ASD's Blueprint for Secure Cloud

Block SECRET and TOP SECRET emails

This section describes the configuration of Data Loss Prevention policies within Microsoft Purview associated with systems built according to guidance in ASD's Blueprint for Secure Cloud.

Estimated reading time: 3 minutes

Name

Name your DLP policy

ItemValue
NameBlock SECRET and TOP SECRET emails
DescriptionBlock emails with a SECRET or TOP SECRET X-Protective-Marking X-header or email subject

Admin units

Assign admin units

ItemValue
Admin unitsFull directory

Locations

Choose where to apply the policy

ItemValue
Exchange emailAll groups
SharePoint sitesNot checked
OneDrive accountsNot checked
Teams chat and channel messagesNot checked
DevicesNot checked
InstancesNot checked
On-premises repositoriesNot checked
Fabric and Power BI workspacesNot checked
Microsoft 365 Copilot (preview)Not checked

Policy settings

ItemValue
Define policy settingsCreate or customize advanced DLP rules

Advanced DLP rules

Block SECRET emails
ItemValue
NameBlock SECRET emails
DescriptionNone
Conditions
Header matches patternsX-Protective-Marking
SEC=SECRET
OR
Subject matches patterns\[SEC=SECRET
Actions
Restrict access or encrypt the content in Microsoft 365 locationsBlock users from receiving email, or accessing shared SharePoint, OneDrive, and Teams files, and Power BI items.
Block everyone.
User notificationsOn
Email notificationsChecked
- Notify the user who sent, shared, or last modified the content.Selected
- Attach matching email message to the notification (applies only to Exchange)Not checked
Policy tipsNot checked
User overrides
Allow overrides from M365 servicesNot checked
Incident reports
Use this severity level in admin alerts and reportsMedium
Send an alert to admins when a rule match occurs.On
Send alert every time an activity matches the ruleSelected
Use email incident reports to notify you when a policy match occurs.Off
Additional options
If there’s a match for this rule, stop processing additional DLP policies and rules.Checked
Evaluate rule per component (Email body and each individual attachment will be considered an individual entity for rule evaluation)Off
Priority0
Block TOP SECRET emails
ItemValue
NameBlock TOP SECRET emails
DescriptionNone
Conditions
Header matches patternsX-Protective-Marking
SEC=TOP SECRET
OR
Subject matches patterns\[SEC=TOP SECRET
Actions
Restrict access or encrypt the content in Microsoft 365 locationsBlock users from receiving email, or accessing shared SharePoint, OneDrive, and Teams files, and Power BI items.
Block everyone.
User notificationsOn
Email notificationsChecked
- Notify the user who sent, shared, or last modified the content.Selected
- Attach matching email message to the notification (applies only to Exchange)Not checked
Policy tipsNot checked
User overrides
Allow overrides from M365 servicesNot checked
Incident reports
Use this severity level in admin alerts and reportsMedium
Send an alert to admins when a rule match occurs.On
Send alert every time an activity matches the ruleSelected
Use email incident reports to notify you when a policy match occurs.Off
Additional options
If there’s a match for this rule, stop processing additional DLP policies and rules.Checked
Evaluate rule per component (Email body and each individual attachment will be considered an individual entity for rule evaluation)Off
Priority0

Policy mode

ItemValue
Policy modeTurn the policy on immediately

Security & Governance

  • None identified

Design

Configuration

  • None identified

References

Do you have a suggestion on how the above page could be improved? Get in touch! ASD's Blueprint for Secure Cloud is an open source project, and we would love to get your input. Submit an issue on our GitHub, or send us an email at blueprint@asd.gov.au

Acknowledgement of Country icon

Acknowledgement of Country
We acknowledge the Traditional Owners and Custodians of Country throughout Australia and their continuing connections to land, sea and communities. We pay our respects to them, their cultures and their Elders; past, present and emerging. We also recognise Australia's First Peoples' enduring contribution to Australia's national security.

Authorised by the Australian Government, Canberra