Licences & Software
All Microsoft licences from a single source – simple, secure and reliable.
Purview combines sensitivity labels and endpoint DLP to reliably block cloud uploads of sensitive files.
Many companies have sensitive data that, for regulatory or business reasons, must not be transferred to the cloud – either intentionally or accidentally. Organisational guidelines cannot technically prevent this.
With Microsoft Purview, such requirements can now be implemented much more precisely – through the combination of sensitivity labels and endpoint DLP.
In this article, I will show you how to create a label such as "NoCloud" and link it to an endpoint DLP policy to effectively block the upload of confidential files to cloud services such as OneDrive, Dropbox or Google Drive.
First, we create a new label that will later serve as the trigger for the DLP rule.
We now ensure that files labelled "NoCloud" can no longer be uploaded to cloud storage – regardless of whether the upload is done via the browser, an app or Explorer.
Alternatively: If you want to prevent all files (regardless of classification) from being uploaded via DLP, you can use the condition "Document size is equal to or greater than". Select 1 byte there, and it will apply to everything.
However, you should find out in advance whether there are scenarios where, for example, partners require an external cloud storage solution or similar.
When it comes to service domains, it should be noted that these do not work for "paste in" actions. This is a feature gap that will surely be closed in the future.
After deployment, a targeted test is recommended:
Several tools are available for tracking and analysis:
Activity Explorer: Shows blocked actions in detail
The combination of unified labelling and endpoint DLP allows you to implement highly targeted protective measures without unnecessarily restricting user productivity. The NoCloud label is a simple but effective way to ensure that certain data does not leave the company via cloud services.
Of course, the relevant clients must first be rolled out in Endpoint DLP (when using MDE, this is done with a single click (Purview Admin Centre > Settings > Device Onboarding > Devices > Turn On Windows Device Monitoring). The service domains and browsers must also be maintained in the Endpoint DLP settings.
In principle, Chrome and Firefox can be used in combination with Purview. The only thing to note is that the Purview extension must be distributed.
Configure settings to prevent data loss at the endpoint - Microsoft Purview | Microsoft Learn
Modern IT and cloud scenarios place new demands on security, governance and operations. Telekom's consulting services on Microsoft security help you analyse your environment in a structured manner and develop it in a targeted way – from initial classification to concrete implementation.
Start with a no-obligation orientation meeting or a Microsoft 365 Security Assessment and receive clear recommendations for action to improve security.
Do you have questions about Telekom's Microsoft service offering or would you like personal advice? Simply contact our experts without obligation using the consultation form.
All Microsoft licences from a single source – simple, secure and reliable.
übergreifend-Teaser-Telekom-Partner-Lizenzen-Software-Link-CMP
Certified experts support you with tailor-made solutions for your business.
Discover our offer
We are always there for you: quick assistance, personal support – at no extra cost.
Contact
ISG and Microsoft-certified services for maximum security and reliability.
About the Microsoft portfolio
Marcus began working with Microsoft Office 365 in 2014. Since then, he has focused on various projects and supported customers from a wide range of industries. In recent years, Marcus has concentrated on Microsoft security issues.