Analytics BIOC
Informational
✕
Microsoft 365 DLP policy disabled or removed
A user disabled or removed a Microsoft 365 data loss prevention (DLP) policy, which may indicate DLP monitoring evasion.
- Module:
- Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security
- Licensed by:
- Identity Threat Detection (ITDR)
- Licensed by:
- Email Security
- Data source:
- Office 365 Audit
ATT&CK tactics: Defense Evasion (TA0005)
ATT&CK techniques: Impair Defenses (T1562) Impair Defenses: Disable or Modify Tools (T1562.001)
Attacker's goals:
An attacker is attempting to bypass Microsoft 365 Data Loss Prevention (DLP) policies.
Investigative actions:
Follow further actions done by the account. Verify that the configuration change was expected. Look for signs that the user account is compromised (e.g. abnormal logins, unusual activity). Monitor the user's activity for any access to sensitive data or data exfiltration. Investigate if any other security policies have been changed or removed.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day
1 variation:
- Rare Microsoft 365 DLP policy removal Low (parent: Informational)