A Microsoft 365 administrator is implementing a new security policy that requires all highly sensitive documents stored in SharePoint Online and OneDrive for Business to be automatically encrypted and restricted from external sharing if they contain specific financial data patterns. The organization uses Microsoft Defender for Cloud Apps and Microsoft Purview Information Protection. Which type of policy in Defender for Cloud Apps should the administrator configure to enforce this requirement?
- ACloud Discovery policy
- BFile policy
- CActivity policy
- DAnomaly detection policy
Show answer & explanationAnswer & explanation
Correct answer: B. File policy
Defender for Cloud Apps file policies are designed to monitor, classify, and apply governance actions to files stored in connected cloud apps. By integrating with Microsoft Purview Information Protection, these policies can detect sensitive information (like financial data patterns), automatically apply sensitivity labels for encryption and external sharing restrictions, and enforce compliance.
Why the other options are wrong
- A. Cloud Discovery policies are used to identify and assess shadow IT applications, not for governing sensitive content within sanctioned cloud storage.
- C. Activity policies monitor user actions (e.g., login, download, share) and can trigger alerts or block actions, but not directly encrypt and restrict files based on content.
- D. Anomaly detection policies identify unusual user behavior or activities, not specifically for content inspection and governance actions on files.
Defender for Cloud Apps File Policy
A type of policy in Microsoft Defender for Cloud Apps that allows administrators to monitor, classify, and apply governance actions to files stored in connected cloud applications, often leveraging Microsoft Purview Information Protection for content inspection and labeling.
- Scans files in cloud storage for sensitive content.
- Can integrate with Microsoft Purview Information Protection.
- Applies governance actions like encryption, access control, and external sharing restrictions.
- Enforces data compliance and prevents data leakage.
Memory trick: File policies are like a smart librarian, categorizing and protecting every document based on its content.