Jump to content

Recommended Posts

Posted

Hi All,

 

I was wondering what people's thoughts are about using Security and Compliance Center to help with mapping where personal data is and helping to prevent it's inappropriate distribution (or at least alerting the user that it's a bad idea).

 

So far I've set up a Data Leak Prevention policy and used all the built-in options for UK Data Protection Act + Credit Card + Debit Card numbers. What else can I do to it to make it a more useful tool? Can I import more 'Sensitive Data Types' from somewhere?

 

I also feel like labels should be useful but can't get my head around how to make it useful.

 

 

Any thoughts appreciated!

Posted

I've taken a look at DLP, but have wondered how useful the built in filters are for us in education. Most of the sensitive data that we will send would be data such as pupi/staff names and information about them.

Has anyone got any examples of how DLP has been used effectively?

Posted

yes, I'm also interested, if I could have keywords looked at (say in attachments) that would alert the sender (or SMT) if any sensitive documents are being sent externally.

 

and any other policies would be nice.

Posted
I've defined a label in Azure AD - Information Protection and want it to be able to be applied to documents manually by people to start with. I have the policy set up, but how does a user add a label to a document in Office Online?
Posted
yes, I'm also interested, if I could have keywords looked at (say in attachments) that would alert the sender (or SMT) if any sensitive documents are being sent externally.

 

and any other policies would be nice.

 

I think keywords is probably the way to go if DLP is to be effective in education. The templates are number formats for credit card numbers, etc. which is great if you're a bank and only dealing with one type of confidential data but obviously isn't so relevant in education with the range of confidential data we process, but if you could make it look for keywords like race, ethnicity, black, Asian, gender, male, female, SEN, autism, EHCP, healthcare, diabetes and so forth, if might work. The number of false positives would be enormous though, so probably best not to block/redirect these emails, just to ask the sender "hang on, are you sure you should be sending this?" as the presence of those words doesn't mean any confidential data is being sent.

Posted
I have to say that it would be great if MS could do a web cast covering this area for Schools? Also I would like to do encrypted e-mail from Office 365.

 

You can do:

 

https://products.office.com/en-gb/exchange/office-365-message-encryption

 

Bit clunky though; you basically have to set up a rule that encrypts anything with particular keywords (like "Encrypt" in the subject line), and unlike some of the other offerings there's no method of revoking the message once sent.

  • Thanks 1
Posted
You can do:

 

https://products.office.com/en-gb/exchange/office-365-message-encryption

 

Bit clunky though; you basically have to set up a rule that encrypts anything with particular keywords (like "Encrypt" in the subject line), and unlike some of the other offerings there's no method of revoking the message once sent.

 

Yup, my rule kicks in if the message is marked as confidential (seemed like a logical thing to do).

Posted
So have you upgraded your subscription? it says you need the e3 subscription. The unlimited subscription I get is only A1 (same reason I cant use the E5 sub security and compliance > data governance > supervision policies)
Posted
Yeah ok I'm stealing this idea.

 

It's included in all 3 Education plans, including A1: https://technet.microsoft.com/en-us/library/mt844095.aspx

 

I'm having a go at getting this working but get the following error when I run the command:

Import-RMSTrustedPublishingDomain -RMSOnline -name "RMS Online"

 

I get this error:

InvalidIssuanceLicenseTemplate
   + CategoryInfo          : NotSpecified: ( [import-RMSTrustedPublishingDomain], RightsManagementException
   + FullyQualifiedErrorId : [server=AM0PR0102MB3106,RequestId=4fb0fd9a-6ab2-4d86-a5b8-6565c5fdceeb,TimeStamp=06/02/2
  018 21:27:30] [FailureCategory=Cmdlet-RightsManagementException] 6191E37C,Microsoft.Exchange.Management.RightsMana
 gement.ImportRmsTrustedPublishingDomain
   + PSComputerName        : outlook.office365.com

 

Can anyone help with what the next step needs to be please?

Posted

Hi All,

 

I thought I'd update this with progress so far. I've been able to complete the setup so far using this article:

 

https://support.office.com/en-us/article/set-up-new-office-365-message-encryption-capabilities-built-on-top-of-azure-information-protection-7ff0c040-b25c-4378-9904-b1b50210d00e

 

I'm going to wait 48 hours for the Outlook on the Web UI to refresh and then I'll have a play and add in some transport rules. This is a great feature that we can use for free. Thanks @djrscally

Posted
No problem. Are you on the new version with the Protect button then? Ours is the old style, works slightly differently (not integrating the Azure Information protection). Is there a way to revoke emails that are sent protected? That's the only feature of things like Egress and GalaxKey that is missing from the O365 version I think.
Posted

Yes I am on the later version built on Azure Information Protection. You still can't revoke sent emails and I believe this is because OME encrypts a file and then sends it to the recipient to then get a licence to decrypt it, whereas I think Egress stores the file on it's servers and people can then access that.

 

I checked later on and found that the protect button had appeared so I tried it out both with the protect button and the transport rules. It works in that it takes an email and adds it as an encrypted attachment but I've tried 2 emails to another O365 address in a different tenancy and they both say I don't have permission to view. Thats with both signing in to office or using a One Time Password. I've tried it on PC and iOS as well as with the outlook iOS app and with iOS Mail/Safari.

Posted
Yes I am on the later version built on Azure Information Protection. You still can't revoke sent emails and I believe this is because OME encrypts a file and then sends it to the recipient to then get a licence to decrypt it, whereas I think Egress stores the file on it's servers and people can then access that.

 

I checked later on and found that the protect button had appeared so I tried it out both with the protect button and the transport rules. It works in that it takes an email and adds it as an encrypted attachment but I've tried 2 emails to another O365 address in a different tenancy and they both say I don't have permission to view. Thats with both signing in to office or using a One Time Password. I've tried it on PC and iOS as well as with the outlook iOS app and with iOS Mail/Safari.

 

Weird. What template does it select? Probably something weird with that.

Posted

I'm having the same issue!

You don't have permission to view this message

 

This message is protected and you don't have permission to view it.

 

Any ideas would be greatly appreciated!

  • Thanks 1
Posted
I'm having the same issue!

You don't have permission to view this message

 

This message is protected and you don't have permission to view it.

 

Any ideas would be greatly appreciated!

I'm still working on it. I thought I'd restricted the transport rule to a small group of dummy accounts but someone emailed me about encrypted USB sticks the other day and now I can't read it because of the above error! Whoops.

  • Thanks 1
Posted
Yes I am on the later version built on Azure Information Protection. You still can't revoke sent emails and I believe this is because OME encrypts a file and then sends it to the recipient to then get a licence to decrypt it, whereas I think Egress stores the file on it's servers and people can then access that.

 

I checked later on and found that the protect button had appeared so I tried it out both with the protect button and the transport rules. It works in that it takes an email and adds it as an encrypted attachment but I've tried 2 emails to another O365 address in a different tenancy and they both say I don't have permission to view. Thats with both signing in to office or using a One Time Password. I've tried it on PC and iOS as well as with the outlook iOS app and with iOS Mail/Safari.

 

We found the same when we were playing with this and we were told that to allow emails to external addresses access you needed the next level of AIP. Nothing would work externally until you did that. We haven't had a chance to try since.

 

Our plan is a bit draconian and we need to have it passed by management but, we are looking at marking all documents as Internal only and then have other levels that allow restrictions removed, mark them as public and make them even more secure. That way an accidentally leaked document is locked but if someone wants to take something off site that is non-sensitive they must make a conscious decision and click through warnings to do it. That way there will be an audit log and they can't deny any knowledge of the policy/what they were doing/someone else must have done it. I do feel it is a bit heavy handed but I can't think of another way to secure the data without having to rely on staff to make a conscious effort.

Posted (edited)
Hi all, reading this forum was really interesting, as far as I am aware DLP keyword filtering on sensitive data is a endless task of false positives. I believe the only real solution to the loss and theft element is to store sensitive data that contains anything which is defined as personally identifiable, IE names, addresses, medical history for students and staff (not just credit card details) in an encrypted format. this means that this data in the cloud, on network or device storage, or even in transit is not accessible by any unauthorized end-users that will cover accidental loss too (e.g copying in the wrong person to the email by accident ) and make sure that your data cant be stolen if the network is hacked at all. Doing what you many of you are talking about wont cover accidental loss and the other DLP email rules and key word filtering will block a huge amount of legitimate emails being sent on a daily basis and cause uproar from the internal staff. Edited by KD1987
Posted
I'm still working on it. I thought I'd restricted the transport rule to a small group of dummy accounts but someone emailed me about encrypted USB sticks the other day and now I can't read it because of the above error! Whoops.

 

I'm coming back to working on this problem. I've raised a support request with MS and will update when (if) I make some progress.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...