How to create a DLP policy for Exchange Online in M365?
Creating a DLP policy for Exchange Online is essential to prevent the accidental or intentional sharing of sensitive information via email. This automatically detects and blocks sensitive data, such as credit card numbers and confidential documents, from being sent outside your organization.
Here are the step-by-step instructions to set up a data loss prevention policy in Microsoft 365.
Create Custom DLP Policy for Exchange Online
- Sign in to the Microsoft Purview compliance portal and navigate to , then click Create policy.
- Select Custom under the Categories and Custom policy from the Regulations lists. Then click Next.
- Give your policy a name, description, and click Next.
- To apply policy to a specific group of people, select the desired admin units using the Add or remove admin units option, or keep it as a Full directory, then click Next.
- Choose Exchange email and other desired locations you want to apply policy. Then click Next.
- Select the option Create or customize advanced DLP rules and click Next.
- Click Create rule, then give a name and description to the rule.
- Specify the desired criteria that define what kind of data should be flagged by the DLP policy in the Conditions section.
- Add the actions that need to be taken when the rule matches the conditions defined in the Actions section.
- Use the Incident reports section to set up the alert, severity, and threshold to notify when the rule condition is matched.
- Click Save once you have configured required settings and then hit Next.
- Set the policy mode to Run the policy in simulation mode and then click Next.
- Review the policy details and settings, click Submit, and hit Done. Then, perform the events that match the created DLP policy’s conditions.
- Select your DLP policy and click View Simulation. Evaluate its accuracy and effectiveness, then hit the Turn the policy on.
Note: Microsoft provides over 40 built-in policy templates for common industry regulations and compliance, which you can use as-is or customize to meet your specific needs.