Skip to content

Commit 6790ae8

Browse files
Merge pull request #53419 from riswinto/main
update to replace bulleted lists
2 parents 70d7bfb + 5ba8309 commit 6790ae8

2 files changed

Lines changed: 5 additions & 16 deletions

File tree

learn-pr/wwl-sci/purview-data-loss-prevention-understand-plan/includes/plan-design-policies.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -20,7 +20,7 @@ DLP can run across many workloads, but enforcement shouldn't begin everywhere at
2020
- Where blocking would cause the most disruption
2121
- Where visibility is more valuable than control early on
2222

23-
Beginning with visibility gives you behavioral insight before introducing restrictions.
23+
In many cases, visibility provides more value than control at the start. Observing how data moves and which actions are most common helps establish a baseline before restrictions are introduced. That insight makes it easier to introduce enforcement in places where it reduces risk without interrupting legitimate work.
2424

2525
## Scope policies intentionally
2626

learn-pr/wwl-sci/purview-data-loss-prevention-understand-plan/includes/understand-deployment-simulation-mode.md

Lines changed: 4 additions & 15 deletions
Original file line numberDiff line numberDiff line change
@@ -45,26 +45,15 @@ These reviews help ensure that enforcement decisions are based on evidence, not
4545

4646
## Using alerts and activity insights to validate policy behavior
4747

48-
Simulation results appear through alerts and activity insights. These views show where and how a policy would have applied.
48+
Simulation results surface through alerts and activity insights, which together show where and how a policy would have applied. Alerts highlight individual events that meet policy conditions, while activity insights help reveal broader patterns across users, locations, and actions.
4949

50-
Use this data to:
51-
52-
- Identify false positives
53-
- Understand patterns of risky behavior
54-
- See where enforcement might interrupt legitimate workflows
55-
56-
Using this data to refine scope and actions improves accuracy before enforcement begins.
50+
Reviewing both views helps clarify whether detections align with real risk or reflect normal business activity. This context is essential for understanding where enforcement might interrupt legitimate workflows and where policy logic needs refinement before actions are applied.
5751

5852
## Common rollout mistakes and how to avoid them
5953

60-
Several issues appear consistently in rushed deployments:
61-
62-
- Enforcing policies without first observing real behavior
63-
- Applying broad scope without piloting
64-
- Blocking actions before users understand expectations
65-
- Treating simulation as optional rather than foundational
54+
Problems often arise when policies are enforced before there's enough evidence to understand their effect. Broad scoping, early blocking, or treating simulation as optional can lead to false positives, user frustration, and reduced trust in DLP controls.
6655

67-
Avoiding these mistakes leads to smoother adoption and more effective protection.
56+
A more deliberate approach uses simulation to observe real behavior first, adjust scope and actions based on that evidence, and introduce enforcement only when confidence is high. This reduces disruption while keeping protection aligned with actual risk.
6857

6958
## A recommended rollout approach
7059

0 commit comments

Comments
 (0)