MDA ‐ Block cut copy paste print - mattnovitsch/M365 GitHub Wiki
Summary
Blocking cut, copy, paste, and printing is something we might want to do for devices that are BYOD. A common situation is allowing users to check their emails at home but making sure they don't copy data off to their personal devices.
Prerequisites
Steps to prevent cut/copy/paste/print
-
Navigate to Defender XDR
-
Navigate to Cloud Apps > Policies > Policy Management > Create Policy > Session Policy
-
Give your policy a name for example "Block cut/copy/paste/print"
-
Under Session Control Type: Select Block Activities
-
Under "Activities matching all of the following" a. Device is optional (However the default is for a BYOD situation) b. App is for any application you want, if you want all of them then just remove it. c. Activity Type should equal what function you want to block. I selected all for this example.
-
If you want to use the labels from Purview you can do that to prevent just those items from being cut, copy, paste, and printed.
-
Under Actions, we want to block.
- Note you can add a custom block message to your environment
- I would strongly recommend turning off Alerts for this policy so you are not spammed with alerts that you would just have to close. You can do reporting data in Advance Hunting if you want to see the data.
- Save Policy
- Note the policy will take effect next time you close the sessions and re-establish a connection. It will NOT apply to current sessions.
- Also Note the screenshot below is for blocking print, paste, copy and cut for all cloud apps for Soren when he is not on a corporate managed device.