1
00:00:00,000 --> 00:00:05,880
In 2020, an employee at Vertifore accidentally exposed 27.7 million Texas driver records,

2
00:00:05,880 --> 00:00:10,420
names, addresses, birth dates and license numbers by storing three data files in an external

3
00:00:10,420 --> 00:00:11,700
storage location.

4
00:00:11,700 --> 00:00:16,400
No malicious hacking, no bad intentions, just routine work that went wrong, and the company

5
00:00:16,400 --> 00:00:17,880
didn't even discover it themselves.

6
00:00:17,880 --> 00:00:19,320
A third party had to tell them.

7
00:00:19,320 --> 00:00:23,320
That's the exact problem Microsoft Peruvio Data Loss Prevention DLP for short solves.

8
00:00:23,320 --> 00:00:27,560
It's not built to stop hackers, it's designed to stop your own people from accidentally leaking

9
00:00:27,560 --> 00:00:32,160
sensitive data. By the end of this episode, you'll know what Microsoft Peruvio DLP really

10
00:00:32,160 --> 00:00:37,000
is, why every business needs it, and how it quietly watches over your data across email,

11
00:00:37,000 --> 00:00:40,640
files, chats, devices, and even AI tools.

12
00:00:40,640 --> 00:00:43,760
The Data League Problem, why DLP exists?

13
00:00:43,760 --> 00:00:47,120
Before we talk about the solution, let's understand the scale of the problem. Here's a number

14
00:00:47,120 --> 00:00:52,760
that matters. 58% of data leaks are accidental. Not malicious, not some sophisticated attack,

15
00:00:52,760 --> 00:00:56,840
just someone forwarding an email to the wrong person or attaching the wrong file. Human

16
00:00:56,840 --> 00:01:00,800
error is the biggest security vulnerability most organizations have. And it's getting

17
00:01:00,800 --> 00:01:06,680
worse last year, 74% of organizations, nearly three out of four, reported a data incident.

18
00:01:06,680 --> 00:01:12,040
Yet organizations using disconnected security tools had 2.8 times more incidents, more tools

19
00:01:12,040 --> 00:01:16,880
meant more problems. Because when your security tools don't talk to each other, you get gaps.

20
00:01:16,880 --> 00:01:21,200
And data leaks through gaps. So what did organizations do before DLP? They locked everything

21
00:01:21,200 --> 00:01:26,040
down, disabled USB ports, outlawed personal email, restricted everything. The problem, that

22
00:01:26,040 --> 00:01:29,920
kills productivity. People need to share files to do their jobs. And when you make it too

23
00:01:29,920 --> 00:01:34,640
hard, they find workarounds. They use personal Gmail, upload to Dropbox or put data on USB

24
00:01:34,640 --> 00:01:38,840
drives anyway. The locks become useless. DLP takes a completely different approach. Instead

25
00:01:38,840 --> 00:01:42,760
of blocking everything, it watches three things. What the data is, who's handling it and where

26
00:01:42,760 --> 00:01:47,280
it's going. Then it enforces rules automatically. The core idea is simple. First, you identify

27
00:01:47,280 --> 00:01:51,560
what counts as sensitive credit card numbers, health records, confidential contracts. Then

28
00:01:51,560 --> 00:01:57,200
you monitor that data across all your Microsoft 365 services, email, files, chats, devices.

29
00:01:57,200 --> 00:02:02,000
And when someone tries to do something risky, DLP either warns them or blocks the action.

30
00:02:02,000 --> 00:02:05,480
It's not about locking people out. It's about catching honest mistakes before they become

31
00:02:05,480 --> 00:02:11,400
headlines. The office building analogy. So how does DLP actually do all that? Let's build

32
00:02:11,400 --> 00:02:15,080
a mental model. Imagine your organization is an office building with different departments

33
00:02:15,080 --> 00:02:18,560
on different floors and different security levels for different areas. The lobby has a

34
00:02:18,560 --> 00:02:23,560
reception desk and that's your identity system. Entra ID. It checks badges at the door. Are

35
00:02:23,560 --> 00:02:29,000
you who you say you are? Good, you're in. But here's the thing. Once you're inside, data

36
00:02:29,000 --> 00:02:33,240
moves constantly. People walk through hallways carrying files. They take documents to meeting

37
00:02:33,240 --> 00:02:37,800
rooms. They send papers through the mail room and they bring laptops home at night. And

38
00:02:37,800 --> 00:02:41,440
that's where the old approach fails. Because checking badges at the front door doesn't

39
00:02:41,440 --> 00:02:45,560
tell you what people are carrying out. DLP is like a team of security guards who don't

40
00:02:45,560 --> 00:02:49,160
just check badges. They look at what's in people's hands. A visitor walking out with a stack

41
00:02:49,160 --> 00:02:53,160
of confidential documents. The guard stops them and employee putting client files into their

42
00:02:53,160 --> 00:02:57,200
personal bag. The guard asks questions. These guards work everywhere in the building in the

43
00:02:57,200 --> 00:03:01,920
mail room scanning every outgoing email that's exchanged online in the file storage room

44
00:03:01,920 --> 00:03:06,160
watching files being shared share point and one drive in the conference rooms monitoring

45
00:03:06,160 --> 00:03:11,760
chat messages teams and on laptops. People take home endpoint DLP protecting devices even

46
00:03:11,760 --> 00:03:16,320
when offline. And there's a new guard that just arrived. The one standing next to the AI

47
00:03:16,320 --> 00:03:21,160
assistant making sure it doesn't hand sensitive data to the wrong person. That's copilot DLP.

48
00:03:21,160 --> 00:03:26,320
The building gets smarter but the guards keep up. Exchange online protecting email. Let's

49
00:03:26,320 --> 00:03:30,360
start in the mail room because email is still the most common way data walks out of your

50
00:03:30,360 --> 00:03:37,200
organization. One wrong reply. All one misplaced attachment or one moment of clicking send

51
00:03:37,200 --> 00:03:42,760
before your brain catches up. That's how most accidental leaks happen. Exchange online DLP

52
00:03:42,760 --> 00:03:47,240
scans every email before it sent both the body text and any attachments and it's not just

53
00:03:47,240 --> 00:03:51,520
doing simple keyword searches. It's using deep content analysis pattern recognition that

54
00:03:51,520 --> 00:03:56,000
catches credit card numbers following a specific format and passing a checksum test proximity

55
00:03:56,000 --> 00:04:00,080
detection that finds a name and an address right next to each other and machine learning

56
00:04:00,080 --> 00:04:05,120
classifiers that get smarter over time. Now imagine this an employee finishes a spreadsheet

57
00:04:05,120 --> 00:04:09,160
with customer credit card numbers. They need to work on it at home so they draft an email

58
00:04:09,160 --> 00:04:13,320
to their personal Gmail address and attach the file they hit send. But before that email

59
00:04:13,320 --> 00:04:17,440
actually leaves exchange DLP scans it finds the credit card numbers in the attachment

60
00:04:17,440 --> 00:04:21,760
recognizes the destination is outside the organization and blocks the send. What does

61
00:04:21,760 --> 00:04:27,320
the employee see a policy tip a pop-up that says something like this email contains sensitive

62
00:04:27,320 --> 00:04:31,240
information and can't be sent to external recipients. Depending on how the policy is

63
00:04:31,240 --> 00:04:35,520
configured they might have the option to override by providing a business justification explaining

64
00:04:35,520 --> 00:04:39,920
why the send is legitimate. That justification gets logged. So if it's a pattern on the same

65
00:04:39,920 --> 00:04:43,960
person doing this every Friday an admin can investigate the point is the email never

66
00:04:43,960 --> 00:04:48,400
reaches the outside it's called before it leaves the building and every match is logged.

67
00:04:48,400 --> 00:04:52,980
So admins can see exactly what was blocked who tried to send it and why the SharePoint

68
00:04:52,980 --> 00:04:57,080
and one drive protecting files at rest and in motion email isn't the only place data

69
00:04:57,080 --> 00:05:00,840
leaks happen. What about the files already sitting in your SharePoint sites or synced

70
00:05:00,840 --> 00:05:05,300
to your one drive that's where the next layer of DLP protection comes in SharePoint and

71
00:05:05,300 --> 00:05:10,320
one drive DLP watches files in two states at rest means the file is stored on the site.

72
00:05:10,320 --> 00:05:14,400
In motion means someone is sharing it with someone else you can create policies that scan

73
00:05:14,400 --> 00:05:18,840
existing files for anything sensitive if DLP find something it shouldn't it can flag

74
00:05:18,840 --> 00:05:23,880
the file or even quarantine it automatically. The quarantine feature is relatively new when

75
00:05:23,880 --> 00:05:28,880
DLP finds a violating file it moves that file to a secure location only admins can reach.

76
00:05:28,880 --> 00:05:33,520
The original file gets replaced with a tombstone file it's just a plain text message explaining

77
00:05:33,520 --> 00:05:37,440
why the file is missing and what the user should do if they think it's a mistake think of

78
00:05:37,440 --> 00:05:41,720
it as a sign that says this file has been secured talk to your admin if you needed for

79
00:05:41,720 --> 00:05:46,880
external sharing DLP gets even more specific you can block sharing to particular domains say

80
00:05:46,880 --> 00:05:50,840
you have a competitor you don't want receiving your internal documents just add their domain

81
00:05:50,840 --> 00:05:54,960
to a block list but here's what makes it really useful that restriction applies retroactively

82
00:05:54,960 --> 00:05:59,840
if a file was already shared with that domain before you created the policy DLP can revoke

83
00:05:59,840 --> 00:06:03,920
that access it's not just locking the door going forward it's checking who's already inside

84
00:06:03,920 --> 00:06:08,000
let's look at a real scenario a contractor working with your company accidentally shares a folder

85
00:06:08,000 --> 00:06:13,760
marked confidential with the entire organization that means hundreds of people now have access DLP

86
00:06:13,760 --> 00:06:17,680
detects the sensitivity label on the documents it sees the sharing activity and it restricts

87
00:06:17,680 --> 00:06:22,080
access to only the intended audience the damages contained before most people even realize

88
00:06:22,080 --> 00:06:26,240
the folder was shared one drive functions as your personal file vault you store your files there

89
00:06:26,240 --> 00:06:31,040
and work on them but DLP watches when you try to sync sensitive files to a personal device say

90
00:06:31,040 --> 00:06:36,720
someone drags a highly confidential document from one drive into their local downloads folder DLP

91
00:06:36,720 --> 00:06:41,040
can block that action because once that file leaves the cloud you lose control over it the guard

92
00:06:41,040 --> 00:06:47,040
at the door checks what's leaving the building even if it's from your own desk teams DLP protecting chat

93
00:06:47,040 --> 00:06:51,760
and channel messages work today doesn't just happen in email or shared folders a lot of it happens

94
00:06:51,760 --> 00:06:57,440
in teams private chats channel conversations quick messages back and forth and people share sensitive

95
00:06:57,440 --> 00:07:01,840
information there all the time a project manager types a client's social security number into a chat

96
00:07:01,840 --> 00:07:06,240
an engineer pays confidential code into a channel with external guests a salesperson drops a credit

97
00:07:06,240 --> 00:07:10,880
card number into a direct message no attachment needed no file required just text flying across

98
00:07:10,880 --> 00:07:16,800
the conversation teams DLP scans those messages to it monitors private chats and channel conversations

99
00:07:16,800 --> 00:07:21,120
and it looks at the message content itself not just attached files so if someone types a social

100
00:07:21,120 --> 00:07:26,400
security number directly into a chat DLP catches it the system can block the message from being sent

101
00:07:26,400 --> 00:07:30,960
show a policy tip explaining why and log the attempt for review let's walk through a specific

102
00:07:30,960 --> 00:07:35,920
scenario you have a channel where you collaborate with external partners someone on your team types

103
00:07:35,920 --> 00:07:43,120
here's the clients ssn 123456789 before that message appears in the channel teams DLP scans it

104
00:07:43,120 --> 00:07:47,600
it recognizes the social security number pattern it sees the message is heading to a channel with

105
00:07:47,600 --> 00:07:52,000
external guests and it blocks the message from being sent the person who typed it sees a warning the

106
00:07:52,000 --> 00:07:56,880
sensitive number never reaches the channel and an alert gets logged for the compliance team teams

107
00:07:56,880 --> 00:08:01,600
feels informal people treated like instant messaging they type things they'd never put in an email

108
00:08:01,600 --> 00:08:07,200
but a leaked ssn in a team's chat is just as damaging as one in an email attachment DLP treats

109
00:08:07,200 --> 00:08:13,040
them exactly the same way endpoint DLP protecting devices so we've put guards in the mail room the file

110
00:08:13,040 --> 00:08:17,040
storage and the conference rooms but what about the actual device someone is using right now

111
00:08:17,040 --> 00:08:22,080
think about a laptop at a coffee shop a desktop in a home office or a device on a plane with no internet

112
00:08:22,080 --> 00:08:27,840
connection that's where npoint DLP steps in endpoint DLP extends protection to the physical device itself

113
00:08:27,840 --> 00:08:32,880
including windows and macOS it watches everything that happens on that machine and it can block or

114
00:08:32,880 --> 00:08:37,920
audit actions that no cloud-based policy can reach things like copying files to a USB drive printing

115
00:08:37,920 --> 00:08:43,120
a confidential document uploading to a personal cloud service like dropbox pasting sensitive text into

116
00:08:43,120 --> 00:08:48,480
an unapproved browser or even sending files over Bluetooth here's something that surprises most

117
00:08:48,480 --> 00:08:53,040
people endpoint DLP works even when the device is offline the policies are cashed locally on the

118
00:08:53,040 --> 00:08:58,320
machine so if someone on a plane tries to copy a confidential file to a USB drive DLP still blocks

119
00:08:58,320 --> 00:09:02,400
it because the rules are already on the device they don't need to phone home how does it work a

120
00:09:02,400 --> 00:09:07,280
small agent runs on the device it uses the same deep content analysis we talked about earlier pattern

121
00:09:07,280 --> 00:09:12,560
recognition proximity detection machine learning but instead of scanning email or sharepoint it scans

122
00:09:12,560 --> 00:09:17,200
content as it moves across the device when you copy a file paste text or try to print the agent checks

123
00:09:17,200 --> 00:09:22,400
it every time it's watching everything that touches sensitive data let me give you a concrete example

124
00:09:22,400 --> 00:09:27,520
an employee opens a file labeled highly confidential and copies a section of text to paste into a

125
00:09:27,520 --> 00:09:33,120
personal gmail tab endpoint DLP detects the sensitivity label on the source file sees the paste is

126
00:09:33,120 --> 00:09:38,400
going to an unapproved browser and blocks it a warning pops up explaining why and the action never

127
00:09:38,400 --> 00:09:44,480
completes endpoint DLP covers a lot of ground copying to a USB drive gets blocked printing a confidential

128
00:09:44,480 --> 00:09:49,280
document gets blocked or audited uploading to dropbox or google drive gets blocked even pasting into

129
00:09:49,280 --> 00:09:54,720
an AI tool like chat GPT gets blocked and less obvious actions like copying to a network share

130
00:09:54,720 --> 00:09:59,920
or remote desktop session can also be monitored getting devices set up is done through internal group

131
00:09:59,920 --> 00:10:04,880
policy Microsoft recommends starting in simulation mode just like with other DLP policies you run the

132
00:10:04,880 --> 00:10:10,160
policy see what would have been blocked review the data tune the rules then enforce no surprises

133
00:10:10,160 --> 00:10:14,960
and you won't break any legitimate workflows recent updates have made endpoint DLP even more powerful

134
00:10:14,960 --> 00:10:20,480
as of 2026 it can detect and block exfiltration of files that haven't been saved yet someone

135
00:10:20,480 --> 00:10:25,600
pasting sensitive data into a new document and trying to copy it out before ever hitting save

136
00:10:25,600 --> 00:10:30,480
and on co-pilot plus PCs it can prevent windows recall from capturing snapshots of sensitive content

137
00:10:30,480 --> 00:10:36,480
the gods on your devices are getting smarter all the time co-pilot and AI DLP the new frontier so

138
00:10:36,480 --> 00:10:40,720
we've got gods in the mail room the file storage the conference rooms and on every laptop but there's

139
00:10:40,720 --> 00:10:46,080
a new corner of the office that needs watching the AI assistant Microsoft 365 co-pilot can access

140
00:10:46,080 --> 00:10:51,200
your organization's data emails files meetings chats that's incredibly powerful but it also creates

141
00:10:51,200 --> 00:10:56,080
a new risk when someone asks co-pilot a question they're essentially asking it to pull sensitive

142
00:10:56,080 --> 00:11:01,440
information from across your entire organization and handed to them in a neat summary here's the

143
00:11:01,440 --> 00:11:06,320
scenario a user opens co-pilot in word and types summarize the quarterly financials from the

144
00:11:06,320 --> 00:11:11,920
confidential folder without dlp co-pilot might pull that data and present it in the response even if

145
00:11:11,920 --> 00:11:16,560
the user has legitimate access the question creates a new copy of sensitive information in a new

146
00:11:16,560 --> 00:11:22,080
context once that summary exists in a new document it can be shared copied or leaked just like any

147
00:11:22,080 --> 00:11:26,560
other file dlp for co-pilot changes that by controlling what co-pilot can do with sensitive information

148
00:11:26,560 --> 00:11:31,360
it can block co-pilot from generating responses that contain sensitive data in our scenario co-pilot

149
00:11:31,360 --> 00:11:36,240
sees the sensitivity label on the quarterly financials recognizes the content is confidential

150
00:11:36,240 --> 00:11:41,360
and either blocks the summary entirely or excludes the sensitive parts this protection works across

151
00:11:41,360 --> 00:11:47,920
word excel powerpoint teams and outlook anywhere co-pilot appears Microsoft deployed default

152
00:11:47,920 --> 00:11:53,520
dlp policies for co-pilot in simulation mode in early 2026 so every tenant has a starting point but

153
00:11:53,520 --> 00:11:58,400
here's the catch those default policies are in simulation mode not actively blocking anything

154
00:11:58,400 --> 00:12:02,720
until you configure them many organizations think they're protected because they see the policy

155
00:12:02,720 --> 00:12:07,680
in the portal but unless enforcement is turned on co-pilot is still handing out sensitive data

156
00:12:07,680 --> 00:12:12,560
there's another angle too dlp can protect against the prompt itself if a user tries to paste

157
00:12:12,560 --> 00:12:18,800
sensitive data into a public AI tool like chat gpt endpoint dlp can block that paste using the same

158
00:12:18,800 --> 00:12:23,760
agent that blocks usb copies the risk isn't just what co-pilot reveals it's what your users accidentally

159
00:12:23,760 --> 00:12:29,200
feed into external AI models and here's a recent update that matters as of 2026 co-pilot will not

160
00:12:29,200 --> 00:12:33,920
interact with files that carry sensitivity labels at all no matter where you open them the label

161
00:12:33,920 --> 00:12:39,040
travels with the file and co-pilot respects it that's a clean boundary if a file is labeled highly

162
00:12:39,040 --> 00:12:45,440
confidential co-pilot won't touch it avoiding common mistakes now all of this sounds great on paper

163
00:12:45,440 --> 00:12:50,880
but here's the thing real world dlp deployments fail all the time it's almost never the technologies fault

164
00:12:50,880 --> 00:12:55,520
it's how the organization approaches it the biggest mistake people make is treating dlp as an

165
00:12:55,520 --> 00:13:00,560
IT project a team of admins sits in a room configures some policies and deploys them then users get

166
00:13:00,560 --> 00:13:05,520
blocked from doing legitimate work help desk calls spike policies get rolled back the security team

167
00:13:05,520 --> 00:13:10,640
loses credibility that's not how this works the dlp is a governance program not an IT project you need

168
00:13:10,640 --> 00:13:16,080
business stakeholders in the room legal compliance HR finance people who understand how data actually

169
00:13:16,080 --> 00:13:21,120
flows because if you block a workflow finance depends on to close the quarter you'll hear about it

170
00:13:21,120 --> 00:13:26,960
second mistake too many sensitivity labels some organizations launch with 15 or more labels nested

171
00:13:26,960 --> 00:13:32,960
sub labels names like semi restricted internal use only external sharing permitted with written

172
00:13:32,960 --> 00:13:37,520
approval users look at that and do one of three things they ignore labels entirely but they apply

173
00:13:37,520 --> 00:13:41,840
the default label to everything or they pick the lowest restriction to avoid friction none of

174
00:13:41,840 --> 00:13:46,640
those protect your data keep it simple start with three to five labels public internal confidential

175
00:13:46,640 --> 00:13:52,000
highly confidential expand only after people have adopted the basics third mistake only covering

176
00:13:52,000 --> 00:13:57,520
email this one's incredibly common an organization configures exchange dlp checks the box declares the

177
00:13:57,520 --> 00:14:02,400
job done but that policy does nothing for teams chats nothing for sharepoint bulk uploads nothing

178
00:14:02,400 --> 00:14:07,920
for someone copying files to usb drive you need to cover all the channels email sharepoint one drive

179
00:14:07,920 --> 00:14:13,680
teams and points and copilot each one is a separate door data can walk out of force mistake skipping

180
00:14:13,680 --> 00:14:18,320
simulation mode the temptation is to turn policies on immediately because you want protection now

181
00:14:18,320 --> 00:14:22,720
but that's how you break things always start in audit mode let the policy run log what it would

182
00:14:22,720 --> 00:14:26,960
have blocked and review the data you'll find legitimate workflows you didn't account for you'll

183
00:14:26,960 --> 00:14:31,920
see false positives you need to tune then move to policy tips warnings that educate users without

184
00:14:31,920 --> 00:14:37,440
blocking then after your confident turn enforcement on here's a practical 90 day plan day one deploy

185
00:14:37,440 --> 00:14:43,200
in audit mode only day 30 analyze the alerts and identify patterns day 60 tune your labels and

186
00:14:43,200 --> 00:14:48,080
exceptions based on what you've learned day 90 turn on enforcement targeting a false positive rate

187
00:14:48,080 --> 00:14:53,360
under five percent remember the number from the beginning 58% of leaks are accidental dlp isn't

188
00:14:53,360 --> 00:14:58,720
about punishing users it's about catching honest mistakes before they become headlines so here's

189
00:14:58,720 --> 00:15:03,520
what Microsoft purview dlp actually is it's a unified set of security guards that protect sensitive

190
00:15:03,520 --> 00:15:09,280
data across email files chats devices and ai tools it watches data in all three states at rest in

191
00:15:09,280 --> 00:15:15,040
motion and in use and it uses deep content analysis to understand what the data is not just

192
00:15:15,040 --> 00:15:19,840
what it looks like the goal isn't to lock everything down the goal is to stop the 58% of accidental

193
00:15:19,840 --> 00:15:26,080
leaks while letting people do their jobs because the vertifore story on 27.7 million records exposed by

194
00:15:26,080 --> 00:15:32,240
one innocent action happens every day in organizations that don't have these protections in place next time

195
00:15:32,240 --> 00:15:38,080
you hear about a data breach that was just an honest mistake remember dlp exists exactly for that

196
00:15:38,080 --> 00:15:42,240
subscribe on your favorite podcast platform and share this with someone starting their data security

197
00:15:42,240 --> 00:15:44,720
journey thanks for listening

