Posted December 8, 20222 yr Before we start, please note that if you want to see a table of contents for all the sections of this blog, you can locate them at the following URL: Microsoft Purview and Modern Work (Part 1) - Overview Disclaimer This document is not meant to replace any official documentation, including those found at docs.microsoft.com. Those documents are continually updated and maintained by Microsoft Corporation. If there is a discrepancy between this document and what you find in the Compliance User Interface (UI) or inside of a reference in docs.microsoft.com, you should always defer to that official documentation and contact your Microsoft Account team as needed. Links to the docs.microsoft.com data will be referenced both in the document steps as well as in the appendix. All of the following steps should be done with test data, and where possible, testing should be performed in a test environment. Testing should never be performed against production data. Target Audience The Information Life Cycle Management section of this blog series is aimed at Security and Compliance and Modern Work officers who need to properly label data, encrypt it where needed. Document Scope This blog and document are meant to help an IT administrator who is looking to secure their data throughout the lifecycle of the data. It is presumed that you already have a basic understanding of the Purview tools and the Modern Work tools (including Exchange, Teams, SharePoint and OneDrive). Out-of-Scope This document does not cover configuring any of the below, ie. Holding your hand through the process of configuration”, as that is covered via other blogs, official Microsoft documents, or through the aid of Microsoft implementation teams or Microsoft partners: Audit Communications Compliance Compliance Manager Data Classification (Sensitive Information Types) Data Classification (Exact Data Matching) Data Classification (Trainable Classifiers) Data Lifecycle Management (retention and disposal) Data Protection Loss (DLP) for Exchange, OneDrive, Devices, etc Information Barriers Information Protection (labeling, encrypting, watermarking, etc of files) Insider Risk Management Microsoft Defender for Cloud Apps (MDCA) Privacy Management (Priva) Records Management (retention and disposal) Standard or Premium eDiscovery This blog entry is only addressing Collaboration (creation, usage, sharing of files and SharePoint/Teams Sites), not Communication (emails, teams chats, etc). Notes After each section of this blog, I will make a note of which of the 3 parts of the CIA Triad that Microsoft tool will help you meet. Here are a few examples. Example #1 – CIA component – Integrity & Availability Example #2 – CIA component – Confidentiality & Availability Example #3 – CIA component – Integrity SharePoint Sharing and Access Controls First, when it comes to protected data, we need to take a moment to make sure that SharePoint specific data controls are enabled. Although we will not go into use cases or configuration on these, you should be aware that where to find these controls. Sharing Go to sharepoint.com. Click on Polices - Sharing On the right side, you will see sliders that control content sharing. Below that you will see More External Sharing Settings. Below that, you will see controls around Link Sharing and other seetings. Access Controls Go to sharepoint.com. Click on Polices – Access Controls On the right side, you will see various options for controlling access to your SharePoint data. Navigate these controls and investigation what options are available to your organization. Move to the next section where we will address the Purview Specific workloads with your SharePoint, Teams, and OneDrive platform. Mapping Purview to Collaboration Here we will map the Lifecycle of the data (Create -> Use -> Retain -> Delete) of files and data to OneDrive, SharePoint Sites and Team Sites. When looking at the Information Lifecycle, it is important to understand which Purview tools map to which collaboration activities within that Information Lifecycle. Here is a high-level map. As this is a bit of an eye chart, we will look at each stage of the Information Lifecycle individually. Please note that Use & Retain are placed together as these tend to be interchangeable. Create (data) In the Create phase of ILM, here are the recommended Purview Tools. Auto/Manual (Information Protection - sensitivity labels) Data Lifecycle Mgmt/Records Mgmt (Auto/Manual Retention label) Premium Audit In the Create phase of ILM, here are the SharePoint-based workloads. One Drive -> Create File via Office, OneDrive or Web client SharePoint -> Create SharePoint Site Teams Site ->Create Teams Site Use & Retain (data) In the Use & Create phase of ILM, here are the recommended Purview Tools. Information Protection (sensitivity labels) Information Barriers Communications Compliance eDiscovery Data Loss Prevention Data Lifecycle Mgmt/Records Mgmt (Auto/Manual Retention label) Insider Risk Mgmt Premium Audit In the Use & Create phase of ILM, here are the SharePoint-based workloads. One Drive -> Add File to OneDrive -> Share File / Copy File SharePoint -> Create File (Office/Web) / Add File to Site SharePoint Site -> Share File/Copy File Teams Site -> Create File (Office/Web) / Add File to Site SharePoint Site -> Share File/Copy File Destroy (data) In the Delete phase of ILM, here are the recommended Purview Tools. Data Lifecycle Mgmt/Records Mgmt (Auto/Manual Retention label) Insider Risk Mgmt Premium Audit In the Delete phase of ILM, here are the SharePoint-based workloads. One Drive -> Manual / Auto delete of File / Site SharePoint -> Manual / Auto delete of File / Site Teams Site -> Manual / Auto delete of File / Site Next Steps We will now move to look at SharePoint Sites and specific Purview workloads that can be mapped to data within that platform. Appendix and Links Microsoft Purview compliance documentation - Microsoft Purview (compliance) | Microsoft Learn Microsoft Purview risk and compliance solutions - Microsoft Purview (compliance) | Microsoft Learn Learn about Microsoft Purview Data Lifecycle Management - Microsoft Purview (compliance) | Microsoft Learn Microsoft Purview Data Lifecycle Management | Microsoft Security Use Microsoft Teams for collaboration - Microsoft 365 Business Premium | Microsoft Learn What is OneDrive? (work or school) - Microsoft Support How to use the Microsoft data classification dashboard - Microsoft Purview (compliance) | Microsoft Learn Learn about insider risk management - Microsoft Purview (compliance) | Microsoft Learn Learn about communication compliance - Microsoft Purview (compliance) | Microsoft Learn Learn about data loss prevention - Microsoft Purview (compliance) | Microsoft Learn Microsoft Purview Compliance Manager - Microsoft Purview (compliance) | Microsoft Learn Microsoft Purview eDiscovery solutions - Microsoft Purview (compliance) | Microsoft Learn Microsoft Purview Audit (Premium) - Microsoft Purview (compliance) | Microsoft Learn Learn about Microsoft Purview Data Lifecycle Management - Microsoft Purview (compliance) | Microsoft Learn Records management for documents and emails in Microsoft 365 - Microsoft Purview (compliance) | Microsoft Learn Learn about information barriers - Microsoft Purview (compliance) | Microsoft Learn Learn about sensitivity labels - Microsoft Purview (compliance) | Microsoft Learn Learn about Microsoft Priva - Microsoft Priva | Microsoft Learn Continue reading...
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.