Planning and implementing DLP
In order to effectively plan for your Microsoft 365 DLP deployment, you need to understand any existing or potential data leakage within your organization. DLP can initially be configured with policies that run in test mode only. This is a good starting point for acquiring the information you need to determine your DLP strategy. But before you can create your test policies, it is important that you understand how DLP works, what sort of information can be detected, and which Microsoft 365 services can be protected.
A good starting point is to examine the SITs used by DLP policies. There are several built-in SITs available in Microsoft 365. You explored sensitive info types in more detail in Chapter 11, Managing Sensitive Information, but as a quick reminder, you can find these in the Microsoft Purview compliance center at https://compliance.microsoft.com under Data classification | Sensitive info types:
Figure 12.1: Sensitive...