A unified data governance solution that helps manage, protect, and discover data across your organization
The current configuration does not mean the policy will evaluate all users everywhere just because the locations are set to All accounts or All sites.
Supported behavior by location is:
- Exchange Online supports Administrative Units.
- SharePoint supports Administrative Units.
- OneDrive supports Administrative Units.
For these locations, when the policy is scoped to an Administrative Unit, the policy is limited to that Administrative Unit for the supported workload.
For the expected result described:
- only users in the Administrative Unit participate in the REF test
- their activity is evaluated in Exchange Online, SharePoint Online, and OneDrive
- users outside the Administrative Unit do not receive the policy tip
the Administrative Unit is the key boundary for the policy.
Specific guidance by workload:
- Exchange Online
- Exchange supports Administrative Units.
- If the policy is scoped to the Administrative Unit, selecting All accounts at the Exchange location does not require duplicating the same users or groups again under Exchange scoping.
- Adding the same users/groups again would be unnecessary duplicate scoping.
- OneDrive
- OneDrive supports Administrative Units.
- If the policy is scoped to the Administrative Unit, selecting All accounts for OneDrive does not require selecting the same users or groups again under the OneDrive location.
- Duplicate user/group scoping is unnecessary unless there is a separate need to narrow the scope further.
- SharePoint Online
- SharePoint supports Administrative Units.
- The documented behavior is explicit: if the policy is scoped to an Administrative Unit that includes SharePoint sites, the policy will only apply to all sites in the Administrative Unit, and no further scoping is possible.
- This means SharePoint behavior depends on whether the Administrative Unit includes SharePoint sites. It is not described as “all activity on all sites by AU users.”
- With All sites selected, the policy does not become tenant-wide for all users if the policy is scoped to an Administrative Unit. For SharePoint, the Administrative Unit still constrains scope.
Recommended configuration for the test objective:
- Scope the DLP policy to the Administrative Unit that contains the intended REF test population.
- Keep Exchange email = All accounts.
- Keep OneDrive accounts = All accounts.
- For SharePoint, verify that the Administrative Unit includes the SharePoint sites that should be in scope.
- Do not add the same test users/groups again under Exchange or OneDrive unless there is a deliberate need to narrow scope further.
Important SharePoint caveat:
- SharePoint scoping under an Administrative Unit is site-based at the Administrative Unit level.
- If the relevant SharePoint sites are not part of the Administrative Unit, the policy will not apply to those sites.
- Also, when the policy is scoped to an Administrative Unit that includes SharePoint sites, no additional SharePoint site scoping is available.
So, the current configuration meets the expected result for Exchange Online and OneDrive without needing duplicate user/group selection in those locations.
For SharePoint Online, the current configuration meets the expected result only if the Administrative Unit includes the SharePoint sites intended for the REF test. If the Administrative Unit contains only users/groups and not the needed SharePoint sites, then the SharePoint portion will not align with the expected result.