From the course: Microsoft Information Security Administrator Associate (SC-401) Cert Prep by Microsoft Press

Unlock this course with a free trial

Join today to access over 25,300 courses taught by industry experts.

Configure DLP policies for Adaptive Protection

Configure DLP policies for Adaptive Protection

Adaptive protection is an advanced feature that makes your DLP policies dynamic based on user behavior risk. It ties into Microsoft's IRM, or Insider Risk Management System. The general idea is that not all users pose the same risk of data leakage. If a particular user has been exhibiting a risky behavior, such as trying to download sensitive files or they're leaving the company soon and have anomalous activities, you might want DLP to be a bit stricter for them. So with adaptive protection, each user is evaluated by insider risk management and assigned a risk level. For example, IRM might label Alice as elevated risk if she's had multiple policy violations in the past or suspicious file movements, whereas Bob might be moderate and Charlie minimal. These risk levels are continually updated by the machine learning analysis of user actions, so like a user risk score. Adaptive DLP policies can then apply different actions depending on the user's risk level. For instance, elevated risk…

Contents