Microsoft Purview Data Protection – Configure the Sensitive Service Domain Groups

A common method for data to exit an organization’s control is through third-party cloud storage locations such as Dropbox or Google Drive.  To support the control of this, it is possible to create Data Loss Prevention (DLP) policies that monitor when data is moved to these locations.  The DLP policies can even block the content uploaded to these locations should the organization determine this is necessary to protect their environment.  In this post, we’ll cover the steps to configure Purview’s DLP settings that can assist administrators in monitoring and blocking content being moved to third-party cloud storage by demonstrating how to configure the Sensitive service domain groups section of DLP.

As always, please be aware of my blog disclaimer

Configure the Sensitive Service Domain Groups

The configuration to be made is to be done within the settings section of the Purview Data Loss Prevention solution.  Fair warning if you haven’t been in the settings before; there are a lot of settings to choose from.  Specifically, the category we are looking for is “Browser and domain restrictions to sensitive data“.  You will also need one of the following roles:

  • Global Adminstrator
  • Compliance administrator
  • Compliance data administrator
  • Information Protection
  • Information Protection Admin
  • Security administrator
  1. Login to Microsoft Purview (https://purview.microsoft.com).
  2. Click on the settings cog (top right-hand corner) and select Data Loss Prevention.

Configure the Sensitive Service Domain Groups - DLP Settings in Purview

  1. Next, scroll down and click on Browser and domain restrictions to sensitive data.

Configure the Sensitive Service Domain Groups - Browser and domain restrictions

  1. There are three components to this category:
    • Unallowed browsers: Allows for specific browsers to access sensitive data within the organization.
    • Service domains: Blocks (or Allows for a safelist scenario) specific domains from accessing sensitive data.  This is limited to Microsoft Edge and Chrome with Purview extension
    • Sensitive service domain groups: Similar to Service domains, but is used for DLP policies.  This is the selection we will be configuring.
  2. Under Sensitive service domain groups, click on “+ Create sensitive service domain group”

Configure the Sensitive Service Domain Groups - Sensitive service domain groups

  1. Provide a meaningful name to the group.
  2. Add the URL of the location to monitor, ensure the match type is URL, and click Add site.
  3. Repeat the above step for as many items as you wish to monitor.

Configure the Sensitive Service Domain Groups - Add Storage Location to Group

  1. Click Save

Once you have added the necessary sensitive service domains, you can use them in a Purview DLP policy.

 

Thanks for reading!!


I’d love to share regularly with you!

Subscribe to get the latest posts sent to your email.

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *