Microsoft 365 FundamentalsDescribe security, compliance, privacy, and trust in Microsoft 365Medium
A Microsoft 365 administrator needs to ensure that specific sensitive data, such as credit card numbers or social security numbers, is not shared accidentally or maliciously outside the organization's control. This includes preventing sharing through email, Teams messages, and SharePoint documents. Which Microsoft 365 capability should the administrator configure to achieve this goal?
- AMicrosoft Purview Communication Compliance
- BMicrosoft Purview Information Protection (MPIP)
- CMicrosoft Purview Message Encryption
- DMicrosoft Purview Data Loss Prevention (DLP)
Show answer & explanationAnswer & explanation
Correct answer: D. Microsoft Purview Data Loss Prevention (DLP)
Microsoft Purview Data Loss Prevention (DLP) policies are designed to identify, monitor, and protect sensitive information across Microsoft 365 services. It can prevent sensitive data from being shared inappropriately, whether accidentally or intentionally.
Why the other options are wrong
- A. Communication Compliance helps detect and prevent inappropriate communications, but DLP specifically targets sensitive data leakage.
- B. MPIP classifies and labels sensitive data, enabling protection, but DLP actively enforces rules to prevent data loss.
- C. Message Encryption protects emails in transit and at rest but does not prevent the initial sharing of sensitive content.
Microsoft Purview Data Loss Prevention (DLP)
A set of policies and tools in Microsoft 365 that helps organizations prevent sensitive information from being accidentally or intentionally shared, disclosed, or misused. DLP policies can identify, monitor, and protect sensitive data across various services.
- Identifies and monitors sensitive information.
- Prevents unauthorized sharing of data.
- Applies across Exchange, SharePoint, OneDrive, and Teams.
Memory trick: DLP: Don't Leak PII! It's your digital bouncer for sensitive info.