/Create-a-File-policy-for-Cloud-Apps

Use Defender for Cloud Apps & create a file policy for detection of sharing US PII. Set email alert.

Create-a-File-policy-for-Cloud-Apps

Use Defender for Cloud Apps & create a file policy for detection of sharing US PII. Set email alert.

Description

Project consists of a creating a Risk-based access policies as a part of Azure AD Identity Protection policies. Risk-based access policies, there are two types of risk policies in Azure Active Directory (Azure AD) Conditional Access we can set up to automate the response to risks and allow users to self-remediate when risk is detected: Sign-in risk policy and User-risk policy. In this practical, it is auto applying for High risk level.

Environments Used

  • Microsoft 365 Defender portal

Prerequisites

- File policy for cloud apps can be created or modified by anyone assigned the following roles:

  • Security Administrator
  • Global Administrator
- Licenses: at-least Azure Active Directory Premium P1

Program walk-through:

Steps:

  1. Go to Microsoft 365 defender
  2. Cloud apps section --> select policies --> policies management
  3. Create policy --> select category ‘file policy’
  4. Give a name, select a ‘sharing control’ as category
  5. Select users-groups, select inspection method & US : PII Social security number
  6. Select alert as email and add email id of recipient
  7. Create

Screenshots:

Policy Management:


Create a new Policy:


Give a name:


Select Users and Inspection method:


Alert settings: