Create segments and policies
After you verified the installed version of Information Barriers (IB), you are ready to create segments and policies.
Create segments
A segment is a group of users defined by a set of properties. Each segment has a filter that tells Entra what accounts come within its scope.
To create a segment:
In a browser, navigate to https://compliance.microsoft.com/ibsegments, select New segment, and then Next.
Establish the condition for the segment to be created.
- Use any of the attributes of a user in Entra, even extended ones.
- You can also use the condition "Member Of" that will use the membership of a Security Group as a condition to be part of the segment.
Important
This must be a security group, only. The membership of the original security group must be only users. Nested groups, as members, won't work.
Create policies
IB policies work by either allowing or blocking segments from communicating with each other.
To create a policy:
In a browser, navigate to https://compliance.microsoft.com/ibpolicies, select Create policy, add a name, and select Next.
Next, select the segment where the policy is to be applied. Select Next.
Select the option for allowing or blocking communication and collaboration.
Choose Allow.
Choose a segment. Select the same segment so that the users in this segment can only communicate and collaborate with the users in the same segment.
Apply the policies
Navigate to Policy application – Microsoft Purview and apply the policies.
Note
It takes time for the policies to propagate, depending on the number of segments and policies created. Once the status changes to “Completed,” it’s recommended to wait 24 hours before testing.