Microsoft 365 FundamentalsDescribe security, compliance, privacy, and trust in Microsoft 365Easy
A small business is using Microsoft 365 and wants to ensure that all sensitive customer data, such as credit card numbers and health information, is not accidentally shared outside the organization via email or other collaboration tools. Which Microsoft 365 security and compliance capability should they implement to prevent this type of data exfiltration?
- AConditional Access policies
- BAzure AD Identity Protection
- CMicrosoft Purview eDiscovery
- DData Loss Prevention (DLP)
Show answer & explanationAnswer & explanation
Correct answer: D. Data Loss Prevention (DLP)
Data Loss Prevention (DLP) policies in Microsoft 365 are designed to identify, monitor, and automatically protect sensitive information across various locations, preventing it from being shared inappropriately or accidentally outside the organization.
Why the other options are wrong
- A. Conditional Access policies control access to resources based on conditions, but don't specifically prevent sensitive content from being shared once access is granted.
- B. Identity Protection focuses on securing user accounts from compromise, not preventing data exfiltration directly.
- C. eDiscovery is for legal content searches, not proactive data loss prevention.
Data Loss Prevention (DLP)
A Microsoft 365 capability that helps prevent sensitive information from being accidentally or intentionally shared outside the organization, ensuring compliance with data protection regulations.
- Identifies sensitive information using built-in or custom sensitive info types.
- Monitors data across Exchange, SharePoint, OneDrive, and Teams.
- Can block sharing, notify users, or encrypt content based on policy.
Memory trick: Prevent Data Loss with intelligent policies.