cancel
Showing results for 
Search instead for 
Did you mean: 
Reply
Highlighted
Responsive Resident
Responsive Resident

DLP seems easy to circumvent via a separate tenant?

TenantA has a DLP with SharePoint in "Business Data Only". This means that users in TenantA cannot email content from SharePont via Flow. This is good.

 

TenantA creates an account for a consultant, Sam. Sam also has an account in a TenantB. Sam creates a flow in his TenantB that connects to SharePoint in TenantA, which emails content from SharePoint. Sam's Flow wouldn't be subject to the DLP, because the Flow is running in TenantB.

 

We also have a separate tenant for developers for them to build/test. They're in charge of that tenant, and so they can also ignore any DLP policies in the main tenant, right?

 

So, what do we actually accomplish by configuring DLP? Is there a way for admins to block users from emailing business data, or posting it to Twitter, via flow?

 

 

 

2 REPLIES 2
Highlighted
Community Support
Community Support

Re: DLP seems easy to circumvent via a separate tenant?

Hi @Mike2500,

 

Thanks for your feedback. A DLP is applied to one or more environments which are created by a tenant. The DLP takes effect in one or more environments which are created by a tenant. The DLP is created in TenantA is not effective in TenantB.

 

More details about Data Loss Prevention Policies, please check the following document:

Introducing Data Loss Prevention Policies in Microsoft Flow

 

Best regards,

Kris

Community Support Team _ Kris Dai
If this post helps, then please consider Accept it as the solution to help the other members find it more quickly.
Highlighted
Responsive Resident
Responsive Resident

Re: DLP seems easy to circumvent via a separate tenant?

So is this a bug in the software, or does the documentation need to be udpated? According to the docs:

 

"Benefits of a DLP policy
Ensures that data is managed in a uniform manner across the organization
Prevents important business data from being accidentally published to services such as social media sites."

 

But because of the issue I pointed out with tenants, these benefits don't actually exist. 

Helpful resources

Announcements
firstImage

Now Live: Power Virtual Agents Community!

We are excited to announce the launch of Power Virtual Agents Community. Check it out now!

firstImage

New & Improved Power Automate Community Cookbook

We've updated and improved the layout and uploading format of the Power Automate Cookbook!

thirdimage

Power Automate Community User Group Member Badge

Fill out a quick form to claim your user group badge now!

Top Solution Authors
Top Kudoed Authors
Users online (5,934)