420333 – Microsoft Purview compliance portal: Endpoint Data Loss Prevention – Ability to fetch the original file resulting in policy match as evidence (Microsoft managed storage)

cloudscout.one Icon

*For this entry exists the more relevant or more recent entry MC940076

check before: 2025-02-01

Product:

Purview Communication Compliance, Purview Data Loss Prevention

Platform:

Web, World tenant

Status:

Launched

Change type:

Links:

MC940076

Details:

With this capability, Admins can choose to store a copy of the file that resulted in a DLP policy match. The admin uses this data to analyze the contents to confirm the full set of data that was exfiltrated to assess severity. To configure Microsoft managed storage, similar to customer managed storage, the user can go to endpoint DLP settings and select Microsoft managed storage. As compared to customer managed storage, the admin need not configure any additional settings like adding a blob, assigning permissions, or selecting storage in policy workflow.

Change Category:
XXXXXXX ... free basic plan only

Scope:
XXXXXXX ... free basic plan only

Release Phase:
Preview, General Availability

Created:
2024-10-29

updated:
2025-03-07

Public Preview Start Date

XXXXXXX ... free basic plan only

Docu to Check

XXXXXXX ... free basic plan only

MS workload name

XXXXXXX ... free basic plan only

summary for non-techies**

XXXXXXX ... free basic plan only

Direct effects for Operations**

Please, look at the most relevant linked item for details

explanation for non-techies**

Imagine you are running a library, and you have a rule that certain rare books cannot leave the premises. If someone tries to take one of these books out, an alarm goes off, and you need to investigate what happened. In the world of IT, this is similar to how Data Loss Prevention (DLP) policies work. They are designed to prevent sensitive information from leaving a company's network.

Microsoft Purview's new feature is like having a security camera that captures a snapshot of the book in question when the alarm goes off. This feature allows administrators to store a copy of the file that triggered the DLP policy. By having this copy, they can review the contents to understand exactly what information was at risk and determine how serious the situation is.

In practical terms, this means that when a file is flagged by a DLP policy, the system can automatically save a copy of it in a secure location managed by Microsoft. This is akin to having a special vault in your library where the snapshot of the book is stored safely. The benefit here is that administrators don't have to worry about setting up this storage themselves, which can involve complex steps like creating storage spaces, setting permissions, or managing access rights. Microsoft takes care of all that, making the process simpler and more efficient.

This feature helps organizations ensure that they have all the necessary information to make informed decisions about potential data breaches, much like how a librarian would use the security footage to understand how a rare book almost left the library.

** AI generated content. This information must be reviewed before use.

a free basic plan is required to see more details. Sign up here


A cloudsocut.one plan is required to see all the changed details. If you are already a customer, choose login.
If you are new to cloudscout.one please choose a plan.



change history

DatePropertyoldnew
2025-03-07RM StatusRolling outLaunched
2025-02-07RM ReleaseApril CY2025February CY2025
2025-02-07RM StatusIn developmentRolling out
2024-11-06RM ReleaseJanuary CY2025April CY2025

Last updated 2 months ago ago

Leave a Reply

Share to MS Teams

Login to your account

Welcome Back, We Missed You!