Back to latest version

MC781588 - Microsoft Purview | Insider Risk Management: Exfiltration of business sensitive data to free public domain emails

Message Center

Metadata at Apr 19, 2024

Published

Apr 19, 2024

Service

Microsoft 365 suite

Tag

New feature
Admin impact

Platforms

Web

Metadata changes

Title
Purview | Insider Risk Management: Exfiltration of business sensitive data to free public domain emailsMicrosoft Purview | Insider Risk Management: Exfiltration of business sensitive data to free public domain emails
Tags
Admin impact, New feature, Updated messageAdmin impact, New feature

Body changes

removed textadded text

Updated August 9, 2024: We have updated the content below with additional information. Thank you for your patience.

Coming soon, Microsoft Purview Insider Risk Management will roll out exfiltration of business sensitive data to free public domain emails.

This message is associated with Microsoft 365 Roadmap ID 393334.

When this will happen:

Public Preview: We will begin rolling out mid-May 2024 and expect to complete by late May 2024.

General Availability: We will begin rolling out late June 2024 and expect to complete by early July 2024.

How this will affect your organization:

WeIn this rollout, we are enhancing the existing email insight alerts to provide additional information when business sensitive data is potentially leaked from a work email account to a free public domain email, potentially leading to a data security incident. The new domain detection group "FreeFree public domains"domains will list the common domains used for personal email accounts. Admins with appropriate permissions can also choose to select these domains in their email indicator variants.

You can also modify the "Free public domains" detection group. Administrators with the necessary permissions now have the flexibility to tailor the default domain list in the "Free public domains" by adding new domains or removing existing ones. Should there be a need to revert to the original domain list provided by Microsoft, the "Reset" function can be utilized. The maximum number of domains allowed per detection group remains capped at 200, and this includes the "Free public domains" group. Any changes made to this group will be taken into account when analyzing potential data exfiltration to personal email accounts.

Microsoft Purview Insider Risk Management correlates various signals to identify potential malicious or inadvertent insider risks, such as IP theft, data leakage, and security violations. Insider Risk Management enables customers to create policies based on their own internal policies, governance, and organizational requirements. Built with privacy by design, users are pseudonymized by default, and role-based access controls and audit logs are in place to help ensure user-level privacy.

Any email going to free public domains (including email sent to self) will be automatically highlighted in email insights.

Updated email insight:

admin settings

Free public domains:

admin settings

New column and filters for email activities:

admin settings

What you need to do to prepare:

This rollout will happen automatically by the specified date with no admin action required before the rollout.

You may want to update any relevant documentation as appropriate. We will update this comm before rollout with revised documentation.

Microsoft Purview Insider Risk Management correlates various signals to identify potential malicious or inadvertent insider risks, such as IP theft, data leakage, and security violations. Insider Risk Management enables customers to create policies based on their own internal policies, governance, and organizational requirements. Built with privacy by design, users are pseudonymized by default, and role-based access controls and audit logs are in place to help ensure user-level privacy. 

You can access the Insider Risk Management solution in the Microsoft Purview compliance portal.