Data Loss Prevention
These guidelines provide recommendations for Texas A&M University System members to implement Data Loss Prevention (DLP) with Microsoft Purview to help protect Social Security Numbers, taxpayer identification information, and student identification numbers from unauthorized transmission.
Purpose
Data Loss Prevention (DLP) is the set of tools and controls used to detect, monitor, and stop the unauthorized transmission of sensitive information outside of an approved boundary. DLP may be implemented through Microsoft Purview, which continuously inspects email, chat, cloud storage, and endpoint activity for content that matches defined sensitive information types, and intervenes in real time when that content is about to be shared, copied, or transmitted improperly.
Why DLP Matters
The system holds vast quantities of information about students, employees, and research subjects that carries real consequences if exposed. Social Security Numbers, taxpayer identification information, and student identification numbers are chief among them. A single email sent to the wrong recipient, an uploaded spreadsheet, or a misdirected file share can expose thousands of records at once. Unlike a password compromise, which typically affects one account, a data loss event can affect an entire population of students or employees simultaneously. The resulting harm (identity theft, tax fraud, or violations of student privacy) can follow an individual for years.
Beyond protecting individuals, DLP is how the system demonstrates and enforces compliance with federal and state requirements, including:
- The Family Educational Rights and Privacy Act (FERPA)
- The Gramm-Leach-Bliley Act (GLBA) as it applies to financial and taxpayer data
- Texas Administrative Code and Texas Government Code requirements for safeguarding confidential information
Microsoft Purview allows members to translate these legal obligations into enforceable, automated controls rather than relying solely on user training and manual review. Users of system information resources should comply with applicable DLP controls.
Microsoft Purview DLP Implementation
The following steps describe how to configure and maintain DLP protections for Social Security Numbers, taxpayer information, and student identification numbers:
-
Create the DLP configuration. A DLP policy is created within the Microsoft Purview compliance portal and scoped to the locations that require protection, including Exchange email, SharePoint, OneDrive, Teams chat, and endpoint devices.
-
Include the three protected forms of identity. Rules should detect the following sensitive information types. Transmission of any one of them outside an approved boundary should trigger the control:
- Social Security Numbers (SSNs)
- Taxpayer information, including Employer Identification Numbers (EINs) and Individual Taxpayer Identification Numbers (ITINs)
- Student identification numbers (UINs)
-
Scope tenant-wide with an approved exception list. Apply the control across the tenant to any user or group that is not explicitly named on an approved exception list. Exceptions should be reserved for roles (such as Financial Aid, the Registrar, or Human Resources) that have a documented, legitimate business need to transmit this information. Each exception should be reviewed and approved before it is added.
- Exception list access should be granted for a limited time when possible (for example, during admission periods) rather than on a standing basis. Time-bound access reduces the risk of privilege creep when an employee leaves the member or changes roles.
-
Set the confidence level for each information type to Low. A Low match confidence instructs Purview to act on content that only loosely resembles the pattern of an SSN, taxpayer number, or student ID, rather than requiring a near-certain match.
A low-confidence threshold increases the likelihood of false positives (content that is flagged but does not actually contain sensitive data). That is a deliberate, risk-averse design choice. Because the consequences of a true data loss event (identity theft, regulatory penalties, and loss of institutional trust) are far more severe than the inconvenience of a blocked or reviewed message, members should intentionally err on the side of caution. A wider net catches sensitive data that a high-confidence setting would miss. False positives should be addressed through user override requests and periodic tuning rather than by loosening detection up front.
Testing, Review, and Monitoring
Once configured, DLP controls should be:
- Tested in simulation mode before enforcement
- Reviewed on a recurring basis as new data patterns and business needs emerge
- Monitored through incident reports to identify trends, refine the exception list, and confirm the controls continue to meet compliance and protection objectives
Questions
Questions regarding these guidelines may be directed to TAMUS Cyber Engagement or your system member's Information Security Officer.