From the course: Microsoft Information Security Administrator Associate (SC-401) Cert Prep by Microsoft Press
Unlock this course with a free trial
Join today to access over 25,300 courses taught by industry experts.
Configure DLP policies for Adaptive Protection - Microsoft 365 Tutorial
From the course: Microsoft Information Security Administrator Associate (SC-401) Cert Prep by Microsoft Press
Configure DLP policies for Adaptive Protection
Adaptive protection is an advanced feature that makes your DLP policies dynamic based on user behavior risk. It ties into Microsoft's IRM, or Insider Risk Management System. The general idea is that not all users pose the same risk of data leakage. If a particular user has been exhibiting a risky behavior, such as trying to download sensitive files or they're leaving the company soon and have anomalous activities, you might want DLP to be a bit stricter for them. So with adaptive protection, each user is evaluated by insider risk management and assigned a risk level. For example, IRM might label Alice as elevated risk if she's had multiple policy violations in the past or suspicious file movements, whereas Bob might be moderate and Charlie minimal. These risk levels are continually updated by the machine learning analysis of user actions, so like a user risk score. Adaptive DLP policies can then apply different actions depending on the user's risk level. For instance, elevated risk…
Contents
-
-
-
-
-
-
(Locked)
Module introduction1m 9s
-
(Locked)
Learning objectives1m 12s
-
(Locked)
Design DLP policies based on an organization’s requirements3m 30s
-
(Locked)
Implement roles and permissions for DLP3m 16s
-
(Locked)
Create and manage DLP policies5m 40s
-
(Locked)
Configure DLP policies for Adaptive Protection5m 31s
-
(Locked)
Interpret policy and rule precedence in DLP5m 26s
-
(Locked)
Create file policies in Microsoft Defender for Cloud Apps by using a DLP policy5m 6s
-
(Locked)
-
-
-
-
-
-