Microsoft MD-102: Data Protection and Information Governance — Study Guide
Part of the Microsoft Endpoint Administrator Associate MD-102 — Study Guide. Practice with verified answers in the Microsoft exam hub, or take timed practice tests on ExamRoll.io.
Overview
Data protection and information governance in Microsoft 365 and Intune rely on unified labeling, endpoint-aware DLP, app-level protections, and real-time session controls that extend to cloud apps. In this domain you use Microsoft Purview Information Protection for labeling and encryption, Purview Data Loss Prevention (DLP) for endpoint activities, Intune Mobile Application Management (MAM) for app-centric safeguards, Microsoft Defender for Cloud Apps for in-session controls, and Purview Insider Risk Management and eDiscovery to investigate and respond. The objective is to ensure sensitive data is classified and protected wherever it travels—on devices, within managed apps, and across sanctioned SaaS services—while providing auditable controls to satisfy regulatory and organizational requirements.
Microsoft Purview Information Protection and Endpoint DLP
Sensitivity labels classify and protect content at the file, email, and container level. Labels can apply encryption (with usage rights and offline access duration), content marking (headers, footers, watermarks), and scoping to locations such as files, email, SharePoint, and Teams. You publish labels to users and groups with label policies. Policies define which labels are visible, default label behavior, whether labeling is mandatory, justification for label downgrade/removal, and whether users are prompted with recommended labels. Label priority (order) determines which label wins when conflicts occur.
Automatic and recommended labeling extend the same label taxonomy to devices. Modern Office apps with built-in sensitivity labeling on Windows, macOS, iOS, and Android can evaluate content as the user creates or edits it. Recommended labeling presents a prompt and justification flow; automatic labeling silently applies the label when confidence thresholds are met. Conditions include sensitive info types (e.g., PCI, PII), exact data match (EDM), keyword dictionaries, proximity, and trainable classifiers for context-aware detection. For files at rest on Windows endpoints, auto-labeling can also be powered by endpoint DLP, allowing enforcement even outside Office apps when files match DLP conditions.
Purview Data Loss Prevention unifies policies across Exchange, SharePoint/OneDrive, Teams, and endpoints. Endpoint DLP requires onboarded devices (Microsoft Defender for Endpoint) and enables control over sensitive files on Windows 10/11 and macOS. Endpoint DLP evaluates file sensitivity based on labels and content inspection and enforces rule actions: audit, block, or block with user override and business justification. Policy tips guide user behavior at the point of risk.
Endpoint DLP monitors sensitive file activities and can restrict them:
- Copying to removable storage (USB), Bluetooth, and virtual drives
- Copying to network shares and remote shares
- Uploading via supported browsers to domains categorized as service domains (e.g., personal cloud storage) or explicitly defined destinations
- Printing to local, network, and virtual printers (including Print to PDF)
- Copy/paste to unmanaged applications or processes
- Creating archives (e.g., ZIP) that include sensitive files
- Access in remote sessions (RDP), including redirection scenarios
- Screen capture attempts and unapproved app access when combined with device control settings
Activity Explorer and DLP Alerts in the Microsoft Purview compliance portal provide near real-time visibility of endpoint events and user justification trails. Device onboarding and policy deployment are typically automated via Intune for MDE onboarding and policy delivery, keeping device coverage in lockstep with enrollment.
Intune App Protection (MAM): Data Transfer, Encryption, Clipboard, and Platform Conditions
App protection policies (MAM) separate work data from personal data within apps, without requiring device enrollment. Policies target user identities and supported apps (e.g., Microsoft 365 apps, Microsoft Edge, and partner apps integrated with the Intune SDK or App Wrapping Tool). You control the flow and storage of corporate data at the app layer with precision.
Data transfer controls limit where corporate data can move. The “Send org data to other apps” and “Receive data from other apps” options determine if sharing is allowed to policy-managed apps only, to any app, or blocked. Clipboard controls enforce “Restrict cut, copy, paste with other apps” with modes such as blocked, policy-managed apps only, or allowed any time. You can require corporate web links to open in Microsoft Edge with app protection so that browser-based downloads inherit policy.
Save-as restrictions ensure corporate data lands only in approved storage. You can allow saving copies of organizational data to OneDrive for Business and SharePoint while blocking local device storage or third-party clouds. Edge integration adds further controls for file downloads and SharePoint/OneDrive account context to prevent data leakage to personal locations.
App-level encryption protects data at rest within the app container. MAM uses platform-native cryptography (e.g., iOS Data Protection classes, Android keystore) to encrypt work data when the app is at rest. Access requirements enforce a PIN or biometric for app launch or resumption, with configurable complexity, timeout, and recheck frequency. You can block app access or selectively wipe corporate data when conditions fail or risk is detected. On Android, you can block screen capture and Assistant; on iOS, the OS does not permit third-party blocking of screenshots, but you can prevent backups to iCloud/iTunes and restrict document interaction to managed destinations.
Conditional launch enforces platform posture at runtime. You can require a minimum OS version and minimum app version, block jailbroken/rooted devices, and require device threat level below a threshold when integrated with Microsoft Defender for Endpoint Mobile. Violations can trigger user warnings, require PIN reset, block access, or initiate a selective wipe of organizational data from the app, preserving personal data.
These MAM protections complement, rather than replace, device-based controls. For corporate devices, combine MAM with endpoint DLP, device compliance, and Conditional Access to ensure only healthy devices and compliant app contexts can access corporate resources.
Real-time Session Controls with Microsoft Defender for Cloud Apps
Microsoft Defender for Cloud Apps (MDCA) enforces real-time controls in SaaS sessions. Conditional Access App Control routes user web sessions through MDCA’s reverse proxy when a Conditional Access policy is set to Use Conditional Access App Control for specific apps and users. You can choose Monitor only, Monitor and block (Control), or Block.
Session policies in MDCA enable granular actions:
- Block or watermark downloads when files are labeled sensitive, or apply a sensitivity label to files on download
- Restrict cut/copy/print in the browser for high-risk sessions
- Limit access to web-only experiences and block file uploads or sync
- Require reauthentication or step-up authentication based on session risk or activity
- Govern unsanctioned SaaS by blocking downloads or exfiltration attempts while still allowing productivity
MDCA integrates with Purview Information Protection, enabling policy decisions based on sensitivity labels and DLP detections. Activity logs from sessions feed into centralized auditing and can trigger alerts for anomalous behavior that may indicate exfiltration or misuse.
Insider Risk Management, eDiscovery, and Device Data in Purview
Insider Risk Management in Microsoft Purview correlates signals across endpoints and cloud services to detect risky sequences such as mass downloads, unusual transfers to personal clouds, printing bursts, copying to USB, forwarding to personal email, or anonymization attempts. Indicators include:
- Endpoint DLP events (e.g., blocked/overridden actions)
- Microsoft 365 activity (SharePoint/OneDrive/Teams file access and sharing)
- Defender for Cloud Apps session anomalies
- HR events (e.g., user termination) via connectors
- Security policy violations and alert context from Microsoft Defender
Policy templates accelerate deployment for common scenarios: Data theft by departing users, Data leaks (general), Security policy violations, Data spillage, and Priority user risks. Policies define scopes (users/groups), triggering indicators, risk scoring thresholds, and escalation workflows. Privacy is preserved via pseudonymization until a case is escalated by authorized roles, with full auditability of reviewer actions.
For investigations and legal response, Microsoft Purview eDiscovery (Standard and Premium) centralizes data discovery, legal hold, and collection. While legal hold primarily targets Exchange, SharePoint/OneDrive, and Teams, device-side evidence is available through multiple channels:
- Endpoint DLP provides device, user, and file activity in Activity Explorer and DLP alert details, establishing a timeline of endpoint interactions with sensitive data
- Integration with Microsoft Defender for Endpoint enables eDiscovery (Premium) device collections for custodians, targeting Windows 10/11 endpoints to collect specific files from known locations with defensible chain of custody
- Microsoft 365 Audit logs capture user and admin actions across services; MDCA session logs add in-session web activity context These capabilities allow you to stitch together device, cloud, and session-level evidence, apply holds to custodial data where supported, and perform targeted, privacy-aware collections that minimize business disruption.
Practical Problem Scenario
Contoso Ltd. needs to prevent financial data from leaving corporate boundaries on both managed Windows laptops and personal mobile devices, while enabling analysts to work in sanctioned SaaS apps. The organization must investigate suspected exfiltration quickly and preserve evidence.
Define sensitivity labels in Microsoft Purview for Public, Confidential, and Confidential-Finance with encryption for the Finance label, scoped to documents and email. Publish labels to Finance and Compliance groups with a policy that makes labeling mandatory and sets Confidential-Finance as the default for finance users. This ensures consistent classification and protection at the source using native labeling in Office across devices.
Enable automatic and recommended labeling for Office apps with conditions matching financial PII (e.g., ABA routing numbers, account numbers via EDM). Configure recommended labeling prompts for ambiguous detections and automatic labeling for high-confidence matches. This captures sensitive content created on devices, reducing user error without blocking productivity.
Onboard Windows 11 devices to Microsoft Defender for Endpoint via Intune and enable Endpoint DLP with rules for Confidential-Finance and financial sensitive info types. Set actions to Block with override for printing, USB copy, and upload to personal cloud domains; Audit for file rename and archive creation. This enforces protections even outside Office and records user justifications for compliance review.
Create Intune MAM app protection policies for iOS and Android that require app-level encryption, a PIN/biometric, and minimum OS versions. Restrict cut/copy/paste to policy-managed apps, force corporate links to open in Microsoft Edge, and limit Save As to OneDrive for Business and SharePoint. Block Android screen capture and backups to personal clouds on iOS. This isolates and protects corporate data on personal devices without enrollment.
Configure Conditional Access to require compliant devices for desktop access and Use Conditional Access App Control for web access to sanctioned SaaS (e.g., Box for Partners). In Microsoft Defender for Cloud Apps, create session policies to watermark and block downloads of labeled content, and to apply a Finance label on download where appropriate. This provides real-time, app-agnostic control over data egress in browsers.
Deploy Insider Risk Management using the Data theft by departing users template, connected to HR termination events. Include indicators from Endpoint DLP, MDCA sessions, and SharePoint downloads, with risk scores and escalation workflows to the Compliance team. This detects likely exfiltration sequences during high-risk periods with privacy controls.
Prepare for investigations in Microsoft Purview eDiscovery (Premium) by enabling device collections via Defender for Endpoint. When an alert triggers, add the custodian, place relevant mailboxes and sites on hold, and run a targeted device collection for specified file paths and hash values. Correlate with Endpoint DLP Activity Explorer and MDCA session logs. This delivers defensible, targeted evidence collection across cloud and endpoints with minimal disruption and full auditability.
Contoso chose Purview Information Protection and label policies for consistent classification and encryption at creation, Endpoint DLP for device-level enforcement regardless of app, Intune MAM to protect corporate data on personal devices, Defender for Cloud Apps to control data in real time within SaaS sessions, Insider Risk Management to surface risky behavior with context, and Purview eDiscovery to investigate and collect evidence across cloud and endpoints.
← Remote Management and Monitoring · All domains · Intune Administration and Governance →
Practice these questions → · Timed practice on ExamRoll.io →
Pass the whole exam — not just this question
You found this answer. Get every verified question and explanation in one place, and save hours of prep. Free to start.
Pass your exam →