Microsoft Defender for Cloud Apps
Cloud and workloads

Commonly used information protection policies | Microsoft Defender for Cloud Apps

In brief

The article now covers file and session policy scenarios, explains when the Data Classification Service inspects file content, and clarifies steps for sensitivity-label filters, governance actions, and GDPR-related data types.

What Defender admins need to know

Administrators have clearer guidance for configuring content inspection and sensitivity-label policies; no required change is stated.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Commonly used Microsoft Defender for Cloud Apps information protection policies

This article shows how to create and configure Defender for Cloud Apps file and session policies allow you to enforce a wide rangefor common information protection scenarios. These scenarios include detecting external sharing of automated processes. Policies can be set to provide information protection, including continuous compliance scans, legal eDiscovery tasks,sensitive data, encrypting data at rest, blocking downloads, and DLP for sensitive content shared publicly.more. Each scenario lists its own prerequisites, such as connected apps or Microsoft Purview Information Protection integration.

Defender for Cloud Apps can monitor any file type based ontype. It supports more than 20 metadata filters, for example,such as access level,level and file type. Several of the policies in this article use the Data Classification Service (DCS), which inspects file content to identify sensitive information types. For details about available metadata filters and policy configuration options,more information, see File policiesFile policies.

Detect and prevent external sharing of sensitive data

Detect when files with personally identifying information or other sensitive data are stored in a Cloud service and shared with users who are external to your organization that violates your company's security policy and creates a potential compliance breach.

Some of the policies in this section use the Data Classification Service (DCS) as the inspection method to identify sensitive information in your files.

Prerequisites

You must have at least one app connected using app connectors to connect apps.

Detect externally shared confidential data

Detect when files that are labeled Confidential and are stored in a cloud service are shared with external users, violatingusers. This sharing violates company policies.

Prerequisites

  1. In the Microsoft Defender Portal, under Cloud Apps, go to Policies -> Policy management. Create a new File policy.

  2. Set the filter Sensitivity label to Microsoft Purview Information Protection equals. Select the Confidential label, or your company's equivalent.

  3. Set the filter Access Level equals Public (Internet) / Public / External.

  4. Optional: Set the Governance actions to be taken onfor files when a violation is detected. The governanceavailable actions available vary between services.

  5. Create the file policy.

Detect and encrypt sensitive data at rest

Detect files containing personally identifying information andthat contain personal data or other sensitive data that is shareshared in a cloud app andapp. Then apply sensitivity labels to limit access only to employees in your company.

Prerequisites

Steps

This policy uses the Data Classification Service (DCS), which inspects file content for sensitive information types.

Use the following proceduresteps to create the policy:

  1. In the Microsoft Defender Portal, under Cloud Apps, go to Policies -> Policy management. Create a new File policy.

  2. Under Inspection method, select Data Classification Service (DCS) and under. Under Select type, select the type of sensitive informationdata you want DCS to inspect.

  3. Under Governance actions, check Apply sensitivity label and select. Select the sensitivity label that your company uses to restrict access to company employees.

Detect and protect GDPR related data across file storage apps

Detect files in cloud storage apps that contain personal data or other sensitive data subject to GDPR. Then apply sensitivity labels to limit access to authorized personnel.

Prerequisites

  1. In the Microsoft Defender Portal, under Cloud Apps, go to Policies -> Policy management. Create a new File policy.

  2. Under Inspection method, select Data Classification Service (DCS). Under Select type, select one or more GDPR-related information types. Examples include EU debit card number, EU drivers license number, EU national/regional identification number, EU passport number, EU SSN, and EU tax identification number.

  3. Set the Governance actions for files when a violation is detected. Select Apply sensitivity label for each supported app.