M365SPO-005: DLP policy configuration

Platform
Entra ID / M365
Category
SharePoint & OneDrive Security
Severity
High
Zero Trust pillar
Data (weight 2)
Golden fixtures
3
Branch coverage
Observed: fixtures prove the verdicts they exercise
Provenance
baseline

What it checks

Data Loss Prevention policies in SharePoint Online and OneDrive detect and protect sensitive information such as personally identifiable information, financial data, and health records from being shared inappropriately. Without DLP policies, users can inadvertently share documents containing sensitive data with external users or through unmonitored channels. DLP policies provide automated detection, user notification, and blocking of sensitive data exposure.

Recommended value

DLP policies configured for all regulated data types with user notifications and sharing blocks for external sharing of sensitive content

Remediation

Create DLP policies targeting SharePoint Online and OneDrive locations that detect sensitive information types relevant to your regulatory requirements such as PII, PCI, or HIPAA data. Configure policy rules to display user notifications with guidance on proper handling when sensitive content is detected, and block external sharing of documents containing high-sensitivity data. Enable incident reports to notify the compliance team of policy matches and review the DLP activity reports to tune policy accuracy and reduce false positives.

Fixture-proven verdicts

Every verdict below is proven by a golden fixture in the module's gating test suite. This table derives from the last green run; it cannot be edited by hand.

Verdict scenarios for M365SPO-005
ScenarioExpected verdict
cleanPASS
known-badWARN
throttledNot Assessed

Framework mappings

CISA SCuBA
MS.DEFENDER.4.1v1
NIST SP 800-53
AC-4, SC-7