MS-102 · Question #66
You have a Microsoft 365 subscription. You configure a data loss prevention (DLP) policy. You discover that users are incorrectly marking content as false positive and bypassing the DLP policy. You…
The correct answer is D. user overrides. In Microsoft Purview DLP policy settings, the 'User overrides' section controls whether end users are permitted to override a DLP policy action and mark content as a false positive or provide a business justification to bypass the rule. To stop users from bypassing the DLP…
Question
You have a Microsoft 365 subscription. You configure a data loss prevention (DLP) policy. You discover that users are incorrectly marking content as false positive and bypassing the DLP policy. You need to prevent the users from bypassing the DLP policy. What should you configure?
Options
- Aactions
- Bincident reports
- Cexceptions
- Duser overrides
How the community answered
(30 responses)- A3% (1)
- B10% (3)
- C17% (5)
- D70% (21)
Explanation
In Microsoft Purview DLP policy settings, the 'User overrides' section controls whether end users are permitted to override a DLP policy action and mark content as a false positive or provide a business justification to bypass the rule. To stop users from bypassing the DLP policy, you should configure (or disable) the 'User overrides' setting so that overrides are not allowed. Actions (A) define what happens when a rule is matched. Incident reports (B) control how administrators are notified. Exceptions (C) define conditions that exclude content from a rule. None of those control the end-user's ability to override an active policy block.
Topics
Community Discussion
No community discussion yet for this question.