Data discovery and management is a difficult task. All orginisations have data that is sensitive, and they need to protect this data from any harm. But this is not easy. Finding the data is a challenge- knowing what it is, where it is, and how it is shared is such a big problem that 80% of it is dark. It is no surprise then that 88% of organizations lack confidence that they can detect and prevent loss of their sensitive data. This problem is worsened by the current situation of remote work and data sharing through devices and locations that are not managed by the corporate. But there is a solution for this.

I have implemented Purview for various customers over the years and I recommend starting by understanding your existing data. Where it is stored, who has access to it, what it actually contains.

I have seen people in the past trying to have Microsoft Purview driven by the IT team, but this should really be driven by the business to define what the policies should be. However, we still need to help the business decision makers make the right choices, so we need to set up the policies in simulation mode, so we can show the business what data exists and how extensive any impact will be.

To create the first policy go to purview.microsoft.com

Select Data loss prevention

Select create policy

Microsoft provides a number of built-in policies that I suggest using to start with, we can always modify them later.

Start by excluding devices and Microsoft Cloud apps from the locations. This will help us set the policy for external data sharing. Then you can adjust the policies to suit your organisation, and choose to test them first. You can also show policy tips to users when they trigger a DLP policy, but I recommend testing first.

An example on how to get this configured is below, next post we will go over how to fine tune the policies.

  • Login to Purview.microsoft.com
  • Select Data Loss Prevention
  • Select Policies
  • Select create policy
  • Select build a policy from a template, for this example we are going to use U.K. Financial Data
  • Provide the policy a name
  • Set the admin units, for this example we are going to do full directory
  • Set the locations, for this example we are just going to use Exchange, SharePoint, OneDrive & Teams
  • Review the policy settings
  • For the detection we are going to set it to detect with people outside my organisation
  • Select the policy actions such as send alerts each time, send reports
  • Identify any access and override settings, as this is going to be in simulation we won’t select anything for now
  • Run the policy in simulation mode