Create a DLP policy in SharePoint Server 2016

Create a DLP policy in SharePoint Server 2016 With a data loss prevention (DLP) policy in SharePoint Server 2016, you can...

Create a DLP policy in SharePoint Server 2016

With a data loss prevention (DLP) policy in SharePoint Server 2016, you can identify, monitor, and automatically protect sensitive information across your SharePoint site collections.

For example, you can quickly create a DLP policy that:

  • Identifies different types of sensitive information that need to be protected under common industry regulations, such as the U.K. Data Protection Act or U.S. State Breach Notification Laws.

  • Displays a policy tip to users in the document library if they save a document that contains sensitive information such as credit card numbers or social security numbers.

  • Automatically blocks access to those documents for everyone but the site owner, content owner, and whoever last modified the document.

  • Allows people to override the blocking action, so that they can continue to work with documents if they have a business justification or are receiving a false positive. Policy tips can help educate your organization about your DLP policies without preventing people from getting their work done.

  • Sends an incident report to the compliance officer with details about any content that matches a DLP policy.

For more information about DLP, see Overview of data loss prevention in SharePoint Server 2016.

Before you begin

You create DLP policies in the Compliance Policy Center, a site collection where you can use permissions to control who can create and manage these policies. First you need to create the Compliance Policy Center site collection, and then add users to the site collection.

We recommend that you create a security group for your compliance team, and then add the appropriate users to the security group. Then you can grant permissions to the security group, instead of to individual users.

Step 1: Create the Compliance Policy Center

An admin with permissions to Central Administration needs to create the Compliance Policy Center site collection.

  1. In Central Administration > Application Management > Create site collections.

  2. On the Create Site Collection page, fill out the form, including these options:

    • Under Template Selection > Enterprise tab > select the Compliance Policy Center template.

          Create a DLP policy in SharePoint Server  Create a DLP policy in SharePoint Server 2016

    • Enter a primary and secondary site collection administrator. These people can add users to the Compliance Policy Center site collection as described next.

Step 2: Grant permissions to the Compliance Policy Center

A site collection admin needs to add users to the Compliance Policy Center site collection. You typically want to add users to the Members group. Members can use the Compliance Policy Center to create and assign DLP policies, but they aren't in the Owners group, so they can't add or remove other users or change their permissions.

  1. Go to the Compliance Policy Center site collection > choose Settings (gear icon) in the upper right > Site Settings.

  2. On the Site Settings page > under Users and Permissions > Site permissions.

  3. Select the Compliance Policy Center Members group > on the Ribbon, choose Grant Permissions > enter the security group or users > Share.

        Create a DLP policy in SharePoint Server  Create a DLP policy in SharePoint Server 2016

Step 1: Create a DLP policy

After you create the Compliance Policy Center and add users to it, you're ready to create a DLP policy. It's a two-step process: first you create the policy, and then you assign the policy to one or more site collections where you want to protect sensitive information.

  1. Go to the Compliance Policy Center site collection > in the left navigation, choose DLP Policy Management.

        Create a DLP policy in SharePoint Server  Create a DLP policy in SharePoint Server 2016

  2. Choose new item.

  3. Under New DLP Policy > choose from these options:

    1. Enter a name for the policy.

    2. Choose the template that corresponds to the common regulatory requirement for which you need to protect sensitive information. Each DLP template identifies and helps protect specific types of sensitive information – for example, the template named U.S. Financial Data identifies content that contains ABA Routing Numbers, Credit Card Numbers, or U.S. Bank Account Numbers.

    3. Enter a number that determines the minimum number of instances of a specific type of sensitive information that must appear in a document before the protective actions are automatically taken (send an incident report, show a policy tip, block access).

      For example, if you select the U.S. Financial Data template and enter 10 here, no action will be taken unless a document contains at least 10 ABA routing numbers, 10 credit card numbers, or 10 U.S. bank account numbers. The minimum count is for each type of sensitive information, not a total of all of them.

    4. Enter a valid email address (typically a compliance officer) to which an incident report is sent when a DLP policy is matched. This report includes details about the detected content such as the title, document owner, and what sensitive information was detected. To enter multiple addresses, separate each with a semicolon (;).

    5. Notify the user with a policy tip when documents that contain sensitive information are saved or edited. The policy tip appears on a document on the site and explains why that document conflicts with a DLP policy, so that people can take remedial action, such as removing the sensitive information from the document. When the document is in compliance, the policy tip disappears.

    6. Block access to the content for everyone except the site owner, document owner, and person who last modified the document. These people can remove the sensitive information from the document or take other remedial action. When the document is in compliance, the original permissions will be automatically restored. It's important to understand that the policy tip gives people the option to override the blocking action. Policy tips can thus help educate users about your DLP policies and enforce them without preventing people from doing their work.

        Create a DLP policy in SharePoint Server  Create a DLP policy in SharePoint Server 2016

  4. When finished, choose Save.

Step 2: Assign the DLP policy to a site collection

After you create a DLP policy, you need to assign it to one or more site collections where you want to protect sensitive information. A single DLP policy can be assigned to multiple site collections, but you need to create each assignment separately, one for each site collection. Unlike document deletion policies, DLP policies cannot be assigned to a site collection template.

  1. Go to the Compliance Policy Center site collection > in the left navigation, choose DLP Policies > DLP Policy Assignments for Site Collections.

        Create a DLP policy in SharePoint Server  Create a DLP policy in SharePoint Server 2016

  2. Choose new item.

  3. Choose First choose a site collection > search for the title or URL of the site collection > select a single site collection > Save.

    Tip: When you search for site collections, you can use the asterisk (*) wildcard when searching for the title of a search collection. For example, searching for *site* returns both the "Content site" and "Default Publishing Site" site collections. Also, entering just a single asterisk in the search box and then searching is a quick way to see many (but not all) of the site collections.

        Create a DLP policy in SharePoint Server  Create a DLP policy in SharePoint Server 2016

  4. Choose Manage Assigned Policies > select a DLP policy > Save.

        Create a DLP policy in SharePoint Server  Create a DLP policy in SharePoint Server 2016

  5. When finished, choose Save.

Edit a DLP policy

You can edit a DLP policy at any time.

  1. Go to the Compliance Policy Center site collection > in the left navigation, choose DLP Policy Management.

  2. Select the title of the policy you want to edit > make any changes > Save.

Turn off a DLP policy by deleting the policy assignment

To turn off a DLP policy for a specific site collection, you need to delete the DLP policy assignment. When you delete a policy assignment, the policy will no longer apply to the site collection.

  1. Go to the Compliance Policy Center site collection > in the left navigation, choose DLP Policies > DLP Policy Assignments for Site Collections.

  2. Select the policy assignment > More options … > Delete Item.

Delete a DLP policy

  1. Go to the Compliance Policy Center site collection > in the left navigation, choose DLP Policy Management.

  2. Select the policy > on the Ribbon > Items tab > Delete Item.

More information

Disclaimer : All images and content that you find here are believed to be in the "public domain". We do not intend to violate legitimate intellectual property, artistic rights or copyright. If you are the legitimate owner of one of the images and content posted on this site, and do not want to be displayed or if you need an appropriate credit, please contact us and we will immediately do whatever is needed by deleting or giving credit to the content displayed.

COMMENTS

Name

Google Aррѕ,1,lainnya,7522,Microsoft Access,1,Microsoft Excel,59,Microsoft Office,13,Microsoft Office 2003,4,Microsoft Office 2007,1,Microsoft Outlook,1,Microsoft Word,71,Mісrоѕоft Office Training,1,Mісrоѕоft Offісе 365,2,Office 2007,3,Power Map,1,PowerPoint,14,Windows Accessibility Options,1,
ltr
item
Microsoft Office Online: Create a DLP policy in SharePoint Server 2016
Create a DLP policy in SharePoint Server 2016
https://support.content.office.net/en-us/media/2145fb0a-f400-4000-9c3b-282579bccbab.png
Microsoft Office Online
https://promisestoread.blogspot.com/2018/10/create-dlp-policy-in-sharepoint-server.html
https://promisestoread.blogspot.com/
https://promisestoread.blogspot.com/
https://promisestoread.blogspot.com/2018/10/create-dlp-policy-in-sharepoint-server.html
true
593202333244584315
UTF-8
Loaded All Posts Not found any posts VIEW ALL Readmore Reply Cancel reply Delete By Home PAGES POSTS View All RECOMMENDED FOR YOU LABEL ARCHIVE SEARCH ALL POSTS Not found any post match with your request Back Home Sunday Monday Tuesday Wednesday Thursday Friday Saturday Sun Mon Tue Wed Thu Fri Sat January February March April May June July August September October November December Jan Feb Mar Apr May Jun Jul Aug Sep Oct Nov Dec just now 1 minute ago $$1$$ minutes ago 1 hour ago $$1$$ hours ago Yesterday $$1$$ days ago $$1$$ weeks ago more than 5 weeks ago Followers Follow THIS PREMIUM CONTENT IS LOCKED STEP 1: Share. STEP 2: Click the link you shared to unlock Copy All Code Select All Code All codes were copied to your clipboard Can not copy the codes / texts, please press [CTRL]+[C] (or CMD+C with Mac) to copy