Outlook: Import support for data files in Outlook

🚨 The Signal: Outlook for Mac now supports importing PST files and importing/exporting OLM files. This increases the risk of uncontrolled data ingress/egress, potentially bypassing data loss prevention (DLP) and eDiscovery controls.

The Impact

Security teams and data owners are affected by increased risk of data exfiltration and unmanaged data ingress.

  • Security teams face challenges in monitoring and controlling data flow.
  • Data owners risk sensitive information leaving managed environments.
  • Compliance officers may struggle to meet eDiscovery and retention obligations.
  • Incident responders could have difficulty tracing data breaches involving PST/OLM files.

The Action

  1. Review and update Microsoft Purview DLP policies to specifically address PST/OLM file transfers.
  2. Implement or strengthen endpoint DLP solutions to monitor and block unapproved PST/OLM operations.
  3. Educate users on acceptable data handling practices and the risks of unmanaged data files.
  4. Assess existing eDiscovery processes for their ability to ingest and search PST/OLM content from endpoints.

Impact: high · Workload: M365 Apps