r/Office365 • u/Severe_Part_5120 • 6h ago
genai paste is our dlp blind spot, purview cant see it...thoughts?
we have purview doing dlp at the m365 layer and it works fine for email and sharepoint. but the gap is the browser itself...specifically genai tools and random web apps where content gets typed or pasted outside anything purview sees.
yes often two approaches i keep seeing are (1) push dlp policy down into the browser layer and feed events back into the existing dlp console for a single pane, or (2) run a separate browser dlp product and accept you're managing two policy engines and two sets of alerts. option 2 is what we have today and it's not great.. i mean analysts context switching between consoles all day, browser alerts needing their own triage logic anyway.
so posting here to understand ...has anyone gotten a browser layer tool to feed clean events into purview or symantec without a separate soc workflow? tbf im less interested in whether an integration "exists" and more in what the event payload actually looks like once it lands, whether your analysts could triage browser events with the same muscle memory as native purview alerts.