In CAS we can focus policies to dedicated object. For example, you have a SharePoint Online Site with sensitive content, and you will get informed if a user is doing a mass download.
We can use the “Mass download by a single user” template to set up a policy:
In the
filter section if the policy select “edit and preview results”:
In the
shown activities list search for the location or event ion which you will
filter. In my demo I take https://sharepointtalk.sharepoint.com/teams/SearchDemo2:
Selecting “Activity
Objects” opens a report with all objects and its ID´s. To filter on the SharePoint
SiteCollection URL we need the second one:
Now we can use
this ID as a filter:





The article provides a practical example of using Cloud App Security policies to focus monitoring on a specific SharePoint Online site. The “Mass download by a single user” policy template is especially useful for detecting unusual download activity when sensitive content is involved.
AntwortenLöschenThe approach of using “edit and preview results” to identify the relevant activity objects makes the filtering process much clearer. Using the SiteCollection object ID as a filter also provides a precise way to limit the policy to the intended SharePoint environment.
This type of object-level monitoring is closely related to Cloud Security Projects, particularly when designing controls for protecting cloud-hosted data and detecting suspicious user activity.
The focus on protecting sensitive SharePoint content and controlling access activity also connects naturally with Information Security Projects, where identifying and responding to potentially unauthorized data movement is an important consideration.
AntwortenLöschen