A unified data governance solution that helps manage, protect, and discover data across your organization
Hello @Ganesh Kitte ,
Thank you for sharing your requirements regarding extending Data Loss Prevention (DLP) controls to third-party SaaS applications such as Salesforce, Keka HR, and future cloud applications.
Based on our analysis, Microsoft 365 Business Premium provides Microsoft Purview DLP protection for Microsoft 365 workloads, including Exchange Online, SharePoint Online, OneDrive, and Microsoft Teams. However, additional capabilities are required to extend DLP and real-time protection to third-party SaaS applications. Use data loss prevention policies for non-Microsoft cloud apps
Recommended Mitigation and Architecture
- Utilize Microsoft Defender for Cloud Apps (MDCA) to provide visibility and governance for supported third-party SaaS applications.
- Configure Microsoft Purview DLP policies for supported connected applications such as Salesforce. Use data loss prevention policies for non-Microsoft cloud apps citeturn4search9
- Implement Conditional Access App Control through Microsoft Defender for Cloud Apps to monitor user activities and enforce real-time controls such as:
- Blocking sensitive uploads
- Restricting downloads
- Preventing data exfiltration
- Session monitoring and access control Conditional Access app control - Microsoft Defender for Cloud Apps
- For Keka HR and future SaaS applications, validate support for Microsoft Entra ID Single Sign-On (SSO), SAML 2.0, or OpenID Connect authentication, as these are prerequisites for onboarding custom applications through Conditional Access App Control. Manual onboarding of apps using Microsoft Entra ID citeturn4search7
- Adopt a centralized security model using:
- Microsoft Purview DLP
- Microsoft Defender for Cloud Apps
- Microsoft Entra Conditional Access
- Microsoft Defender for Cloud Apps
- Microsoft Purview DLP
Next Steps
- Review current licensing to determine the required Microsoft Defender for Cloud Apps and Microsoft Purview add-ons.
- Validate third-party application compatibility with Microsoft Entra ID federation.
- Identify applications requiring data-at-rest protection versus real-time session controls.
- Design and test onboarding for supported SaaS applications before production deployment.
Please let us know if you would like assistance reviewing the licensing requirements or validating specific SaaS applications for onboarding and DLP enforcement.
Best Regards,
Sivasankar Yeddula
Microsoft Azure Support.