Skip to content

Commit

Permalink
Update sensitive-by-default.md
Browse files Browse the repository at this point in the history
  • Loading branch information
ybhargav1995 authored Nov 28, 2024
1 parent 629ee32 commit 1cf10cb
Showing 1 changed file with 3 additions and 0 deletions.
3 changes: 3 additions & 0 deletions SharePoint/SharePointOnline/sensitive-by-default.md
Original file line number Diff line number Diff line change
Expand Up @@ -25,6 +25,9 @@ description: "Learn how to block external sharing of newly added SharePoint and

# Prevent guest access to files while DLP rules are applied

[!NOTE]
> Any user whose usertype is member are considered internal and users with member type Guest are only considered external

When new files are added to SharePoint or OneDrive in Microsoft 365, it takes a while for [Microsoft Purview Data Loss Prevention (DLP) policy](/microsoft-365/compliance/dlp-learn-about-dlp) to scan the content and apply rules to help protect sensitive content. If external sharing is turned on, sensitive content could be shared and accessed by guests before the DLP rule finishes processing.

Instead of turning off external sharing entirely, you can mark the files in your organization as sensitive by default. This blocks guest access to new content until it's scanned for sensitive content and DLP policies that include content-based conditions are applied. Guests are notified that the file is being scanned if they attempt to access it during this time.
Expand Down

0 comments on commit 1cf10cb

Please sign in to comment.