SC-401 Lab 6 – Configure Endpoint DLP

Enable and validate Endpoint Data Loss Prevention policies to monitor and restrict sensitive data activity on devices.

Tools Used

Steps Taken

  1. Signed into Microsoft Purview portal as MOD Administrator.
  2. Navigated to Data Loss Prevention → Endpoint DLP Settings.
  3. Enabled Endpoint DLP and onboarded devices using Defender for Endpoint integration.
  4. Created a new Endpoint DLP policy targeting file copy and print actions.
  5. Configured conditions using sensitive information types and location filters.
  6. Deployed policy and verified enforcement on test device.
  7. Reviewed audit logs and alerts in Microsoft Defender portal.

Outcome

Endpoint DLP successfully configured and validated. Devices now enforce restrictions on sensitive data actions, supporting compliance and insider risk mitigation.

Certification Alignment

SC-401 Domain 1.3 – Implement Data Loss Prevention Solutions

Sandbox Link

Lab 6 – Configure Endpoint DLP