Implementing data loss prevention policies in test mode
When you are configuring data loss prevention policies, it can be hard to understand the full effect on users. Test mode is there so that administrators can make new DLP policies and monitor the effect and usefulness of the policy for users. You will receive an email with the results that contain incident reports, where a rule within the policy matches data in the specific locations. Reviewing these reports will assist you in determining whether the policy is working as it should be or whether you need to amend the policy before turning it on.
A good example of this is when you configure a policy that protects UK driving license numbers from being shared but when checking the data classification specs, you see that the internal product numbers the organization uses are almost identical to the pattern of the license numbers you are trying to protect. Here, you want to test the impact this policy would potentially have on users...