Microsoft 365 FundamentalsDescribe Microsoft 365 pricing and supportHard
A Microsoft 365 administrator wants to implement a policy that automatically encrypts emails containing sensitive financial information sent outside the organization. Which Microsoft 365 Purview capability should the administrator configure to achieve this?
- AData Loss Prevention (DLP)
- BMicrosoft Defender for Cloud Apps
- CInformation Barriers
- DeDiscovery
Show answer & explanationAnswer & explanation
Correct answer: A. Data Loss Prevention (DLP)
Data Loss Prevention (DLP) policies in Microsoft Purview are designed to identify, monitor, and automatically protect sensitive information, such as financial data, by enforcing actions like encryption when it's shared inappropriately or externally.
Why the other options are wrong
- B. Microsoft Defender for Cloud Apps is a Cloud Access Security Broker (CASB) that monitors and controls cloud app usage, but it's not the primary tool for automatically encrypting emails based on content.
- C. Information Barriers are used to prevent communication between specific groups of users within an organization, not to encrypt external emails.
- D. eDiscovery is used for searching and collecting electronic data for legal purposes, not for active content-based encryption policies.
Microsoft Purview Data Loss Prevention (DLP)
A set of capabilities within Microsoft Purview that identifies, monitors, and protects sensitive information across Microsoft 365 services and endpoints, preventing its accidental or intentional sharing outside the organization.
- Detects sensitive information types (e.g., credit card numbers, PII).
- Applies policies to emails, documents, and other content.
- Can block, warn, or encrypt content based on policy rules.
- Works across Exchange Online, SharePoint Online, OneDrive for Business, and Teams.
Memory trick: DLP: Don't Lose PII, encrypt it if it leaves.