ASD's Blueprint for Secure Cloud

Data Loss Prevention: Default policy for devices

This section describes the configuration of Data Loss Prevention (DLP) policies within Microsoft Purview associated with systems built according to guidance in ASD's Blueprint for Secure Cloud.

Estimated reading time: 4 minutes

Name

ItemValue
NameDefault policy for devices
DescriptionThis policy detects the presence of credit card numbers in files on devices when users perform specific activities (such as printing a file). When detected, the activity is only audited (not blocked). Admins will receive an alert, but policy tips won’t be displayed to users. You can edit these actions at any time.

Admin units

ItemValue
Admin unitsFull directory

Locations

ItemValue
Exchange email
SharePoint sites
OneDrive accounts
Teams chat and channel messages
DevicesAll users and groups
Instances
On-premises repositories
Power BI workspaces

Advanced DLP rules

Default Endpoint DLP Policy Rule - Low Volume

ItemValue
NameDefault Endpoint DLP Policy Rule - Low Volume
DescriptionThis rule is matched if 1 to 9 credit card numbers are detected in a file when a user performs certain device-related activities. When detected within a 24-hour period, the activity is only audited (not blocked). Admins won’t receive alerts.
Conditions

Content contains

ItemValue
Group nameDefault
Group operatorAny of these
Sensitive info types
- Credit Card NumberHigh confidence
Instance count: 1 to 9
Actions

Audit or restrict activities on devices

ItemValue
Service domain and browser activities
Upload to a restricted cloud service domain or access from an unallowed browsersChecked
Audit only
Paste to supported browsers
File activities for all apps
Apply restrictions to specific activityChecked
Copy to ClipboardChecked
Audit only
Copy to removable USB deviceChecked
Audit only
Copy to a network shareChecked
Audit only
PrintChecked
Audit only
Copy or move using unallowed Bluetooth appChecked
Audit only
Copy or move using RDPChecked
Audit only
Restricted app activities
Access by restricted appsChecked
Audit only
User notifications
ItemValue
Use notifications to inform your users and help educate them on the proper use of sensitive infoOff
User overrides
ItemValue
Allow overrides from M365 servicesNot checked
Business justificationNot checked
Incident reports
ItemValue
Use this severity level in admin alerts and reportsLow
Send an alert to admins when a rule match occursOff
Additional options
ItemValue
If there’s a match for this rule, stop processing additional DLP policies and rulesNot checked
Priority0

Default Endpoint DLP Policy Rule - High Volume

ItemValue
NameDefault Endpoint DLP Policy Rule - High Volume
DescriptionThis rule is matched if 10 or more credit card numbers are detected in a file when a user performs certain device-related activities. When detected within a 24-hour period, the activity is only audited (not blocked), and admins will be alerted in email.
Conditions

Content contains

ItemValue
Group nameDefault
Group operatorAny of these
Sensitive info types
- Credit Card NumberHigh confidence
Instance count: 10 to Any
Actions

Audit or restrict activities on devices

ItemValue
Service domain and browser activities
Upload to a restricted cloud service domain or access from an unallowed browsersChecked
Audit only
Paste to supported browsers
File activities for all apps
Apply restrictions to specific activityChecked
Copy to ClipboardChecked
Audit only
Copy to removable USB deviceChecked
Audit only
Copy to a network shareChecked
Audit only
PrintChecked
Audit only
Copy or move using unallowed Bluetooth appChecked
Audit only
Copy or move using RDPChecked
Audit only
Restricted app activities
Access by restricted appsChecked
Audit only
User notifications
ItemValue
Use notifications to inform your users and help educate them on the proper use of sensitive infoOff
User overrides
ItemValue
Allow overrides from M365 servicesNot checked
Business justificationNot checked
Incident reports
ItemValue
Use this severity level in admin alerts and reportsMedium
Send an alert to admins when a rule match occursOff
Additional options
ItemValue
If there’s a match for this rule, stop processing additional DLP policies and rulesNot checked
Priority1

Policy mode

ItemValue
Policy modeTurn the policy on immediately

Security & Governance

  • None identified

Design

  • None identified

Configuration

  • None identified

References

  • None identified

Do you have a suggestion on how the above page could be improved? Get in touch! ASD's Blueprint for Secure Cloud is an open source project, and we would love to get your input. Submit an issue on our GitHub, or send us an email at blueprint@asd.gov.au

Acknowledgement of Country icon

Acknowledgement of Country
We acknowledge the Traditional Owners and Custodians of Country throughout Australia and their continuing connections to land, sea and communities. We pay our respects to them, their cultures and their Elders; past, present and emerging. We also recognise Australia's First Peoples' enduring contribution to Australia's national security.

Authorised by the Australian Government, Canberra