web
You’re offline. This is a read only version of the page.
close
Skip to main content

Announcements

News and Announcements icon
Community site session details

Community site session details

Session Id :
Power Platform Community / Forums / Power Automate / DLP seems easy to circ...
Power Automate
Unanswered

DLP seems easy to circumvent via a separate tenant?

(1) ShareShare
ReportReport
Posted on by 1,247 Super User 2024 Season 1

TenantA has a DLP with SharePoint in "Business Data Only". This means that users in TenantA cannot email content from SharePont via Flow. This is good.

 

TenantA creates an account for a consultant, Sam. Sam also has an account in a TenantB. Sam creates a flow in his TenantB that connects to SharePoint in TenantA, which emails content from SharePoint. Sam's Flow wouldn't be subject to the DLP, because the Flow is running in TenantB.

 

We also have a separate tenant for developers for them to build/test. They're in charge of that tenant, and so they can also ignore any DLP policies in the main tenant, right?

 

So, what do we actually accomplish by configuring DLP? Is there a way for admins to block users from emailing business data, or posting it to Twitter, via flow?

 

 

 

Categories:
I have the same question (0)
  • v-xida-msft Profile Picture
    Microsoft Employee on at

    Hi @Mike2500,

     

    Thanks for your feedback. A DLP is applied to one or more environments which are created by a tenant. The DLP takes effect in one or more environments which are created by a tenant. The DLP is created in TenantA is not effective in TenantB.

     

    More details about Data Loss Prevention Policies, please check the following document:

    Introducing Data Loss Prevention Policies in Microsoft Flow

     

    Best regards,

    Kris

  • Mike2500 Profile Picture
    1,247 Super User 2024 Season 1 on at

    So is this a bug in the software, or does the documentation need to be udpated? According to the docs:

     

    "Benefits of a DLP policy
    Ensures that data is managed in a uniform manner across the organization
    Prevents important business data from being accidentally published to services such as social media sites."

     

    But because of the issue I pointed out with tenants, these benefits don't actually exist. 

Under review

Thank you for your reply! To ensure a great experience for everyone, your content is awaiting approval by our Community Managers. Please check back later.

Helpful resources

Quick Links

Introducing the 2026 Season 1 community Super Users

Congratulations to our 2026 Super Users!

Kudos to our 2025 Community Spotlight Honorees

Congratulations to our 2025 community superstars!

Leaderboard > Power Automate

#1
Haque Profile Picture

Haque 283

#2
David_MA Profile Picture

David_MA 256 Super User 2026 Season 1

#3
Expiscornovus Profile Picture

Expiscornovus 225 Most Valuable Professional

Last 30 days Overall leaderboard