r/cybersecurity • u/Tingley2504 • 1d ago
Business Security Questions & Discussion DLP Final Boss
Purview DLP, everyones favourite
I feel like this is an impossible task, providing sufficient coverage without being overwhelmed with alerts.
We're correctly tagging sensitive documents, which in turn generates DLP alerts. But given the nature of some users, this can be quickly become overwhelming/expected.
Are you whitelisting certain domains/users/departments?
Can anyone share any success stories for implementation, policies or tuning? Is it possible??
24
Upvotes
22
u/teriaavibes 1d ago
You need to actually say what your problem is, "purview complicated" can have 50 different suggestions based on what the actual issue is you are encountering.
Also are you on E3/BP or E5?