MS-102 Flashcards
(348 cards)
To see DLP Alerts
show all –> compliance –> data loss prevention –> Alerts
Required licenses for ENDPOINT DLP
M365 E5, A5, Protection and Governance
To edit ENDPOINT DLP settings in Purview
compliance –> data loss prevention –
> endpoint DLP settings (RESTRICT APPS AND GROUPS, EVIDENCE COLLECTION)
To implements DLP for ENDPOINTS
Show all –> compliance –> settings –> device onboarding –> “Turn on device onboarding” and download the onboarding package
Custom DLP Policies
Will need to have a rule with a condition that contains a certain sensitive info type
To create a DLP policy in Purview
show all –> compliance –> Data loss prevention –
> Policies
Data Loss Prevention DLP
Prevents data leakage from occurring, monitors and protects sensitive info, identify sensitive info
To create Sensitivity Labels in Purview
show all –> compliance –> Information protection –> sensitivity labels (must publish)
Retention labels
must be published to be accessible, adaptive or static, can be auto applied or applied manually
Retention Policy
Gets rid of certain things at a certain time, info that can only be retained for so long
To create Retention labels in Purview
show all –> compliance –> data lifecycle management –>labels
To create new Sensitive Info types in Purview
show all –> compliance –> data classifications –> classifiers
Microsoft Purview license requirements
M365: E5, A5, G5
Office 365: E5, A5, G5
Purview Sensitivity Labels
identify and label sensitive information, applied to documents and emails, available to end users
Defender for Cloud Apps: App Discovery Policy
App discovery policies enable you to set alerts that notify you when new apps are detected within your organization.
Defender for Cloud Apps: Session Policy
Session policies provide you with real-time monitoring and control over user activity in your cloud apps`
Defender for Cloud Apps: Access Policy
Access policies provide you with real-time monitoring and control over user logins to your cloud apps
Defender for Cloud Apps: File Policy
enable you to scan your cloud apps for specified files or file types (shared, shared with external domains), data (proprietary information, personal data, credit card information, and other types of data) and apply governance actions to the files (governance actions are cloud-app specific)
Defender for Cloud Apps: Malware Detection Policy
enable you to identify malicious files in your cloud storage and automatically approve or revoke it. This is a built-in policy that comes with Defender for Cloud Apps and can’t be created
Defender for Cloud Apps: OAuth Policy
enable you to investigate which permissions each OAuth app requested and automatically approve or revoke it. (built in)
Defender for Cloud Apps: Anomaly Detection Policy
enable you to look for unusual activities on your cloud. Detection is based on the risk factors you set to alert you when something happens that is different from the baseline of your organization or from the user’s regular activity
Defender for Cloud Apps: Activity Policy
Activity policies allow you to enforce a wide range of automated processes using the app provider’s APIs. These policies enable you to monitor specific activities carried out by various users, or follow unexpectedly high rates of a certain type of activity.
To configure a Defender for Cloud Apps policy
show all –>security –> cloud apps –> Policies (can either create your own or use pre-built)