Outlook: Insert Signature Image from OneDrive
🚨 The Signal: Outlook users can now embed signature images directly from OneDrive. This expands potential data exfiltration vectors and complicates data loss prevention (DLP) enforcement for sensitive images.
The Impact
All users are affected, increasing the risk of sensitive image data being inadvertently or maliciously embedded in email signatures and exfiltrated.
- End Users: Risk of accidental sharing of sensitive images via signatures.
- Security Teams: Increased complexity in monitoring and preventing data exfiltration.
- Compliance Teams: New challenge in enforcing data handling policies for images.
- IT Administrators: Potential for unapproved images in signatures, impacting brand.
The Action
- Review existing Microsoft Purview DLP policies for 'Image' sensitive info types and 'OneDrive' locations.
- Consider creating new DLP policies to detect and block sensitive images in email signatures.
- Educate users on appropriate content for email signatures and the risks of embedding sensitive images.
- Evaluate Microsoft Entra Conditional Access policies for OneDrive access in conjunction with Outlook.
Domain: Purview · Impact: high · Workload: OneDrive