WWL Tenants - Terms of use

If you are provided with a tenant as part of an instructor-led training delivery, please note that the tenant is made available for the purpose of supporting the hands-on labs in the instructor-led training.

Tenants should not be shared or used for purposes outside of hands-on labs. The tenant used in this course is a trial tenant and cannot be used or accessed after the class is over and is not eligible for extension.

Tenants must not be converted to a paid subscription. Tenants obtained as part of this course remain the property of Microsoft Corporation, and we reserve the right to obtain access and repossess them at any time.

Lab 2 – Exercise 1 – Implement and manage DLP policies

Joni Sherman, the newly hired Information Security Administrator at Contoso Ltd., has been asked to configure data loss prevention (DLP) policies to help protect sensitive customer data across Microsoft 365. In this lab, you’ll use Microsoft Purview to create and manage DLP policies from templates, customize policy rules, test policies in simulation mode, and configure DLP by using PowerShell.

Tasks:

  1. Create a DLP policy from a template
  2. Create a custom DLP policy in simulation mode
  3. Modify a DLP policy
  4. Create a DLP policy in PowerShell
  5. Activate a policy in simulation mode
  6. Modify policy priority

Estimated time: 60-75 minutes

Task 1 – Create a DLP policy from a template

In this task, you’ll create a DLP policy from a template to help protect personal data stored in SharePoint and OneDrive. Starting from a template gives you a baseline policy with preconfigured rules that you can review and adjust before enforcement.

  1. Log into Client 1 VM (SC-401-CL1) as the SC-401-CL1\admin account.

  2. In Microsoft Edge, navigate to https://purview.microsoft.com and log into the Microsoft Purview portal as Joni Sherman. Sign in as JoniS@WWLxZZZZZZ.onmicrosoft.com (where ZZZZZZ is your unique tenant prefix provided by your lab hosting provider). User account passwords are provided by your lab hosting provider.

  3. Select Solutions > Data Loss Prevention > Policies.

  4. On the Policies page, select + Create policy.

  5. On the What info do you want to protect? page, select Enterprise applications & devices.

  6. On the Start with a template or create a custom policy page, select Privacy under Categories, then select GDPR under Regulations.

  7. Select Next.

  8. On the Name your DLP policy page, keep the default name and description, then select Next.

  9. On the Assign admin units page, select Next.

  10. On the Choose where to apply the policy page, select the locations for SharePoint sites and OneDrive accounts only. If any other locations are selected, deselect them.

  11. Select Next.

  12. On the Define policy settings page, review the settings created by the template, then select Next.

  13. On the Info to protect page, leave the default settings, then select Next.

  14. On the Protection actions page, leave the default settings, then select Next.

  15. On the Customize access and override settings page, select the checkbox for Require a business justification to override, then select Next.

  16. On the Policy mode page, select Run the policy in simulation mode.

  17. Select the checkboxes for Show policy tips while in simulation mode and Turn the policy on if it’s not edited within fifteen days of simulation.

  18. Select Next.

  19. On the Review and finish page, review your settings, then select Submit.

  20. On the New policy created page, select Done.

You’ve created a DLP policy from a template that scans SharePoint and OneDrive content for personal data. The policy runs in simulation mode so you can review matches and user experience before enforcement.

Task 2 – Create a custom DLP policy in simulation mode

In this task, you’ll create a DLP policy in simulation mode that targets credit card numbers in Teams messages. The policy will notify users when they attempt to share sensitive content and allow them to override with justification.

  1. You should still be logged into Client 1 VM (SC-401-CL1) as the SC-401-CL1\admin account, and you should be logged into Microsoft Purview as Joni Sherman.

  2. Select Solutions > Data Loss Prevention > Policies.

  3. On the Policies page, select + Create policy.

  4. On the What info do you want to protect? page, select Enterprise applications & devices.

  5. On the Start with a template or create a custom policy page, select Custom as the category, then select Custom policy under Regulations.

  6. Select Next.

  7. On the Name your DLP policy page enter:

    • Name: DLP - Credit Card Protection
    • Description: Detect and restrict sharing of credit card numbers in Teams messages.
  8. Select Next.

  9. On the Assign admin units page, select Next.

  10. On the Choose where to apply the policy page, enable the location for Teams chat and channel messages only. If any other locations are selected, deselect them.

  11. Select Next.

  12. On the Define policy settings page, select Create or customize advanced DLP rules, then select Next.

  13. On the Customize advanced DLP rules page, select + Create rule.

  14. In the Create rule flyout:
    • In the Name field, enter Credit card information.
  15. Under Conditions, select + Add condition > Content is shared from Microsoft 365.

  16. In the Content is shared from Microsoft 365 section:
    • Select the option for with people outside my organization.
  17. Select + Add condition > Content contains.

  18. In the new Content contains section:
    • Select Add > Sensitive info types.
    • On the Sensitive info types page, search for and select Credit Card Number, then select Add.
  19. Under Actions, select + Add an action > Restrict access or encrypt the content in Microsoft 365 locations.

  20. In the Restrict access or encrypt the content section:
    • Select Block only people outside your organization.
  21. Under User notifications:
    • Turn on the toggle for Use notifications to inform your users and help educate them on the proper use of sensitive info..
    • Select the checkbox for Notify users in Office 365 service with a policy tip.
  22. Under User overrides:
    • Select the checkbox for Allow users to override policy restrictions in Fabric (including Power BI), Exchange, SharePoint, OneDrive, and Teams.
    • Select the checkbox for Require a business justification to override.
  23. Under Incident reports, in the Use this severity level in admin alerts and reports dropdown:
    • Select Low.
  24. At the bottom of the Create rule flyout, select Save.

  25. Back on the Customize advanced DLP rules, select Next.

  26. On the Policy mode page, select Run the policy in simulation mode and select the checkbox for Show policy tips while in simulation mode.

  27. Select Next.

  28. On the Review and finish page, review your settings then select Submit.

  29. On the New policy created page, select Done.

You’ve created a DLP policy that scans Teams content for credit card numbers and allows overrides with business justification.

Task 3 – Modify a DLP policy

In this task, you’ll expand the scope of your existing DLP policy to include Exchange email. This helps ensure consistent protection across additional communication channels.

  1. You should still be logged into Client 1 VM (SC-401-CL1) as the SC-401-CL1\admin account, and you should be logged into Microsoft 365 as Joni Sherman.

  2. You should still be on the Policies page in Microsoft Purview. If not, open Microsoft Edge and navigate to https://purview.microsoft.com. Select Solutions > Data Loss Prevention > Policies.

  3. On the Policies page, select the checkbox for the recently created DLP - Credit Card Protection, then select Edit policy to open the policy configuration.

  4. On the Name your DLP policy page, edit the description to Detect and restrict sharing of credit card numbers in Teams and Exchange messages.

  5. Select Next.

  6. On the Assign admin units page, select Next.

  7. On the Choose where to apply the policy page, select the checkbox for Exchange email to add this location to your DLP policy.

  8. Select Next until you reach the Review and finish page.

  9. Select Submit on the Review and finish page to apply the change you made to the policy.

  10. Once the policy is updated, select Done on the Policy updated page.

You’ve successfully updated the policy to scan email along with Teams messages.

Task 4 – Create a DLP policy in PowerShell

In this task, you’ll create a DLP policy using PowerShell to block sharing of employee IDs via email. This approach demonstrates how to define and enforce policy settings through scripting.

  1. You should still be logged into Client 1 VM (SC-401-CL1) as the SC-401-CL1\admin account.

  2. Open an elevated PowerShell window by right-clicking the Start button in the task bar, then select Terminal (Admin).

  3. Run the Install Module cmdlet in the terminal window to install the latest Exchange Online PowerShell module version:

     Install-Module ExchangeOnlineManagement
    
  4. Confirm the Untrusted repository security dialog with Y for Yes and press Enter. This process might take some time to complete.

  5. Run the Connect-IPPSSession cmdlet to connect to the Security & Compliance PowerShell:

     Connect-IPPSSession
    
  6. Sign in as Joni Sherman JoniS@WWLxZZZZZZ.onmicrosoft.com (where ZZZZZZ is your unique tenant prefix provided by your lab hosting provider) in the Sign in to your account pop-up window. User account passwords are provided by your lab hosting provider.

  7. Run the New-DlpCompliancePolicy cmdlet to create a DLP policy that scans all Exchange mailboxes:

     New-DlpCompliancePolicy -Name "EmployeeID DLP Policy" -Comment "This policy blocks sharing of Employee IDs" -ExchangeLocation All
    
  8. Run the New-DlpComplianceRule cmdlet to add a DLP rule to the DLP policy you created in the previous step. This policy uses the Contoso Employee IDs sensitive info type created in a previous exercise:

     New-DlpComplianceRule -Name "EmployeeID DLP rule" -Policy "EmployeeID DLP Policy" -BlockAccess $true -ContentContainsSensitiveInformation @{Name="Contoso Employee IDs"}
    
  9. Run the Get-DLPComplianceRule cmdlet to review the EmployeeID DLP rule:

     Get-DLPComplianceRule -Identity "EmployeeID DLP rule"
    

You’ve successfully used PowerShell to create a DLP policy that blocks the sharing of employee IDs.

Task 5 – Activate a policy in simulation mode

Now that your DLP policy has been tested in simulation, you’ll activate it to begin enforcing its actions.

  1. You should still be logged into Client 1 VM (SC-401-CL1) as the SC-401-CL1\admin account, and you should be logged into Microsoft 365 as Joni Sherman.

  2. In Microsoft Edge, navigate to DLP policies by going to https://purview.microsoft.com > Solutions > Data Loss Prevention then select Policies from the left sidebar.

  3. On the Policies page, select the DLP - Credit Card Protection policy.

  4. At the bottom of the flyout on the right, select View simulation.

  5. On the simulation page, take a moment to explore:

    • The Simulation overview tab, which shows scanning progress, total matches, and scanning status by location.
    • The Items for review tab, where any predicted matches will appear once available.
    • The Alerts tab, where any alerts triggered in simulation mode would be listed.
  6. After exploring the insights in simulation mode, select Turn the policy on, then Confirm to activate the DLP policy.

    A confirmation flyout will appear indicating that the policy has been published successfully.

The policy is now active and enforcing restrictions on credit card information in Teams and Exchange.

Task 6 – Modify policy priority

When multiple policies exist, their priority determines which one applies first. In this task, you’ll move the employee ID policy to the highest priority.

  1. You should still be logged into Client 1 VM (SC-401-CL1) as the SC-401-CL1\admin account, and you should be logged into Microsoft 365 as Joni Sherman.

  2. In Microsoft Edge, the Microsoft Purview portal tab should still be open to the Policies page. If not, open Microsoft Edge and navigate to https://purview.microsoft.com. Select Solutions > Data Loss Prevention > Policies.

  3. On the Policies page, select the EmployeeID DLP Policy.

  4. Select Reprioritize from the top navigation ribbon, then select Move to top (highest priority).

  5. In the Data loss prevention window, select Refresh and review the priority in the Order column of the policy table.

You’ve updated policy priority so that the employee ID policy takes precedence over others.