Share via

Where do Actions for a DLP Exchange Policy Live (Policy Created in Purview)

DVO 41 Reputation points
2022-12-23T17:08:40.343+00:00

We've created a basic DLP policy targeting Exchange, with an action to forward an email for approval when a condition is met. The email is never forwarded, and have opened a SR, which is not getting anywhere. Message Trace shows no errors, and also nothing of use for troubleshooting.

Documentation states that DLP for Exchange in Purview uses Exchange transport rules. I looked in EAC and see no such rule for forwarding. I also don't see rules for notifications or policy tips (which work fine)--so mail rule configuration is stored somewhere....but where?

Does anyone know where this kind of configuration lives? Purview is impossible to troubleshoot, as there's no REST API. For policy, you get a handful of Powershell cmdlets that do not return needed information. I get it--Purview is a new wrapper portal for existing underlying services, but devop types need to know where the new data types live, and how to access them before they will trust it enough to implement.

Thank you in advance for any insight.

Microsoft Security | Microsoft Purview
0 comments No comments
{count} votes

Answer accepted by question author
  1. Jordan Millama 1,391 Reputation points
    2022-12-23T17:33:43.82+00:00

    I believe what you are looking for resides under mail flow within EAC.

    273739-image.png

    ----------

    Please accept as an answer if this was helpful.

    0 comments No comments

1 additional answer

Sort by: Most helpful
  1. DVO 41 Reputation points
    2022-12-23T17:49:08.65+00:00

    Thank you for the reply! Correct. That's where I looked, but did not see any rules pertaining to forwarding.

    MSFT's response is this:

    I must say this is by design, let's say we have a lot of DLP configuration for OneDrive, SharePoint, Exchange and we don't want these transport rules to be mixed up with our Exchange Online transport rules. As we know the features of Exchange Online transport rule is kind of different than the DLP and DLP is designed for protecting organization valued and sensitive data although there are some similarities and dependencies specially in mail transport and notifications

    which is counter to their own documentation suggesting that it uses EXO transport rules in the context of an organization's EXO. That's why I'm hoping someone here knows where these transport rules live. Support's next step? "Can you create a second policy before we escalate?"

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.