Microsoft Purview Information Protection - Simply Explained
Welcome to another episode of Knowledge Nuggets with Mirko Peters. Today we're exploring Microsoft Purview Information Protection, the foundation of Microsoft's data classification and protection strategy across Microsoft 365. Every day, organizations create thousands of documents, spreadsheets, emails, presentations, and Teams conversations. Some of that information is completely public, while other files contain financial records, customer information, legal contracts, intellectual property, or confidential business plans. The challenge isn't simply storing this data—it's ensuring every piece of information is handled appropriately wherever it travels. Microsoft Purview Information Protection solves this challenge by allowing organizations to classify sensitive information, apply persistent sensitivity labels, and automatically enforce protection policies across Microsoft 365. Instead of waiting until data is about to leave the organization, protection begins the moment the content is created. In this episode, we'll explore how Microsoft Purview Information Protection works, how sensitivity labels travel with your data, how automatic classification operates behind the scenes, and how it integrates with Data Loss Prevention, Microsoft Teams, and Microsoft 365 Copilot.
WHY INFORMATION PROTECTION MATTERS
Many organizations assume their information is secure simply because it resides in Microsoft 365. However, protecting data from hackers is only one part of the challenge. The larger risk often comes from accidental sharing, misclassification, or users unknowingly exposing confidential information. Traditional security approaches attempted to inspect files only when they were leaving the organization. Every outgoing email or shared document had to be scanned before determining whether it contained sensitive information. While effective, this approach introduces delays and only reacts after data has already begun moving. Microsoft Purview Information Protection changes the model entirely. Instead of waiting until information leaves the organization, content is classified and labeled immediately. Once protected, every Microsoft 365 service instantly understands how that information should be handled without repeatedly scanning the content. Protection becomes proactive rather than reactive.
WHAT IS MICROSOFT PURVIEW INFORMATION PROTECTION?
Microsoft Purview Information Protection provides a centralized framework for classifying, labeling, and protecting sensitive information. The core concept is remarkably simple. Every document or email receives a sensitivity label that communicates its security requirements. Common examples include:
- Public
- Internal
- Confidential
- Highly Confidential
- Encryption
- Access restrictions
- Watermarks
- Headers and footers
- Printing restrictions
- Sharing controls
- Copy protection
CLASSIFICATION: FINDING SENSITIVE INFORMATION
Before information can be protected, Microsoft Purview must first identify sensitive content. Microsoft uses two primary detection methods. The first is Sensitive Information Types (SITs). These recognize structured information such as:
- Credit card numbers
- Passport numbers
- National identification numbers
- Healthcare identifiers
- Banking information
- Contracts
- Legal documents
- Resumes
- Financial reports
- Project documentation
SENSITIVITY LABELS: THE FOUNDATION OF PROTECTION
Once content has been classified, sensitivity labels determine how Microsoft 365 should handle it. Each label becomes much more than a simple category. A single label can automatically apply multiple protections simultaneously. For example, a Highly Confidential label might:
- Encrypt the document
- Prevent external sharing
- Disable printing
- Restrict copy and paste
- Apply visible watermarks
- Limit editing permissions
MANUAL VS AUTOMATIC LABELING
Organizations can apply sensitivity labels in two different ways. Manual labeling allows users to choose the appropriate label directly within Microsoft Office applications. This works well when users understand the business context surrounding a document. However, relying entirely on users creates inconsistency. Microsoft therefore provides automatic labeling. Client-side automatic labeling operates inside Office applications while users create documents. If sensitive information such as payment card data appears, Office can recommend or automatically apply the correct label before the document is saved. Service-side automatic labeling works across Microsoft 365 itself. Existing documents stored in SharePoint, OneDrive, or Exchange Online are scanned and labeled automatically without requiring user interaction. Microsoft recommends combining both approaches. Automatic labeling provides consistent baseline protection across large environments, while manual labeling allows users to apply additional context when appropriate. Simulation mode allows organizations to evaluate automatic labeling policies before enforcing them in production.
Become a supporter of this podcast: https://www.spreaker.com/podcast/m365-fm-modern-work-security-and-productivity-with-microsoft-365--6704921/support.
🚀 Want to be part of m365.fm?
Then stop just listening… and start showing up.
👉 Connect with me on LinkedIn and let’s make something happen:
- 🎙️ Be a podcast guest and share your story
- 🎧 Host your own episode (yes, seriously)
- 💡 Pitch topics the community actually wants to hear
- 🌍 Build your personal brand in the Microsoft 365 space
This isn’t just a podcast — it’s a platform for people who take action.
🔥 Most people wait. The best ones don’t.
👉 Connect with me on LinkedIn and send me a message:
"I want in"
Let’s build something awesome 👊
00:00:00,000 --> 00:00:05,880
In 2020, an employee at Vertifore accidentally exposed 27.7 million Texas driver records,
2
00:00:05,880 --> 00:00:10,420
names, addresses, birth dates and license numbers by storing three data files in an external
3
00:00:10,420 --> 00:00:11,700
storage location.
4
00:00:11,700 --> 00:00:16,400
No malicious hacking, no bad intentions, just routine work that went wrong, and the company
5
00:00:16,400 --> 00:00:17,880
didn't even discover it themselves.
6
00:00:17,880 --> 00:00:19,320
A third party had to tell them.
7
00:00:19,320 --> 00:00:23,320
That's the exact problem Microsoft Peruvio Data Loss Prevention DLP for short solves.
8
00:00:23,320 --> 00:00:27,560
It's not built to stop hackers, it's designed to stop your own people from accidentally leaking
9
00:00:27,560 --> 00:00:32,160
sensitive data. By the end of this episode, you'll know what Microsoft Peruvio DLP really
10
00:00:32,160 --> 00:00:37,000
is, why every business needs it, and how it quietly watches over your data across email,
11
00:00:37,000 --> 00:00:40,640
files, chats, devices, and even AI tools.
12
00:00:40,640 --> 00:00:43,760
The Data League Problem, why DLP exists?
13
00:00:43,760 --> 00:00:47,120
Before we talk about the solution, let's understand the scale of the problem. Here's a number
14
00:00:47,120 --> 00:00:52,760
that matters. 58% of data leaks are accidental. Not malicious, not some sophisticated attack,
15
00:00:52,760 --> 00:00:56,840
just someone forwarding an email to the wrong person or attaching the wrong file. Human
16
00:00:56,840 --> 00:01:00,800
error is the biggest security vulnerability most organizations have. And it's getting
17
00:01:00,800 --> 00:01:06,680
worse last year, 74% of organizations, nearly three out of four, reported a data incident.
18
00:01:06,680 --> 00:01:12,040
Yet organizations using disconnected security tools had 2.8 times more incidents, more tools
19
00:01:12,040 --> 00:01:16,880
meant more problems. Because when your security tools don't talk to each other, you get gaps.
20
00:01:16,880 --> 00:01:21,200
And data leaks through gaps. So what did organizations do before DLP? They locked everything
21
00:01:21,200 --> 00:01:26,040
down, disabled USB ports, outlawed personal email, restricted everything. The problem, that
22
00:01:26,040 --> 00:01:29,920
kills productivity. People need to share files to do their jobs. And when you make it too
23
00:01:29,920 --> 00:01:34,640
hard, they find workarounds. They use personal Gmail, upload to Dropbox or put data on USB
24
00:01:34,640 --> 00:01:38,840
drives anyway. The locks become useless. DLP takes a completely different approach. Instead
25
00:01:38,840 --> 00:01:42,760
of blocking everything, it watches three things. What the data is, who's handling it and where
26
00:01:42,760 --> 00:01:47,280
it's going. Then it enforces rules automatically. The core idea is simple. First, you identify
27
00:01:47,280 --> 00:01:51,560
what counts as sensitive credit card numbers, health records, confidential contracts. Then
28
00:01:51,560 --> 00:01:57,200
you monitor that data across all your Microsoft 365 services, email, files, chats, devices.
29
00:01:57,200 --> 00:02:02,000
And when someone tries to do something risky, DLP either warns them or blocks the action.
30
00:02:02,000 --> 00:02:05,480
It's not about locking people out. It's about catching honest mistakes before they become
31
00:02:05,480 --> 00:02:11,400
headlines. The office building analogy. So how does DLP actually do all that? Let's build
32
00:02:11,400 --> 00:02:15,080
a mental model. Imagine your organization is an office building with different departments
33
00:02:15,080 --> 00:02:18,560
on different floors and different security levels for different areas. The lobby has a
34
00:02:18,560 --> 00:02:23,560
reception desk and that's your identity system. Entra ID. It checks badges at the door. Are
35
00:02:23,560 --> 00:02:29,000
you who you say you are? Good, you're in. But here's the thing. Once you're inside, data
36
00:02:29,000 --> 00:02:33,240
moves constantly. People walk through hallways carrying files. They take documents to meeting
37
00:02:33,240 --> 00:02:37,800
rooms. They send papers through the mail room and they bring laptops home at night. And
38
00:02:37,800 --> 00:02:41,440
that's where the old approach fails. Because checking badges at the front door doesn't
39
00:02:41,440 --> 00:02:45,560
tell you what people are carrying out. DLP is like a team of security guards who don't
40
00:02:45,560 --> 00:02:49,160
just check badges. They look at what's in people's hands. A visitor walking out with a stack
41
00:02:49,160 --> 00:02:53,160
of confidential documents. The guard stops them and employee putting client files into their
42
00:02:53,160 --> 00:02:57,200
personal bag. The guard asks questions. These guards work everywhere in the building in the
43
00:02:57,200 --> 00:03:01,920
mail room scanning every outgoing email that's exchanged online in the file storage room
44
00:03:01,920 --> 00:03:06,160
watching files being shared share point and one drive in the conference rooms monitoring
45
00:03:06,160 --> 00:03:11,760
chat messages teams and on laptops. People take home endpoint DLP protecting devices even
46
00:03:11,760 --> 00:03:16,320
when offline. And there's a new guard that just arrived. The one standing next to the AI
47
00:03:16,320 --> 00:03:21,160
assistant making sure it doesn't hand sensitive data to the wrong person. That's copilot DLP.
48
00:03:21,160 --> 00:03:26,320
The building gets smarter but the guards keep up. Exchange online protecting email. Let's
49
00:03:26,320 --> 00:03:30,360
start in the mail room because email is still the most common way data walks out of your
50
00:03:30,360 --> 00:03:37,200
organization. One wrong reply. All one misplaced attachment or one moment of clicking send
51
00:03:37,200 --> 00:03:42,760
before your brain catches up. That's how most accidental leaks happen. Exchange online DLP
52
00:03:42,760 --> 00:03:47,240
scans every email before it sent both the body text and any attachments and it's not just
53
00:03:47,240 --> 00:03:51,520
doing simple keyword searches. It's using deep content analysis pattern recognition that
54
00:03:51,520 --> 00:03:56,000
catches credit card numbers following a specific format and passing a checksum test proximity
55
00:03:56,000 --> 00:04:00,080
detection that finds a name and an address right next to each other and machine learning
56
00:04:00,080 --> 00:04:05,120
classifiers that get smarter over time. Now imagine this an employee finishes a spreadsheet
57
00:04:05,120 --> 00:04:09,160
with customer credit card numbers. They need to work on it at home so they draft an email
58
00:04:09,160 --> 00:04:13,320
to their personal Gmail address and attach the file they hit send. But before that email
59
00:04:13,320 --> 00:04:17,440
actually leaves exchange DLP scans it finds the credit card numbers in the attachment
60
00:04:17,440 --> 00:04:21,760
recognizes the destination is outside the organization and blocks the send. What does
61
00:04:21,760 --> 00:04:27,320
the employee see a policy tip a pop-up that says something like this email contains sensitive
62
00:04:27,320 --> 00:04:31,240
information and can't be sent to external recipients. Depending on how the policy is
63
00:04:31,240 --> 00:04:35,520
configured they might have the option to override by providing a business justification explaining
64
00:04:35,520 --> 00:04:39,920
why the send is legitimate. That justification gets logged. So if it's a pattern on the same
65
00:04:39,920 --> 00:04:43,960
person doing this every Friday an admin can investigate the point is the email never
66
00:04:43,960 --> 00:04:48,400
reaches the outside it's called before it leaves the building and every match is logged.
67
00:04:48,400 --> 00:04:52,980
So admins can see exactly what was blocked who tried to send it and why the SharePoint
68
00:04:52,980 --> 00:04:57,080
and one drive protecting files at rest and in motion email isn't the only place data
69
00:04:57,080 --> 00:05:00,840
leaks happen. What about the files already sitting in your SharePoint sites or synced
70
00:05:00,840 --> 00:05:05,300
to your one drive that's where the next layer of DLP protection comes in SharePoint and
71
00:05:05,300 --> 00:05:10,320
one drive DLP watches files in two states at rest means the file is stored on the site.
72
00:05:10,320 --> 00:05:14,400
In motion means someone is sharing it with someone else you can create policies that scan
73
00:05:14,400 --> 00:05:18,840
existing files for anything sensitive if DLP find something it shouldn't it can flag
74
00:05:18,840 --> 00:05:23,880
the file or even quarantine it automatically. The quarantine feature is relatively new when
75
00:05:23,880 --> 00:05:28,880
DLP finds a violating file it moves that file to a secure location only admins can reach.
76
00:05:28,880 --> 00:05:33,520
The original file gets replaced with a tombstone file it's just a plain text message explaining
77
00:05:33,520 --> 00:05:37,440
why the file is missing and what the user should do if they think it's a mistake think of
78
00:05:37,440 --> 00:05:41,720
it as a sign that says this file has been secured talk to your admin if you needed for
79
00:05:41,720 --> 00:05:46,880
external sharing DLP gets even more specific you can block sharing to particular domains say
80
00:05:46,880 --> 00:05:50,840
you have a competitor you don't want receiving your internal documents just add their domain
81
00:05:50,840 --> 00:05:54,960
to a block list but here's what makes it really useful that restriction applies retroactively
82
00:05:54,960 --> 00:05:59,840
if a file was already shared with that domain before you created the policy DLP can revoke
83
00:05:59,840 --> 00:06:03,920
that access it's not just locking the door going forward it's checking who's already inside
84
00:06:03,920 --> 00:06:08,000
let's look at a real scenario a contractor working with your company accidentally shares a folder
85
00:06:08,000 --> 00:06:13,760
marked confidential with the entire organization that means hundreds of people now have access DLP
86
00:06:13,760 --> 00:06:17,680
detects the sensitivity label on the documents it sees the sharing activity and it restricts
87
00:06:17,680 --> 00:06:22,080
access to only the intended audience the damages contained before most people even realize
88
00:06:22,080 --> 00:06:26,240
the folder was shared one drive functions as your personal file vault you store your files there
89
00:06:26,240 --> 00:06:31,040
and work on them but DLP watches when you try to sync sensitive files to a personal device say
90
00:06:31,040 --> 00:06:36,720
someone drags a highly confidential document from one drive into their local downloads folder DLP
91
00:06:36,720 --> 00:06:41,040
can block that action because once that file leaves the cloud you lose control over it the guard
92
00:06:41,040 --> 00:06:47,040
at the door checks what's leaving the building even if it's from your own desk teams DLP protecting chat
93
00:06:47,040 --> 00:06:51,760
and channel messages work today doesn't just happen in email or shared folders a lot of it happens
94
00:06:51,760 --> 00:06:57,440
in teams private chats channel conversations quick messages back and forth and people share sensitive
95
00:06:57,440 --> 00:07:01,840
information there all the time a project manager types a client's social security number into a chat
96
00:07:01,840 --> 00:07:06,240
an engineer pays confidential code into a channel with external guests a salesperson drops a credit
97
00:07:06,240 --> 00:07:10,880
card number into a direct message no attachment needed no file required just text flying across
98
00:07:10,880 --> 00:07:16,800
the conversation teams DLP scans those messages to it monitors private chats and channel conversations
99
00:07:16,800 --> 00:07:21,120
and it looks at the message content itself not just attached files so if someone types a social
100
00:07:21,120 --> 00:07:26,400
security number directly into a chat DLP catches it the system can block the message from being sent
101
00:07:26,400 --> 00:07:30,960
show a policy tip explaining why and log the attempt for review let's walk through a specific
102
00:07:30,960 --> 00:07:35,920
scenario you have a channel where you collaborate with external partners someone on your team types
103
00:07:35,920 --> 00:07:43,120
here's the clients ssn 123456789 before that message appears in the channel teams DLP scans it
104
00:07:43,120 --> 00:07:47,600
it recognizes the social security number pattern it sees the message is heading to a channel with
105
00:07:47,600 --> 00:07:52,000
external guests and it blocks the message from being sent the person who typed it sees a warning the
106
00:07:52,000 --> 00:07:56,880
sensitive number never reaches the channel and an alert gets logged for the compliance team teams
107
00:07:56,880 --> 00:08:01,600
feels informal people treated like instant messaging they type things they'd never put in an email
108
00:08:01,600 --> 00:08:07,200
but a leaked ssn in a team's chat is just as damaging as one in an email attachment DLP treats
109
00:08:07,200 --> 00:08:13,040
them exactly the same way endpoint DLP protecting devices so we've put guards in the mail room the file
110
00:08:13,040 --> 00:08:17,040
storage and the conference rooms but what about the actual device someone is using right now
111
00:08:17,040 --> 00:08:22,080
think about a laptop at a coffee shop a desktop in a home office or a device on a plane with no internet
112
00:08:22,080 --> 00:08:27,840
connection that's where npoint DLP steps in endpoint DLP extends protection to the physical device itself
113
00:08:27,840 --> 00:08:32,880
including windows and macOS it watches everything that happens on that machine and it can block or
114
00:08:32,880 --> 00:08:37,920
audit actions that no cloud-based policy can reach things like copying files to a USB drive printing
115
00:08:37,920 --> 00:08:43,120
a confidential document uploading to a personal cloud service like dropbox pasting sensitive text into
116
00:08:43,120 --> 00:08:48,480
an unapproved browser or even sending files over Bluetooth here's something that surprises most
117
00:08:48,480 --> 00:08:53,040
people endpoint DLP works even when the device is offline the policies are cashed locally on the
118
00:08:53,040 --> 00:08:58,320
machine so if someone on a plane tries to copy a confidential file to a USB drive DLP still blocks
119
00:08:58,320 --> 00:09:02,400
it because the rules are already on the device they don't need to phone home how does it work a
120
00:09:02,400 --> 00:09:07,280
small agent runs on the device it uses the same deep content analysis we talked about earlier pattern
121
00:09:07,280 --> 00:09:12,560
recognition proximity detection machine learning but instead of scanning email or sharepoint it scans
122
00:09:12,560 --> 00:09:17,200
content as it moves across the device when you copy a file paste text or try to print the agent checks
123
00:09:17,200 --> 00:09:22,400
it every time it's watching everything that touches sensitive data let me give you a concrete example
124
00:09:22,400 --> 00:09:27,520
an employee opens a file labeled highly confidential and copies a section of text to paste into a
125
00:09:27,520 --> 00:09:33,120
personal gmail tab endpoint DLP detects the sensitivity label on the source file sees the paste is
126
00:09:33,120 --> 00:09:38,400
going to an unapproved browser and blocks it a warning pops up explaining why and the action never
127
00:09:38,400 --> 00:09:44,480
completes endpoint DLP covers a lot of ground copying to a USB drive gets blocked printing a confidential
128
00:09:44,480 --> 00:09:49,280
document gets blocked or audited uploading to dropbox or google drive gets blocked even pasting into
129
00:09:49,280 --> 00:09:54,720
an AI tool like chat GPT gets blocked and less obvious actions like copying to a network share
130
00:09:54,720 --> 00:09:59,920
or remote desktop session can also be monitored getting devices set up is done through internal group
131
00:09:59,920 --> 00:10:04,880
policy Microsoft recommends starting in simulation mode just like with other DLP policies you run the
132
00:10:04,880 --> 00:10:10,160
policy see what would have been blocked review the data tune the rules then enforce no surprises
133
00:10:10,160 --> 00:10:14,960
and you won't break any legitimate workflows recent updates have made endpoint DLP even more powerful
134
00:10:14,960 --> 00:10:20,480
as of 2026 it can detect and block exfiltration of files that haven't been saved yet someone
135
00:10:20,480 --> 00:10:25,600
pasting sensitive data into a new document and trying to copy it out before ever hitting save
136
00:10:25,600 --> 00:10:30,480
and on co-pilot plus PCs it can prevent windows recall from capturing snapshots of sensitive content
137
00:10:30,480 --> 00:10:36,480
the gods on your devices are getting smarter all the time co-pilot and AI DLP the new frontier so
138
00:10:36,480 --> 00:10:40,720
we've got gods in the mail room the file storage the conference rooms and on every laptop but there's
139
00:10:40,720 --> 00:10:46,080
a new corner of the office that needs watching the AI assistant Microsoft 365 co-pilot can access
140
00:10:46,080 --> 00:10:51,200
your organization's data emails files meetings chats that's incredibly powerful but it also creates
141
00:10:51,200 --> 00:10:56,080
a new risk when someone asks co-pilot a question they're essentially asking it to pull sensitive
142
00:10:56,080 --> 00:11:01,440
information from across your entire organization and handed to them in a neat summary here's the
143
00:11:01,440 --> 00:11:06,320
scenario a user opens co-pilot in word and types summarize the quarterly financials from the
144
00:11:06,320 --> 00:11:11,920
confidential folder without dlp co-pilot might pull that data and present it in the response even if
145
00:11:11,920 --> 00:11:16,560
the user has legitimate access the question creates a new copy of sensitive information in a new
146
00:11:16,560 --> 00:11:22,080
context once that summary exists in a new document it can be shared copied or leaked just like any
147
00:11:22,080 --> 00:11:26,560
other file dlp for co-pilot changes that by controlling what co-pilot can do with sensitive information
148
00:11:26,560 --> 00:11:31,360
it can block co-pilot from generating responses that contain sensitive data in our scenario co-pilot
149
00:11:31,360 --> 00:11:36,240
sees the sensitivity label on the quarterly financials recognizes the content is confidential
150
00:11:36,240 --> 00:11:41,360
and either blocks the summary entirely or excludes the sensitive parts this protection works across
151
00:11:41,360 --> 00:11:47,920
word excel powerpoint teams and outlook anywhere co-pilot appears Microsoft deployed default
152
00:11:47,920 --> 00:11:53,520
dlp policies for co-pilot in simulation mode in early 2026 so every tenant has a starting point but
153
00:11:53,520 --> 00:11:58,400
here's the catch those default policies are in simulation mode not actively blocking anything
154
00:11:58,400 --> 00:12:02,720
until you configure them many organizations think they're protected because they see the policy
155
00:12:02,720 --> 00:12:07,680
in the portal but unless enforcement is turned on co-pilot is still handing out sensitive data
156
00:12:07,680 --> 00:12:12,560
there's another angle too dlp can protect against the prompt itself if a user tries to paste
157
00:12:12,560 --> 00:12:18,800
sensitive data into a public AI tool like chat gpt endpoint dlp can block that paste using the same
158
00:12:18,800 --> 00:12:23,760
agent that blocks usb copies the risk isn't just what co-pilot reveals it's what your users accidentally
159
00:12:23,760 --> 00:12:29,200
feed into external AI models and here's a recent update that matters as of 2026 co-pilot will not
160
00:12:29,200 --> 00:12:33,920
interact with files that carry sensitivity labels at all no matter where you open them the label
161
00:12:33,920 --> 00:12:39,040
travels with the file and co-pilot respects it that's a clean boundary if a file is labeled highly
162
00:12:39,040 --> 00:12:45,440
confidential co-pilot won't touch it avoiding common mistakes now all of this sounds great on paper
163
00:12:45,440 --> 00:12:50,880
but here's the thing real world dlp deployments fail all the time it's almost never the technologies fault
164
00:12:50,880 --> 00:12:55,520
it's how the organization approaches it the biggest mistake people make is treating dlp as an
165
00:12:55,520 --> 00:13:00,560
IT project a team of admins sits in a room configures some policies and deploys them then users get
166
00:13:00,560 --> 00:13:05,520
blocked from doing legitimate work help desk calls spike policies get rolled back the security team
167
00:13:05,520 --> 00:13:10,640
loses credibility that's not how this works the dlp is a governance program not an IT project you need
168
00:13:10,640 --> 00:13:16,080
business stakeholders in the room legal compliance HR finance people who understand how data actually
169
00:13:16,080 --> 00:13:21,120
flows because if you block a workflow finance depends on to close the quarter you'll hear about it
170
00:13:21,120 --> 00:13:26,960
second mistake too many sensitivity labels some organizations launch with 15 or more labels nested
171
00:13:26,960 --> 00:13:32,960
sub labels names like semi restricted internal use only external sharing permitted with written
172
00:13:32,960 --> 00:13:37,520
approval users look at that and do one of three things they ignore labels entirely but they apply
173
00:13:37,520 --> 00:13:41,840
the default label to everything or they pick the lowest restriction to avoid friction none of
174
00:13:41,840 --> 00:13:46,640
those protect your data keep it simple start with three to five labels public internal confidential
175
00:13:46,640 --> 00:13:52,000
highly confidential expand only after people have adopted the basics third mistake only covering
176
00:13:52,000 --> 00:13:57,520
email this one's incredibly common an organization configures exchange dlp checks the box declares the
177
00:13:57,520 --> 00:14:02,400
job done but that policy does nothing for teams chats nothing for sharepoint bulk uploads nothing
178
00:14:02,400 --> 00:14:07,920
for someone copying files to usb drive you need to cover all the channels email sharepoint one drive
179
00:14:07,920 --> 00:14:13,680
teams and points and copilot each one is a separate door data can walk out of force mistake skipping
180
00:14:13,680 --> 00:14:18,320
simulation mode the temptation is to turn policies on immediately because you want protection now
181
00:14:18,320 --> 00:14:22,720
but that's how you break things always start in audit mode let the policy run log what it would
182
00:14:22,720 --> 00:14:26,960
have blocked and review the data you'll find legitimate workflows you didn't account for you'll
183
00:14:26,960 --> 00:14:31,920
see false positives you need to tune then move to policy tips warnings that educate users without
184
00:14:31,920 --> 00:14:37,440
blocking then after your confident turn enforcement on here's a practical 90 day plan day one deploy
185
00:14:37,440 --> 00:14:43,200
in audit mode only day 30 analyze the alerts and identify patterns day 60 tune your labels and
186
00:14:43,200 --> 00:14:48,080
exceptions based on what you've learned day 90 turn on enforcement targeting a false positive rate
187
00:14:48,080 --> 00:14:53,360
under five percent remember the number from the beginning 58% of leaks are accidental dlp isn't
188
00:14:53,360 --> 00:14:58,720
about punishing users it's about catching honest mistakes before they become headlines so here's
189
00:14:58,720 --> 00:15:03,520
what Microsoft purview dlp actually is it's a unified set of security guards that protect sensitive
190
00:15:03,520 --> 00:15:09,280
data across email files chats devices and ai tools it watches data in all three states at rest in
191
00:15:09,280 --> 00:15:15,040
motion and in use and it uses deep content analysis to understand what the data is not just
192
00:15:15,040 --> 00:15:19,840
what it looks like the goal isn't to lock everything down the goal is to stop the 58% of accidental
193
00:15:19,840 --> 00:15:26,080
leaks while letting people do their jobs because the vertifore story on 27.7 million records exposed by
194
00:15:26,080 --> 00:15:32,240
one innocent action happens every day in organizations that don't have these protections in place next time
195
00:15:32,240 --> 00:15:38,080
you hear about a data breach that was just an honest mistake remember dlp exists exactly for that
196
00:15:38,080 --> 00:15:42,240
subscribe on your favorite podcast platform and share this with someone starting their data security
197
00:15:42,240 --> 00:15:44,720
journey thanks for listening