ASD's Blueprint for Secure Cloud

Data Loss Prevention: Default policy for Teams

This section describes the configuration of Data Loss Prevention (DLP) policies within Microsoft Purview associated with systems built according to guidance in ASD's Blueprint for Secure Cloud.

Estimated reading time: 3 minutes

Name

ItemValue
NameDefault policy for Teams
DescriptionThis policy detects the presence of credit card numbers in Teams chats and channel messages. When this sensitive info is detected, admins will receive an alert but policy tips won’t be displayed to users. You can edit these actions at any time.

Admin units

ItemValue
Admin unitsFull directory

Locations

ItemValue
Exchange email
SharePoint sites
OneDrive accounts
Teams chat and channel messagesAll users and groups
Devices
Instances
On-premises repositories
Power BI workspaces

Advanced DLP rules

Default Teams DLP policy rule

ItemValue
NameDefault Teams DLP policy rule
DescriptionThis rule detects the presence of one or more credit card numbers. Admins will be alerted in email when 10 or more instances are detected within a 24-hour period for all users.
Conditions

Content contains

ItemValue
Group nameDefault
Group operatorAny of these
Sensitive info types
Credit Card NumberHigh confidence
Instance count: 1 to Any
Actions

None

User notifications
ItemValue
Use notifications to inform your users and help educate them on the proper use of sensitive infoFalse
User overrides
ItemValue
Allow overrides from M365 servicesFalse
Incident reports
ItemValue
Use this severity level in admin alerts and reportsLow
Send an alter to admins when a rule match occurs
Use email incident reports to notify you when a policy match occursChecked
Send notifications to these peopleSiteAdmin
You can also include the following information in the report:
The name of the person who last modified the contentChecked
The types of sensitive content that matched the ruleChecked
The rule’s severity levelChecked
The content that matched the rule, including the surrounding textNot checked
The item containing the content that matched the ruleNot checked
Additional options
ItemValue
If there’s a match for this rule, stop processing additional DLP policies and rulesNot checked
Priority0

Policy mode

ItemValue
Policy modeTurn the policy on immediately

Security & Governance

  • None identified

Design

  • None identified

Configuration

  • None identified

References

  • None identified

Do you have a suggestion on how the above page could be improved? Get in touch! ASD's Blueprint for Secure Cloud is an open source project, and we would love to get your input. Submit an issue on our GitHub, or send us an email at blueprint@asd.gov.au

Acknowledgement of Country icon

Acknowledgement of Country
We acknowledge the Traditional Owners and Custodians of Country throughout Australia and their continuing connections to land, sea and communities. We pay our respects to them, their cultures and their Elders; past, present and emerging. We also recognise Australia's First Peoples' enduring contribution to Australia's national security.

Authorised by the Australian Government, Canberra