Microsoft Purview DLP for Azure SQL

Kansara, Ankit 20 Reputation points
2024-09-12T23:42:49.4833333+00:00

Hello,

I understand that Microsoft Purview DLP policies can be commonly used for Exchange, OneDrive, Teams, SharePoint, Endpoints, etc. which are commonly used exfiltration channels.

But can we also use a dlp policy for Azure SQL databases, is there any use case for a DLP policy for Azure SQL database or any other structured data?

Azure SQL Database
SharePoint
SharePoint
A group of Microsoft Products and technologies used for sharing and managing content, knowledge, and applications.
10,675 questions
Microsoft Purview
Microsoft Purview
A Microsoft data governance service that helps manage and govern on-premises, multicloud, and software-as-a-service data. Previously known as Azure Purview.
1,160 questions
OneDrive Management
OneDrive Management
OneDrive: A Microsoft file hosting and synchronization service.Management: The act or process of organizing, handling, directing or controlling something.
1,252 questions
{count} votes

Accepted answer
  1. Alberto Morillo 33,861 Reputation points MVP
    2024-09-13T01:43:18.2233333+00:00

    To my knowledge you cannot create DLP policies that apply directly on Azure SQL databases. However, you can create DLP policies in Microsoft Purview for scenarios like data exfiltration from Azure SQL to other Microsoft 365 services (commonly Excel and SharePoint are used to query data from Azure SQL). If data is exported from Azure SQL and used in Office files, the DLP policies in Microsoft 365 can prevent sharing information that you have classified as sensitive on Azure SQL.

    Enabling Azure SQL Auditng can help track activities that might involve sensitive data and detect possible violations.


1 additional answer

Sort by: Most helpful
  1. PRADEEPCHEEKATLA-MSFT 89,296 Reputation points Microsoft Employee
    2024-09-17T13:20:51.68+00:00

    @Kansara, Ankit - Thanks for the question and using MS Q&A platform.

    Unfortunately, Microsoft Purview DLP policies cannot be applied to Azure SQL or Azure SQL Databases.

    According to the official documentation: Learn about data loss prevention

    You can apply DLP policies to data at rest, data in use, and data in motion in locations such as:

    • Exchange Online email
    • SharePoint sites
    • OneDrive accounts
    • Teams chat and channel messages
    • Microsoft Defender for Cloud Apps (Instances)
    • Windows 10, Windows 11, and macOS (three latest released versions) devices
    • On-premises repositories
    • Fabric and Power BI workspaces

    Each one has different prerequisites. Sensitive items in some locations, like Exchange online, can be brought under the DLP umbrella by just configuring a policy that applies to them. Others, such as on-premises file repositories, require a deployment of Microsoft Purview Information Protection scanner. You'll need to prepare your environment, code draft policies, and test them thoroughly before activating any blocking actions.

    Appreciate if you could share the feedback on our feedback channel. Which would be open for the user community to upvote & comment on. This allows our product teams to effectively prioritize your request against our existing feature backlog and gives insight into the potential impact of implementing the suggested feature.

    Hope this helps. Do let us know if you any further queries.


    If this answers your query, do click Accept Answer and Yes for was this answer helpful. And, if you have any further query do let us know.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.