Microsoft Purview: Data Loss Prevention - Data Security for non-Microsoft connected apps

🚨 The Signal: Purview Data Loss Prevention (DLP) and auto-labeling now protect sensitive data in non-Microsoft cloud apps like Google Workspace and Salesforce. This extends data security policies beyond Microsoft 365, reducing data exfiltration risks across your SaaS estate.

The Impact

Security teams are affected by new configuration options, reducing the risk of sensitive data loss in third-party cloud applications.

  • Security Teams: Reduced risk of data exfiltration from non-Microsoft SaaS apps.
  • Compliance Teams: Improved ability to meet data protection regulatory requirements.
  • IT Admins: New configuration tasks for connecting and managing third-party app DLP.
  • End Users: Consistent data protection experience across more cloud applications.

The Action

  1. Review existing Purview DLP policies for applicability to non-Microsoft apps.
  2. Configure new connectors for relevant third-party cloud applications in Purview.
  3. Create or update DLP policies to include non-Microsoft app locations.
  4. Test DLP policies with sample sensitive data in connected third-party apps.
  5. Monitor DLP alerts and incidents from non-Microsoft connected applications.

Domain: Purview · Impact: high · Workload: Microsoft Purview