300 likes | 311 Views
Learn about Data Loss Prevention (DLP) in Microsoft Office 365, including its features, examples, and policy enforcement. Explore DLP in Exchange Online and SharePoint Online, DLP content detection flows, user experiences, policy templates, and examples. Discover how DLP helps monitor, protect, and identify sensitive data, with real-world scenarios and advanced content analysis opportunities.
E N D
Melbourne Office 365 User Group November 2014 Proudly Sponsored by
Agenda House keeping What’s new in Office 365 this month DLP in Office 365 Meet and mingle
New in Office 365 world … Rolled out: DLP for SharePoint Online FastTrack 2.0 onboarding& adoption benefits Office for iPad changes eDiscovery Enhancements Shared Computer activation for Office 365 ProPlus ADFS support for client (preview) System Center Management Pack
New in Office 365 world … Rolling out: Delve & the Office Graph Document Conversations Groups in Office 365 SharePoint Online encryption at rest User themes Office 365 Video OneDrive for Business unlimited storage (CY 2015) Outlook for Mac updated
Office 365 Ignite Training Melbourne December 8th through 10th http://aka.ms/ausignite
Office 365 Dev Camp Melbourne December 11th http://aka.ms/365DevCamp2014
Office 365 Ignite Summit Sydney March 30th through 31st, 2015 http://summit.office.com/
Melbourne Office 365 User Group Data Loss Prevention in Office 365 Michael Frank Infrastructure Consultant Kloud Solutions Michael.Frank@Kloud.com.au Harris Schneiderman Account Manager Kloud Solutions Harris.Schneiderman@Kloud.com.au
“ “ Large Retailer Leaks Payment Information via Email… “ “ Data breaches leave the Australian public fuming …http://www.businessspectator.com.au/news/2013/5/27/technology/data-breaches-leave-australian-public-fuming
Monitor Protect Identify DLP helps To YOUR SENSITIVE DATA
Session Agenda What is DLP in Microsoft Office 365? How does DLP work? DLP in Exchange Online DLP in SharePoint Online DLP Examples Policy Tips Reporting, Auditing, and Notifications Office 365 DLP Roadmap
Backend policy evaluation • DLP policy configuration • Admin • Audit & incident data generation DLP system walkthrough • Policy distribution • Contextual policy education • Information workers
Integrated into Exchange Transport Rule (ETR) engine • Runs in categorizer during OnResolvedMessage • Integrated as a new ETR predicate • Performs text extraction for body & attachments followed by classification • Can be combined with any existing predicates & actions SMTP receive Categorizer Transport rule agent Text extraction Classification DLP content detection flow in Exchange Queue management Message delivery Store driver
Runs in Content Processing Pipeline as an operator Invoked for search crawler as new content discovered and changed Classification results and counts stored in the content index Crawler Content Processing Component Delete item Index Delete Links DLP content detection flow in SharePoint Document Parser Property Mapping Language Detection Wordbreaking Custom Entity Extraction Classification Operator Document summary Insert new or updated item Excel Format Handler Ifilter sandbox
Flexible tools for policy enforcement that provide the right level of control Transport Rules Rights Management Data Loss Prevention APPEND OVERRIDE REVIEW ENCRYPT CLASSIFY REDIRECT DLP Policy Enforcement ALERT BLOCK
DEMO DLP User Experience
Built-in templates based on common regulations Import DLP policy templates from partners Build your own DLP policy templates
Predefined rules targeted at sensitive data types Advanced content detection Combination of regular expressions, dictionaries, and internal functions (e.g. validate checksum on credit card numbers) Extensibility for customer and ISV defined data types Sensitive content detection
DEMO DLP Admin Experience
Examples: Get Content Joseph F. Foster Visa: 4485 3647 3952 7352 Expires: 2/2015 RegEx Analysis 4485 3647 3952 7352 a 16 digit number is detected 4485 3647 3952 7352 matches checksum 1234 1234 1234 1234 does NOT match Function Analysis Keyword Visa is near the number A regular expression for date (2/2015) is near the number Additional Evidence Content analysis process Verdict There is a regular expression that matches a check sum Additional evidence increases confidence
Advanced deep content analysis enabling new scenarios! A tax firm needs to detect and encrypt standard tax forms, like the 1040 EZ, W2, etc. Company Confidential documents like Patents detected based on their template A Law firm can fingerprint legal forms, and have them detected automatically for policy application Integrates with the existing DLP infrastructure as a custom sensitive information type Surfaced in Exchange, Outlook and OWA DLP Document Fingerprinting
Get Template Content Fabrikam Patent Form Tracking Number Author Date Invention Title Names of all authors... CLASSIFICATION RULE with FINGERPRINT CONFIGURATION Create Fingerprint Condensed representation of the template content Document is not stored Stored as a sensitive information type Evaluation + verdict Fabrikam Patent Form Tracking Number 12345Author Alex Date 1/28/2014Invention Title Fabrikam Green Energy... Get Email Content Document Fingerprinting Temporary in memory representation Used for comparson with source fingerprint created at config time Create Fingerprint RUNTIME FINGERPRINT GENERATION Verdict Compare the two fingerprints Evaluate a ’containtment coefficient’ to declare template contained in email content
Search for sensitive data Built-in classifications Identification and export Extends to data in OneDrive DLP in SharePoint Online
Classification • Match details • Audit data • Rule details Real Time Notifications
Custom DLP content Supplemental DLP policy rules Supplemental DLP classification rules Incident reports integration with custom workflows Custom reporting solutions Remote PowerShell management DLP extensibility points
EXCHANGE and OUTLOOK 2013 NEW in SP1 – EXCHANGE and OUTLOOK 2013 Deep content analysis engine 46 OOB sensitive information types 40 OOB DLP Templates Support for 3rd party defined DLP policy templates Policy Tips in OWA and Mobile OWA Advanced Document Fingerprinting in Exchange, Outlook, and OWA 5 new OOB sensitive information types Policy Tips in Outlook 2013 Contextual user education and empowerment Incident management Rich reporting DLP Feature Set in Office 365 DLP in SharePoint coming soon
Monitor Protect Identify DLP helps To YOUR SENSITIVE DATA
Thank You • Merging with Melbourne SharePoint User Group • Next Meetup will me in February (Date TBC) • UG Xmas Drinks December 18th 5:30pm @ Melbourne Public Bar at South Wharf • Feedback: https://www.surveymonkey.com/s/KNNXHMZ • We want you! Calling all speakers & sponsors! • Sponsors: Microsoft & Kloud