DLP-01: Enable Sensitive Data Classification

Frequently asked questions about implementing and managing the DLP-01 security control in Microsoft 365 and Entra ID.

Q
What is DLP-01 (Enable Sensitive Data Classification)?
A

DLP-01 is a security control that without data classification, you cannot protect what you cannot identify. sensitivity labels enable targeted protection policies, ensuring sensitive data receives appropriate controls regardless of where it is stored or shared. It requires that microsoft purview sensitivity labels are configured and at least 3 sensitivity levels are defined (e.g., public, internal, confidential), labels are applied to sensitive data in sharepoint and onedrive.

Related controls:DLP-01
Q
Why is Enable Sensitive Data Classification important for Microsoft 365 security?
A

Without data classification, you cannot protect what you cannot identify. Sensitivity labels enable targeted protection policies, ensuring sensitive data receives appropriate controls regardless of where it is stored or shared.

Related controls:DLP-01
Q
How do I implement DLP-01 in my tenant?
A

DLP-01 requires manual implementation. Requires Microsoft Purview license and configuration

Related controls:DLP-01
Q
What license do I need for DLP-01?
A

This control requires Microsoft 365 E5 Compliance add-on or E5 licensing.

Related controls:DLP-01
Q
Which security baseline includes DLP-01?
A

DLP-01 is included in the Enhanced Security baseline (Level 2). This level adds stricter controls for security-conscious organizations.

Related controls:DLP-01

5

Questions

1

Related Controls

Categorized

Related Resources

Still have questions?

Our security experts are here to help. Start a free trial and get personalized guidance for your Microsoft 365 environment.

Start Free Trial