ITS Data Loss Prevention Initiatives
Note: As Microsoft improves the MS365 DLP product, users may see different behaviors in Outlook, depending on the client (e.g., web, desktop, mobile). If you experience any issue that impacts your ability to use Outlook, please contact the ITS Service Desk at umtech@memphis.edu or 901.678.8888.
Terms to know
Data Loss Prevention (DLP): An organization's strategies for keeping private and sensitive data safe from unauthorized access
Personally Identifiable Information (PII): Data that can be used to identify a unique individual, such as social security and driver's license numbers (protected under FERPA and HIPAA)
Payment Card Industry data (PCI): Information such as credit/debit card numbers and bank account data that can be used for financial transactions (protected under GLBA and PCI DSS)
DLP Tools
The University of Memphis currently enforces rigorous policies to keep data safe. ITS data storage procedures provide an overview of how information may be stored and who should have access to it, and IT6005 – Data Security Policy details the expectations for all UofM employees to limit the risk of data exposure. ITS has implemented tools to further ensure data confidentiality and regulatory compliance.
Microsoft 365 DLP
Microsoft 365 (MS365) offers DLP functionality to warn users when it detects potentially sensitive information. Outlook users composing emails that include PII/PCI will be alerted that the message or attachment could be in violation of University policy.
DLP policy tip in Outlook
A user who sends a message with data detected as potentially restricted will receive a system email describing the violation, and security administrators will be informed of the potential offense.
DLP warning email in Outlook
Currently, some restricted data may prevent emails from sending to external recipients. Outlook web and desktop app users may report false positives to avoid disruptions caused by misidentified information. See "My email was blocked by DLP." below.
Further functionality, such as detection of sensitive data with similar warnings in MS365 Word and Excel, may be implemented without notice.
Frequently Asked Questions
I sent an email with restricted data and received a warning email. What happens now?
A report will be sent to security administrators, who will determine whether any policies
were violated. You may be contacted for more information and provided guidance on
how to properly store and transmit restricted data.
What kind of restricted data will trigger a DLP warning?
A warning will be triggered if an email message or attachment contains text identified
by the DLP system as certain restricted data elements, including but not limited to
the following:
- U.S. Social Security Number (SSN)
- Individual Taxpayer ID Number (ITIN)
- Credit/debit card information
- Bank account information
- Driver’s license information
- U.S. passport number
I got a DLP warning, but my email didn’t include any restricted data. What should
I do?
The DLP software uses standardized rules to analyze text for PII and PCI data. An
email could include text that the system incorrectly recognizes as an indicator of
such data, thereby generating a false alert.
If you are confident your message and any attachments did not include restricted data, please disregard the warning.
My email was blocked by DLP. Can I override it and send anyway?
DLP in MS365 (current web and desktop versions only) will display a policy tip while
the email is being composed to warn the user that restricted data might be included.
If no restricted data is included in the email, users may view the details of the
restricted data, then click "Report" to report a false positive and override the sending
block. If the email is sent despite the warning, a warning email will be sent to the
user, and security administrators will be review the incident for potential violations
of University policy. The user’s original message is sent as intended.
I received a warning email after sending my message, but I never saw a policy tip
while composing it.
Your version of Outlook may impact the function of DLP policy tips. Tips may not be
not available in the mobile app, and desktop app tips may show unexpected behavior
as Microsoft continues to improve the DLP product. However, warning emails will still
be delivered when restricted data is detected after a message is sent.
Are my emails being read by a University employee?
In accordance with University policy IT6003 – Acceptable Use of Information Technology Resources, “The University does not routinely monitor electronic communications, electronic
activity, or electronic data for specific users.” The MS365 DLP tool scans the text
of all email and compares it to a set of rules designed to detect specific restricted
data, such as SSN or credit card numbers, just as the spell check tool does for spelling
and grammar. This text is treated the same as any other email.
However, as further stated in the above policy: “The University may monitor electronic communications or electronic activity in the course of protecting University information,” including “investigations of misuse, unauthorized use or illegal activity.” In the event of a policy violation, appropriate administrators will follow up with the user. Users should be aware of and follow all University policies regarding technology use, including IT6008 – Email Use. These policies can be found on the ITS Policies and Procedures page.
I need to send a document that contains restricted data. How can I do that safely?
Email is not an approved method for sending or storing restricted data. If you have
a legitimate need to send restricted PII or payment data, please review the University Data Storage Procedures. For more guidance, please contact the ITS Service Desk at 901.687.8888 or umtech@memphis.edu.
