What problem does it solve?
Sensitive data such as PII, PHI, and PCI can leave an organization through everyday endpoint activities like USB copies, cloud uploads, webmail pastes, and printing. This Skill guides the deployment of endpoint Data Loss Prevention controls that detect and block unauthorized data movement while meeting GDPR, HIPAA, and PCI DSS requirements.
Core Features & Use Cases
- Sensitive Information Type Definition: Configure built-in and custom SITs (credit cards, SSNs, employee IDs) with regex patterns, confidence levels, and corroborating keywords.
- Policy Creation & Channel Coverage: Build Microsoft Purview or Symantec DLP policies covering USB, cloud upload, network share, print, clipboard, unallowed browsers, and Remote Desktop copy.
- Phased Enforcement & Monitoring: Deploy in audit mode, tune false positives via Activity Explorer, then enforce blocking while tracking override rates and incident response.
- Use Case: A security team seeds a test file containing five credit card numbers, then attempts USB copy, personal OneDrive upload, and webmail paste from a test endpoint to verify each channel produces a block event with the matched SIT.
Quick Start
Ask the assistant to walk you through creating a Microsoft Purview endpoint DLP policy that blocks credit card data from being copied to USB drives and personal cloud storage.