Microsoft Defender for Cloud Apps
Cloud and workloads

DLP content inspection

In brief

The article now identifies “Grant permission” as one-time administrator consent, clarifies that content and metadata are inspected by default, and adds guidance for configuring file policies that inspect protected files.

What Defender admins need to know

Administrators configuring protected-file inspection can follow the clarified consent step and new file-policy guidance.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

DLP content inspection in Microsoft Defender for Cloud Apps

Matched text is replaced with "X" characters, and the surrounding context (100 characters before and after the match) is masked. Numbers in the context are replaced with "#" and aren't stored. To expose the final four digits of a match, enable the Unmask the last four characters of a match setting in the file policy.

You can also define which file elements are inspected—content, metadata, or file name. By default, inspection applies to both content and metadata. This approachInspecting both content and metadata by default allows inspection of protected files, detection of sensitive data, enforcement of compliance, and application of governance controls, while reducing false positives and aligning enforcement with internal classification standards.

Prerequisites

To grant one-time admin consent, in the Defender portal go to Settings > Cloud Apps > Microsoft Information Protection > Inspect protected files, and select Grant permission.

Content inspection for protected files

Configure file policies for protected files

To configure a file policy that inspects protected files, complete the following steps:

  1. In the Defender portal, go to Settings > Cloud Apps > Policies > Policy management.
  2. Follow the steps to create a new file policy.
  3. Select either Apply to all files, or Apply to selected files to specify which files to scan. This option is useful if you have an inner classification keyword standard that you want to exclude from the policy. :::image type="content" source="media/content-inspection/inspection-method-data-classification-service.png" alt-text="Screenshot that shows the Data classification service inspection method.":::

Next stepsRelated content