Skip to main content

Notifications

Power Automate - General Discussion
Unanswered

DLP seems easy to circumvent via a separate tenant?

(1) ShareShare
ReportReport
Posted on by 1,247

TenantA has a DLP with SharePoint in "Business Data Only". This means that users in TenantA cannot email content from SharePont via Flow. This is good.

 

TenantA creates an account for a consultant, Sam. Sam also has an account in a TenantB. Sam creates a flow in his TenantB that connects to SharePoint in TenantA, which emails content from SharePoint. Sam's Flow wouldn't be subject to the DLP, because the Flow is running in TenantB.

 

We also have a separate tenant for developers for them to build/test. They're in charge of that tenant, and so they can also ignore any DLP policies in the main tenant, right?

 

So, what do we actually accomplish by configuring DLP? Is there a way for admins to block users from emailing business data, or posting it to Twitter, via flow?

 

 

 

  • Mike2500 Profile Picture
    Mike2500 1,247 on at
    Re: DLP seems easy to circumvent via a separate tenant?

    So is this a bug in the software, or does the documentation need to be udpated? According to the docs:

     

    "Benefits of a DLP policy
    Ensures that data is managed in a uniform manner across the organization
    Prevents important business data from being accidentally published to services such as social media sites."

     

    But because of the issue I pointed out with tenants, these benefits don't actually exist. 

  • v-xida-msft Profile Picture
    v-xida-msft on at
    Re: DLP seems easy to circumvent via a separate tenant?

    Hi @Mike2500,

     

    Thanks for your feedback. A DLP is applied to one or more environments which are created by a tenant. The DLP takes effect in one or more environments which are created by a tenant. The DLP is created in TenantA is not effective in TenantB.

     

    More details about Data Loss Prevention Policies, please check the following document:

    Introducing Data Loss Prevention Policies in Microsoft Flow

     

    Best regards,

    Kris

Under review

Thank you for your reply! To ensure a great experience for everyone, your content is awaiting approval by our Community Managers. Please check back later.

Helpful resources

Quick Links

Microsoft Kickstarter Events…

Register for Microsoft Kickstarter Events…

Announcing Our 2025 Season 1 Super Users!

A new season of Super Users has arrived, and we are so grateful for the daily…

Announcing Forum Attachment Improvements!

We're excited to announce that attachments for replies in forums and improved…

Leaderboard

#1
WarrenBelz Profile Picture

WarrenBelz 145,495

#2
RandyHayes Profile Picture

RandyHayes 76,287

#3
Pstork1 Profile Picture

Pstork1 64,822

Leaderboard