|
| 1 | +Named Entity Sensitive Information Types (SITs) are pre-built, Microsoft-managed classifiers designed to detect common sensitive entities like people's names, physical addresses, and medical terminology. Unlike custom SITs that organizations create for specific business needs, Named Entity SITs are provided by Microsoft and enable organizations to implement sophisticated data protection without requiring custom development. By configuring Named Entity SITs in auto-labeling policies and DLP rules, organizations can automatically classify and protect content containing sensitive personal information, employee data, and domain-specific terminology. This transforms data protection from purely technical pattern-matching (like detecting credit card numbers or social security numbers) into intelligent, semantically-aware classification systems that understand context. Organizations handling content with sensitive entity information—executive communications, customer data, medical records, or other high-sensitivity content—should deploy at least one Named Entity SIT in their protection policies. Demonstrating Named Entity SIT deployment shows sophisticated, context-aware information protection beyond basic generic SIT detection. |
| 2 | + |
| 3 | +**Remediation action** |
| 4 | + |
| 5 | +To deploy Named Entity SITs in your policies: |
| 6 | + |
| 7 | +**Option 1: Deploy via DLP Policy** |
| 8 | +1. Sign in as Global Administrator or Compliance Administrator to the [Microsoft Purview portal](https://purview.microsoft.com) |
| 9 | +2. Navigate to [DLP Policies](https://purview.microsoft.com/datalossprevention/policies) |
| 10 | +3. Create a new DLP policy or edit an existing one |
| 11 | +4. Add a rule with condition: "Content contains sensitive information" |
| 12 | +5. Select Named Entity SITs from the dropdown: |
| 13 | + - **All Full Names** - Detects common and uncommon full names worldwide |
| 14 | + - **All Physical Addresses** - Detects addresses in various formats |
| 15 | + - **All Medical Terms and Conditions** - Detects medical terminology and conditions |
| 16 | + - **Country/Region-Specific Variants** - e.g., "Austria Physical Addresses", "Canada Physical Addresses" |
| 17 | +6. Configure the action (notify user, restrict access, send alert, etc.) |
| 18 | +7. Specify the workload scope (Exchange, SharePoint, OneDrive, Teams, Power BI) |
| 19 | +8. Enable and deploy the policy |
| 20 | + |
| 21 | +**Option 2: Deploy via Auto-Labeling Policy** |
| 22 | +1. Navigate to [Auto-Labeling Policies](https://purview.microsoft.com/informationprotection/autolabeling) |
| 23 | +2. Create a new auto-labeling policy or edit an existing one |
| 24 | +3. In the rule configuration, add a condition: "Content contains sensitive information" |
| 25 | +4. From the sensitive information types list, select Named Entity SITs (e.g., "All Full Names") |
| 26 | +5. Configure the sensitivity label to apply when content matches |
| 27 | +6. Set the policy scope (Exchange, SharePoint, OneDrive, Teams, Power BI, or All) |
| 28 | +7. Enable and deploy the policy |
| 29 | + |
| 30 | +**View Available Named Entity SITs:** |
| 31 | +- Navigate to [Sensitive Information Types](https://purview.microsoft.com/informationprotection/dataclassification/multicloudsensitiveinfotypes) |
| 32 | +- Named Entity SITs have `Classifier: EntityMatch` in their properties |
| 33 | + |
| 34 | +**Query via PowerShell:** |
| 35 | +```powershell |
| 36 | +Connect-IPPSSession |
| 37 | +Get-DlpSensitiveInformationType | Where-Object { $_.Classifier -eq "EntityMatch" } | Select-Object Name, Classifier, Capability |
| 38 | +``` |
| 39 | + |
| 40 | +**Example Scenarios:** |
| 41 | +- **Protect Executive Communications**: Auto-label emails containing "All Full Names" with "Executive Communications" label |
| 42 | +- **Protect Healthcare Records**: DLP rule blocking external sharing of content with "All Medical Terms and Conditions" |
| 43 | +- **Address Data Protection**: DLP rule restricting content with "All Physical Addresses" to internal sharing only |
| 44 | + |
| 45 | +<!--- Results ---> |
| 46 | +%TestResult% |
0 commit comments