatically labeled and encrypted. The organization uses Microsoft Information Protection (MIP) sensitivity labels. Which Microsoft Defender for Cloud Apps policy type should the administrator configure to enforce this requirement?
- AActivity policy
- BFile policy
- CCloud Discovery policy
- DAnomaly detection policy
Show answer & explanationAnswer & explanation
Correct answer: B. File policy
To enforce automatic labeling and encryption of sensitive documents shared externally, a Microsoft Defender for Cloud Apps 'File policy' is the appropriate choice. File policies scan files stored in connected cloud apps (like SharePoint Online) for sensitive content and can apply governance actions, including applying sensitivity labels and encryption, based on predefined criteria. Activity policies monitor user actions, anomaly detection policies identify unusual behavior, and Cloud Discovery policies identify shadow IT, none of which directly apply labels/encryption to files.
Why the other options are wrong
- A. Activity policies monitor user actions (e.g., 'download file', 'share externally') and can trigger alerts or block actions, but they don't directly apply sensitivity labels or encryption to the file itself.
- C. Cloud Discovery policies identify and assess unsanctioned cloud apps ('shadow IT') used in the organization, unrelated to file labeling or encryption.
- D. Anomaly detection policies identify unusual behavior patterns that deviate from the norm, not for enforcing specific content-based labeling and encryption on files.
Defender for Cloud Apps File Policies
Microsoft Defender for Cloud Apps File policies allow administrators to scan files in connected cloud apps for sensitive content and apply governance actions, including applying Microsoft Information Protection sensitivity labels and encryption.
- Scans content of files in cloud storage.
- Can detect sensitive information (e.g., PII, credit card numbers).
- Applies governance actions like labeling, encryption, deletion, quarantine.
- Integrates with Microsoft Information Protection (MIP).
Memory trick: Remember, to 'Govern' 'Files' in the 'Cloud' with 'Labels', you need a 'File Policy' to 'Protect' them.