Skip to Content
SecurityCloud App SecurityCloud DLP

Cloud DLP

Apply Data Loss Prevention policies to cloud applications connected to Microsoft Defender for Cloud Apps.

Note: Requires Microsoft Defender for Cloud Apps with E5 or E5 Compliance license.

Overview

  • Active Policies — DLP policies applied to cloud apps
  • Policy Matches — Content items matching DLP rules
  • Blocked Actions — Sharing or download actions blocked

Supported Apps

AppDLP Capabilities
SharePoint OnlineContent inspection, auto-labeling
OneDriveFile scanning, sharing restrictions
Exchange OnlineEmail and attachment scanning
TeamsChat and channel message inspection
Third-Party (via MCAS)File scanning for Box, Dropbox, Salesforce

Policy Configuration

  1. Choose template or create custom policy
  2. Select monitored locations and apps
  3. Define sensitive info types to detect
  4. Configure actions (block, encrypt, notify)
  5. Test in simulation mode before enforcing

Actions

  • Block sharing — Prevent external sharing of matched content
  • Apply encryption — Auto-encrypt matched files
  • Notify admin — Alert compliance team on matches
  • Generate incident — Create DLP incident for review

API Reference

  • GET /api/security/cloud-dlp/policies — List policies
  • GET /api/security/cloud-dlp/matches — List matches
  • GET /api/security/cloud-dlp/reports — Get reports
Last updated on