Note
Access to this page requires authorization. You can try signing in or changing directories.
Access to this page requires authorization. You can try changing directories.
Important
This feature is currently in preview. The Supplemental Terms of Use for Microsoft Azure Previews include additional legal terms that apply to Azure features that are in beta, in preview, or otherwise not yet released into general availability.
Microsoft Purview Data Loss Prevention (DLP) extend to non-Microsoft connected apps, allowing you to detect, monitor, and protect sensitive data at rest in non-Microsoft SaaS applications. You can create DLP policies that apply to data stored in these non-Microsoft apps, using the same classification engine and policy framework available for Microsoft 365 locations.
Tip
Get started with Microsoft Security Copilot to explore new ways to work smarter and faster using the power of AI. Learn more about Microsoft Security Copilot in Microsoft Purview.
Supported non-Microsoft apps
Microsoft Purview supports DLP policies for the following non-Microsoft apps:
- Box
- Dropbox
- Google Workspace
- Salesforce
Note
These apps are rolling out in phases. Not all apps may be available in your tenant at the same time. Check the Microsoft 365 roadmap for the latest availability information.
Before you begin
Licensing requirements
For information on licensing, see
Permissions
The account you use to create and deploy policies must be a member of one of these role groups:
- Compliance administrator
- Compliance data administrator
- Information Protection
- Information Protection Admin
- Security administrator
Important
Microsoft recommends that you use roles with the fewest permissions. This helps improve security for your organization. Global Administrator is a highly privileged role that should only be used in scenarios where a lesser privileged role can't be used.
Set up a Microsoft Defender for Cloud Apps connector
Before you can apply DLP policies to a non-Microsoft app, you must connect that app to Microsoft Defender for Cloud Apps using an app connector. Purview uses the existing Microsoft Defender for Cloud Apps connectors to access capabilities in the non-Microsoft app.
For instructions on setting up app connectors, see Connect apps to get visibility and control with Microsoft Defender for Cloud Apps.
After you connect your cloud apps to Defender for Cloud Apps, you can create DLP policies for them in Microsoft Purview.
Create a DLP policy for non-Microsoft connected apps
To create a DLP policy scoped to non-Microsoft connected apps:
Sign in to the Microsoft Purview portal.
Go to Solutions > Data Loss Prevention > Policies > + Create policy.
On What info do you want to protect?, choose the Enterprise applications & devices option.
Select Custom > Custom policy, and then select Next.
Important
Non-Microsoft connected app policies are only supported with the Custom policy template. The predefined Financial, Medical and health, and Privacy templates don't support non-Microsoft app locations.
Enter a name and description for the DLP policy, then select Next.
On Assign admin units, the scope is set to Full directory. Administrative units aren't supported for non-Microsoft app locations.
On Choose where to apply the policy, select one or more of the supported non-Microsoft apps (such as Box, Dropbox, Google Workspace, and Salesforce.
Important
Non-Microsoft app locations can be selected together, but they can't be combined with other locations like SharePoint, OneDrive, Exchange, Fabric, or Devices in the same policy.
By default, the policy applies to all instances of the selected app. To scope the policy to specific tenants, select Edit.
- To exclude instances, in All instances, select Exclude instances > + Exclude instance. From the list of instances, select instances to exclude from the policy, and then select Done > Done.
- To apply the policy to specific instances, select Specific instances > + Include instance. From the list of instances, select instances to include, then select Done > Done.
Select Next to proceed.
On Define policy settings, select Create or customize advanced DLP rules to define an advanced DLP rule. Only advanced DLP rules are supported for non-Microsoft connected apps. Select Next.
Select + Create rule, and provide a Name and Description.
Configure Conditions for the rule. The conditions you can use vary by app.
Configure Actions for the rule. The available actions vary by app.
Configure Notifications. Note the following limitations for non-Microsoft apps:
- Policy tips aren't supported.
- User overrides aren't supported.
Select Save to save the rule, then select Next.
On Policy mode, choose either Turn the policy on immediately or Leave the policy turned off. Select Next.
Important
Simulation mode isn't supported for non-Microsoft connected app policies.
Review your settings and select Submit to create the policy.
Attribute availability by app
The conditions and actions you can use in a policy depend on the item attributes that each app makes available. Most attributes are available for all supported apps, but some aren't available for certain apps. Use the following table to understand which attributes you can rely on when you build rules for a specific app.
| Attribute | Description | Availability |
|---|---|---|
| Name | The display name of the item. | Available in all apps |
| File access level | The item's access level, which indicates its sharing scope. | Available in all apps |
| Created date | The date the item was created. | Not available in Dropbox |
| Modified date | The date the item was last modified. | Available in all apps |
| Collaborators | The users the item is shared with, including their roles. | Available in all apps |
| Parent folders | The parent folders that contain the item. | Available in all apps |
Monitoring and reporting
Activity explorer
Activity explorer supports non-Microsoft connected app policies. You can monitor DLP policy activity for your non-Microsoft apps in the same way you monitor Microsoft 365 locations.
Content explorer
Content explorer isn't supported for non-Microsoft connected apps. You can't browse or inspect content stored in these apps through Content explorer.
Alerts
DLP alerts are supported for non-Microsoft connected app policies. Alerts appear in the DLP alerts dashboard alongside alerts from other locations.
Known issues
The following is a list of known issues when using non-Microsoft connected apps for DLP policies:
- Encrypted files – Encrypted files stored in non-Microsoft apps aren't currently supported for classification.
- PDF files – PDF files stored in non-Microsoft apps aren't currently supported for classification.