I had different use cases with Microsoft Purview Data Loss Prevention. One of my customers was already working with McAfee DLP, and they migrated from McAfee DLP to Microsoft DLP. I had to do the entire migration and ensure it was working as they expected. They had selected the tool, but I had to ensure it was implemented throughout and tested. It was live in the environment as well.
In this case, I implemented Microsoft DLP for four Microsoft services, including OneDrive, Teams, SharePoint, and Exchange email. An endpoint DLP was implemented for the endpoints.
The solution's most valuable feature is the mature O365 DLP, which works with SharePoint and Teams. It works fine, but we have to make sure that we are doing it right.
My main concern was more about the endpoint side because you should have many different functionalities on the endpoint. Endpoints are not just about the USB or the network share. They deal with many things, and we should be able to understand them.
We should have different settings available on the endpoints about what should be allowed, what should not be allowed, off the network, on the network, etc. The endpoint needs some improvement.
A major improvement is required in the solution's incident handling and alerting. It is a mess, and it cannot handle anything. I don't know what Microsoft is doing. It is really sad. It is a very good endpoint product but does not work as expected.
If an email is detected, I have email evidence because it is going through the exchange. I can download the image, and the operations team can look into the kind of email sent and so on. The evidence is there for forensic purposes.
Microsoft has given functionality for endpoints where anything violating the content on the endpoint should be uploaded to some storage location in Azure Cloud for evidence purposes, which does not work at all. Microsoft has provided it, but their technical team does not know how these things work, which is really sad.
The solution's incident handling is pathetic. They have the compliance portal and security portal. You get alerts on both the compliance portal and the security portal. Having two different alerts on the security and compliance portals does not make sense.
Incidents are not categorized properly. All the incidents are put together, which is really sad. It's not about detecting the data; it's more about handling it once it is detected. I know the data has been detected, but it is useless if I cannot figure it out or work on the incidents. The tool does not make sense to me.
You would face some difficulties on the endpoint side. It is really difficult when you're working on the endpoints. Microsoft is not clear on how they want to portray this product.
For the past four years, I've worked on and off with different tools, including Microsoft Purview Data Loss Prevention. I have at least three years of experience with Microsoft Purview Data Loss Prevention.
The solution’s technical support is pathetic.
You cannot compare Microsoft with other DLP products because they are very mature products. Microsoft is not a mature product. It gives you the functionalities, and organizations buy it because they need not spend elsewhere for these options.
People should think a lot before choosing Microsoft Endpoint products. Data security is very important, and we cannot just choose a solution because you're getting it for free.
On a scale from one to ten, where one is difficult and ten is easy, I rate the solution's initial setup a seven out of ten.
You get the solution in a bundle if you get the E5 suite. Some additional charges are there for your endpoint DLP because that comes with your endpoint management.
Overall, I rate the solution a seven out of ten.