The most effective DLP suite for Microsoft environments
Use Cases and Deployment Scope
I oversee our Information Security program and utilize Microsoft Purview to govern and enforce aspects of our Data Security including data discovery, data classification, data retention, and data loss prevention. As an E5 customer, Microsoft Purview is included and has strong integration into the Microsoft ecosystem. We utilize it to scan our files stores including OneDrive, SharePoint, Teams, and Email as well as data stores within Azure. The product comes with built in classifiers to detect sensitive content (e.g. SIN/SSN, financial information, health information, etc...). It also allows trainable classifiers to be created to detect content that is proprietary to organizations.
There are multiple levels of DLP controls which can be applied at various points in the data path to reduce risk of unwanted data disclosure, or malicious exfiltration.
Pros
- Extensive library for data content classifiers.
- Strong integration with Microsoft products allowing effective controls to be applied (e.g. Exchange/M365 for email, Microsoft Defender for Cloud Apps to control web, SharePoint/OneDrive to apply policies on sharing.)
- Insider Risk module provides visibility into suspicious activities which may not be detected by regular DLP rules.
Cons
- Requires a lot of time to configure. This is not unique to Purview DLP, but new customers should anticipate this and allocate sufficient time and resources to plan for a successful deployment.
- Steep learning curve. There are a lot of sections, pages, and tabs which need to be configured. Learning where to find these and what each setting does will require subject matter expertise.
- Integration with Microsoft Defender suite is lacking. Purview is designed for Data Governance, Compliance, and Privacy. For this reason, it makes sense to be standalone; however, the DLP modules should have stronger integration into the Microsoft Defender console where Security teams spend the bulk of their time.
Likelihood to Recommend
I would highly recommend Microsoft Purview Data Loss Prevention for companies that are utilizing Microsoft technologies based on the strong integrations.
If a company is using other technologies (e.g Google Workspace), then Microsoft Purview Data Loss Prevention would not be a good fit and would be difficult to implement/manage.
