Outlook: Import support for data files in Outlook
🚨 The Signal: Outlook for Mac now supports importing PST files and importing/exporting OLM files. This increases the risk of uncontrolled data ingress/egress, potentially bypassing data loss prevention (DLP) and eDiscovery controls.
The Impact
Security teams and data owners are affected by increased risk of data exfiltration and unmanaged data ingress.
- Security teams face challenges in monitoring and controlling data flow.
- Data owners risk sensitive information leaving managed environments.
- Compliance officers may struggle to meet eDiscovery and retention obligations.
- Incident responders could have difficulty tracing data breaches involving PST/OLM files.
The Action
- Review and update Microsoft Purview DLP policies to specifically address PST/OLM file transfers.
- Implement or strengthen endpoint DLP solutions to monitor and block unapproved PST/OLM operations.
- Educate users on acceptable data handling practices and the risks of unmanaged data files.
- Assess existing eDiscovery processes for their ability to ingest and search PST/OLM content from endpoints.
Impact: high · Workload: M365 Apps