Microsoft Office 365 Data Loss Protection (DLP) Tutorial - YouTube

Channel: Sly Gittens – Tech Simplified

[0]
Welcome to the Sly Gittens-Tech Simplified channel
[3]
and in today's video,
[5]
I will be showcasing and discussing
[8]
how to create office 365 DLP
[12]
or data loss prevention policy from a template.
[14]
And you want to watch this video to the end
[17]
because I've got a special demo showcasing
[20]
how to make sure credit card information
[23]
doesn't leave your environment accidentally.
[27]
So stay tuned and watch this video to the end.
[35]
So the first thing I need you to do is make your way over to the Microsoft 365 admin Center
[40]
and then once you get here,
[41]
you're going to click on security
[44]
and then once this page loads,
[46]
we're going to click on data loss prevention
[48]
then click on policy
[50]
then click on create a policy.
[52]
Wow.
[54]
Since I'm showcasing us data, so let me search for that
[59]
and then I want to click on US financial data
[62]
and as you can see,
[63]
it protects information such as credit card numbers,
[66]
US bank account numbers,
[68]
ABA routing numbers as well right.
[71]
So you wanna click next.
[71]
I have the option to change the name or update the description.
[75]
They also gives me the ability to select
[77]
where my data is being stored that I want to protect
[80]
and be notified if it leaves our organization.
[83]
Where do you want to do that?
[84]
So I can say from all areas such as exchange email,
[88]
teams chat, channel messages, onedrive, a SharePoint
[92]
One thing I do want to show you if you do choose to...
[95]
specify the areas, you can remove something. If you don't use team in your environment,
[99]
you can remove it.
[100]
Areas I see a lot of customers using
[102]
in selecting who needs to follow this
[105]
because maybe everyone your organization don't need to have this policy
[109]
sent out to them
[110]
and some people that you might want to exclude just for certain reasons as well.
[114]
So you can include or exclude certain people.
[117]
But what I'm going to do is just protect everything.
[119]
So the next thing is what data do you want to find.
[122]
So they already selected it already for if this template I'm leverage
[125]
but if you do have other criteria,
[127]
you can go here and find that information.
[129]
And then, the next option allows you to select
[132]
"Do you only want to apply this policy to people outside the organization
[136]
or only with people inside the organization."
[138]
So you can definitely do that and then you have some other areas that you can configure
[142]
when you're going to use advance settings.
[144]
We're not going to be covering that in this video.
[145]
The next thing they want you to think about is "What do you want to do if we detect sensitive information?"
[153]
So what I want to do, I want to make sure that they notify the users when this policy matches, right.
[158]
The next thing I want to do is,
[159]
I want to say if one piece of this information is received,
[163]
I want you to send me a report
[165]
and I also want you to ensure that they can't send it by blocking it.
[170]
I do have the option of encrypting that message for exchange
[173]
but I just want to block it because I don't want this information to leave my environment.
[177]
2) I want to give my team members or my company employees
[182]
the possibility to override that policy.
[184]
Why would I want to do that?
[185]
Because maybe there's business justification that
[188]
warrants the ability to send that information outside the organization
[192]
and this example, I'm not going to do that.
[195]
I would say, :Hey check the Microsoft documentation for more information...
[199]
and also reach out to your legal team and your compliance team
[203]
to ensure that you're making the right decision right here.
[206]
So just make sure you do that.
[207]
Next is "Do you want to turn it on right away?"
[209]
For this demo purposes, I do want to turn it on right away.
[213]
For you, I probably say if you haven't rolled this out yet
[216]
to test it first and don't show any type of tips when you're testing it
[221]
and then just deploy it to a small subsection of people
[224]
and roll it out in phases to see
[226]
how does it work before you send it out globally to everyone in your company.
[230]
So click 'Next', then we're going to click'Create'.
[232]
Now, let's take a look at the actual demo of blocking a credit card leaving my organization.
[238]
Are you still with me? Are you still listening?
[240]
I know you're pretty attentive right now.
[242]
You locked into your focus.
[244]
So let's go to the next area.
[246]
Now, what I need you to do is go to Office.com or portal.office.com
[252]
and I need you to click on 'Outlook'
[255]
and once you click on 'Outlook',
[256]
let's create a new message.
[258]
Put in external email,
[260]
put in a fake credit our number.
[262]
Let's see what happens when we do this and the first thing you see is says set block this messes includes one or more recipients who aren't authorized to receive sensitive information please remove those recipients and try to send the message again this shows you how quick and easy it was to implement and for it to enforce in your environment so now I don't need to worry if this data is leaving in my environment because I know it's being blocked and I'll be notified so I can see it within my reporting structure to see who is sending this out to ensure that their account isn't compromised now that we learned that let's go to the next steps of what's going to happen in this video series so you made it to the end but the fun does not stop here next week Monday I'll be releasing a new video talking about passing that MS 500 Microsoft 365 security exam it's a hands-on test that gives up a lot of candidates trouble but I'm going to show you and how to pass it and the only way you can get this great information and stay notified is subscribing and also keep the learning going today and watch other videos of my channel until next time have a wonderful evening day or whatever time you're watching this video
[265]
The first thing you see, it says "Set block.
[268]
This message includes one or more recipients who aren't authorized to receive sensitive information."
[275]
Please remove those recipients and try to send the message again.
[280]
This shows you how quick and easy it was to implement
[284]
and for it to enforce in your environment.
[287]
So now, I don't need to worry if this data is leaving in my environment
[291]
because I know it's being blocked and I'll be notified.
[295]
So I can see it within my reporting structure
[297]
to see who is sending this out
[299]
to ensure that their account isn't compromised.
[302]
Now, that we learned that,
[303]
let's go to the next steps of what's going to happen in this video series.
[309]
So you made it to the end
[310]
but the fun does not stop here.
[314]
Next week Monday, I'll be releasing a new video
[317]
talking about passing that MS 500 Microsoft 365 security exam.
[325]
It's a hands-on test that gives up a lot of candidates trouble
[329]
but I'm going to show you and how to pass it.
[332]
And the only way you can get this great information and stay notified,
[336]
is subscribing and also keep the learning going today
[340]
and watch other videos of my channel.
[342]
Until next time, have a wonderful evening day or whatever time you're watching this video