ASD's Blueprint for Secure Cloud

Block PROTECTED emails except for approved domains

This section describes the configuration of Data Loss Prevention policies within Microsoft Purview associated with systems built according to guidance in ASD's Blueprint for Secure Cloud.

Estimated reading time: 5 minutes

Name

Name your DLP policy

ItemValue
NameBlock PROTECTED emails except for approved domains
DescriptionBlock emails with PROTECTED labels (including SH and IMM variants) if either the sending or the receiving domain has not been explicitly allowed

Admin units

Assign admin units

ItemValue
Admin unitsFull directory

Locations

Choose where to apply the policy

ItemValue
Exchange emailAll groups
SharePoint sitesNot checked
OneDrive accountsNot checked
Teams chat and channel messagesNot checked
DevicesNot checked
InstancesNot checked
On-premises repositoriesNot checked
Fabric and Power BI workspacesNot checked
Microsoft 365 Copilot (preview)Not checked

Policy settings

ItemValue
Define policy settingsCreate or customize advanced DLP rules

Advanced DLP rules

Block unapproved recipient domains
ItemValue
NameBlock unapproved recipient domains
DescriptionNone
Conditions
Content contains
- Group nameDefault
- Group operatorAny of these
- Sensitivity labelsSelect all PROTECTED labels
- Evaluate predicate for (available for Exchange workload only)Message or attachment
Condition group AND
NOT
Conditions
Recipient domain is<external organisation's domains used for email>
<your organisation's domains used for email>
Actions
Restrict access or encrypt the content in Microsoft 365 locationsBlock users from receiving email, or accessing shared SharePoint, OneDrive, and Teams files, and Power BI items.
Block everyone.
User notificationsOn
Email notificationsChecked
- Notify the user who sent, shared, or last modified the content.Selected
- Attach matching email message to the notification (applies only to Exchange)Checked
Policy tipsChecked
- Customize the policy tip textChecked
Your attempt to email PROTECTED information will be blocked. If you believe this is in error, please contact <support@organisation.gov.au>.
- Show the policy tip as a dialog for the end user before send (available for Exchange workload only)Checked
- Upload a JSON file containing custom content that will be used in the pop-up dialogNot checked
- Provide a compliance URL for the end user to learn more about your organization’s policies (available for Exchange workload only)Not checked
User overrides
Allow overrides from M365 servicesNot checked
Incident reports
Use this severity level in admin alerts and reportsMedium
Send an alert to admins when a rule match occurs.On
Send alert every time an activity matches the ruleSelected
Use email incident reports to notify you when a policy match occurs.Off
Additional options
If there’s a match for this rule, stop processing additional DLP policies and rules.Not checked
Evaluate rule per component (Email body and each individual attachment will be considered an individual entity for rule evaluation)Off
Priority0
Block unapproved sender domains
ItemValue
NameBlock unapproved sender domains
DescriptionNone
Conditions
Content contains
- Group nameDefault
- Group operatorAny of these
- Sensitivity labelsSelect all PROTECTED labels
- Evaluate predicate for (available for Exchange workload only)Message or attachment
Condition group AND
NOT
Conditions
Sender domain is<external organisation's domains used for email>
<your organisation's domains used for email>
Actions
Restrict access or encrypt the content in Microsoft 365 locationsBlock users from receiving email, or accessing shared SharePoint, OneDrive, and Teams files, and Power BI items.
Block everyone.
User notificationsOn
Email notificationsChecked
- Notify the user who sent, shared, or last modified the content.Selected
- Attach matching email message to the notification (applies only to Exchange)Checked
Policy tipsChecked
- Customize the policy tip textChecked
Your attempt to email PROTECTED information will be blocked. If you believe this is in error, please contact <support@organisation.gov.au>.
- Show the policy tip as a dialog for the end user before send (available for Exchange workload only)Checked
- Upload a JSON file containing custom content that will be used in the pop-up dialogNot checked
- Provide a compliance URL for the end user to learn more about your organization’s policies (available for Exchange workload only)Not checked
User overrides
Allow overrides from M365 servicesNot checked
Incident reports
Use this severity level in admin alerts and reportsMedium
Send an alert to admins when a rule match occurs.On
Send alert every time an activity matches the ruleSelected
Use email incident reports to notify you when a policy match occurs.Off
Additional options
If there’s a match for this rule, stop processing additional DLP policies and rules.Not checked
Evaluate rule per component (Email body and each individual attachment will be considered an individual entity for rule evaluation)Off
Priority1

Policy mode

ItemValue
Policy modeTurn the policy on immediately

Security & Governance

  • None identified

Design

Configuration

  • None identified

References

Do you have a suggestion on how the above page could be improved? Get in touch! ASD's Blueprint for Secure Cloud is an open source project, and we would love to get your input. Submit an issue on our GitHub, or send us an email at blueprint@asd.gov.au

Acknowledgement of Country icon

Acknowledgement of Country
We acknowledge the Traditional Owners and Custodians of Country throughout Australia and their continuing connections to land, sea and communities. We pay our respects to them, their cultures and their Elders; past, present and emerging. We also recognise Australia's First Peoples' enduring contribution to Australia's national security.

Authorised by the Australian Government, Canberra