How does this align with Essential Eight?
π Restrict Administrative Privileges
This policy enforces access boundaries by detecting when sensitive financial data is shared externally.
This supports the principle of least privilege and help prevent unauthorised data exposure.
β
π§Ύ Policy Overview
π§ Name: E8-IBP-Australia Financial Data
π Type: Data Loss Prevention (DLP) Simulation Policy
π Scope: Exchange, SharePoint, OneDrive for Business, Teams, On-Premises Scanner
π§ͺ Mode: TestWithoutNotifications (Audit)
π οΈ Status: Distribution Pending (Sync Successful)
π¦ Target Locations: All Exchange, OneDrive, SharePoint, Teams, On-Premises Scanner
π Minimum Licensing Requirement: Microsoft 365 Business Premium
π§ Detection Logic
This policy helps detect high volumes of sensitive financial data in Australia, including:
π³ Credit Card Numbers
π¦ Australia Bank Account Numbers
π§Ύ Australia Tax File Numbers
π SWIFT Codes
Detection is based on confidence levels and minimum counts:
High volume rule triggers on β₯10 instances
Low volume rule triggers on 1β9 instance
π£ Notifications & Alerts
π Alerts generated for Site Admin
π§ Notifications sent to Site Admin, Last Modifier, and Owner
π Email attachments included in notifications
π« No quarantine or access blocking (simulation mode only)
