MS-102 Implement Compliance Flashcards
(41 cards)
Microsoft Purview Compliance Manager
uses a centralized dashboard to calculate a risk-based score, measuring an organization’s progress in completing actions that help reduce risks around data protection and regulatory standards.
Organizations can use sensitivity labels to:
Enforce message encryption
Enforce usage restrictions
Apply visual markings
Protect information across platforms and devices, on-premises and in the cloud
Services that Retention policies can be applied to
Teams and Yammer messages
Exchange email
SharePoint sites
OneDrive accounts
Key elements of Compliance Manager
Controls, Assessments, Templates
Controls
a requirement of a regulation, standard, or policy. It defines how an organization assesses and manages system configuration, organizational process, and the people responsible for meeting a specific requirement of a regulation, standard, or policy.
Assessments
grouping of controls from a specific regulation, standard, or policy. Completing the actions within an assessment helps organizations meet the requirements of a standard, regulation, or law.
When an organization comes to Compliance Manager for the first time, what is its initial score based on?
Microsoft 365 data protection baseline
the Microsoft 365 data protection baseline. This baseline assessment, which is available to all organizations, is a set of controls that includes common industry regulations and standards.
to enable insider risk analytics:
In the Microsoft Purview compliance portal, select Insider risk management in the navigation pane.
Select Run scan on the Scan for insider risks in your organization card on the Insider risk management Overview tab. This action turns on analytics scanning for your organization. You can also turn on scanning in your organization by navigating to Insider risk settings, then Analytics and enabling the option titled: Scan your tenant’s user activity to identify potential insider risks.
On the Analytics details pane, select Run scan to start the scan for your organization. Analytics scan results may take up to 48 hours before insights are available as reports for review.
Insider risk management policies
define what triggering events and risk indicators an organization examines. These conditions include:
How alerts use risk indicators.
The users included in the policy.
The services the organization prioritized.
The monitoring time period.
Which of the following actions is considered the heart of the insider risk management workflow?
Creating a case,
This area is where risk activities, policy conditions, alerts details, and user details are synthesized into an integrated view for reviewers.
Members of the following roles can assign users to Insider risk management role groups
Microsoft Entra Global Administrator
Microsoft Entra Compliance Administrator
Microsoft Purview compliance portal Organization Management
Microsoft Purview compliance portal Compliance Administrator
Policy templates
Insider risk management templates are predefined policy conditions. Each template defines the types of risk indicators and risk scoring model the associated policy uses.
How many policies does insider risk management support for each policy template?
5
To create a new Insider risk management policy
In the Microsoft Purview compliance portal, select Insider risk management in the navigation pane.
On the Insider risk management page, select the Policies tab.
Select Create policy on the menu bar. This option opens the Policy wizard.
In the Policy wizard, on the Policy template page, choose a policy category and then select the template for the new policy. These templates consist of conditions and indicators that define the risk activities an organization wants to detect and investigate. Review the template prerequisites, triggering events, and detected activities to confirm this policy template fits your needs.
To manually start scoring an activity for users in one or more Insider risk management policies
In the Microsoft Purview compliance portal, select Insider risk management on the navigation pane.
On the Insider risk management page, select the Policies tab.
On the policy dashboard, select the policy or policies you want to add users to.
Select Start scoring activity for users.
In the Reason field in the Add users to multiple policies pane, add a reason for adding the users.
In the This should last for (choose between 5 and 30 days) field, define the number of days to score the user’s activity for the policy.
To triage an insider risk alert,
In the Microsoft Purview compliance portal, select Insider risk management in the navigation pane.
On the Insider risk management page, select the Alerts tab.
On the Alerts dashboard, select the alert you want to triage.
On the Alert detail page, you can review information about the alert. You can:
Confirm the alert and create a new case.
Confirm the alert and add to an existing case.
Dismiss the alert.
Alert throttling
Insider risk management uses built-in alert throttling to help protect and optimize an organization’s risk investigation and review experience. Throttling guards against issues that may result in an overload of policy alerts.
To escalate a case to a user investigation:
in the Microsoft Purview compliance portal, select Insider risk management on the navigation pane.
On the Insider risk management page, select the Cases tab.
On the Cases tab, select a case. Then select the Escalate for investigation button on the menu bar.
In the Escalate for investigation dialog box, enter a name for the new user investigation. If needed, enter notes about the case and select Escalate.
Review the notice fields and update as appropriate. The values entered here override the values on the template.
Complete the following steps to resolve a case:
In the Microsoft Purview compliance portal, select Insider risk management on the navigation pane.
On the Insider risk management page, select the Cases tab.
On the Cases tab, select a case. Then select the Resolve case button on the menu bar.
Microsoft Purview Information Barriers (IB)
a compliance solution that allows organizations to restrict two-way communication and collaboration between groups and users in Microsoft Teams, SharePoint, and OneDrive.
SharePoint, information barriers (IBs) can determine and prevent the following kinds of unauthorized collaborations:
Adding a user to a site.
User access to a site or site content.
Sharing a site or site content with other users.
What’s the maximum number of compatible segments that can be associated with a site?
100
What happens if the segments associated with a user’s OneDrive don’t match the segment applied to the user?
The user can’t access their OneDrive
- How many segments can a user be in?
1