Enforce data loss prevention policies across Microsoft Teams

McAfee enforces DLP policies for files and messages across Microsoft Teams to ensure compliance with regulations and internal policies. McAfee supports DLP rules based on keywords, data identifiers, user groups, and regular expressions. Enforcement actions include coach users, notify administrator, block, encrypt, quarantine, and tombstone. Leverage pre-built industry templates, create custom policies in McAfee, or leverage policies in an existing on-premises DLP solution.

New Cloud Access Policy
Incident Management

Unified DLP Reporting and Remediation

McAfee reports on DLP violations in Microsoft Teams and other cloud services, including Microsoft Office 365 in a unified interface with highlighted excerpts revealing the exact content that triggered the DLP policy. During review, if a file does not violate a policy, the reviewer can rollback the remediation action to restore the file and/or its sharing permissions.

Deep Integration with On-Premises DLP Solutions

With McAfee you have the option of leveraging our best-in-class DLP engine or the policies in your existing on-premises solution such as McAfee DLP, Symantec DLP, Forcepoint DLP, and more. McAfee optionally performs a first-pass content inspection, brokers inspection by the on-premises solution, acts as an enforcement point to apply policies to data in the cloud, and registers enforcement in the on-premises solution that maintains the policy. When using McAfee DLP, data classifications can be shared between devices and cloud services, including Microsoft Teams.

Detect internal and external threats

McAfee captures a complete record of all user activity in Microsoft Teams and leverages machine learning to analyze activity across multiple heuristics and accurately detect threats. As a comprehensive cloud security platform, McAfee can detect cross-cloud threats that involve usage across Microsoft Teams and other cloud services. As threats are resolved, McAfee automatically incorporates this data into its behavioral models to improve detection accuracy.

Insider Threats

McAfee automatically constructs a behavior model with dynamic and continuously updated thresholds for each user and team to identify activity indicative of insider threat, whether the threat is accidental or malicious. Using Guided Learning, you can fine tune the detection of cloud-based threats by providing feedback to the system that is incorporated into models of user behavior to more accurately detect future threats.

Compromised Accounts

McAfee detects compromised account activity in Microsoft Teams based on brute force login attempts, logins from new and untrusted locations for a specific user, and consecutive login attempts from two locations in a time period that implies impossible travel, even if the two logins occur across two cloud services. Darknet Intelligence reveals user accounts for sale online that are at risk of compromise.

Secure BYOD access to Microsoft Teams

McAfee enforces fine-grained access policies, such as allowing document preview on unmanaged devices but preventing downloads to devices without appropriate endpoint security. McAfee can also integrate with identity management solutions to require additional factors of authentication for users based on device or access patterns.

Make Microsoft Teams your corporate standard

McAfee identifies collaboration solutions that employees use in place of the corporate standard, Microsoft Teams, and provides a risk rating for each service. Using McAfee, you can enforce risk-based governance controls and coach users to Microsoft Teams to improve collaboration while also reducing cost and risk.

Key features

Cloud Data Loss Prevention

Enforces DLP policies based on data identifiers, keywords, and structured/unstructured fingerprints across data at rest and uploaded or shared in real time.

Pre-Built DLP Templates

Provides out-of-the-box DLP templates and a broad range of international data identifiers to help identify sensitive content such as PII, PHI, or IP.

Unstructured Data Fingerprinting

Fingerprints sensitive files and detects exact match and partial or derivative matches with a policy-defined threshold for percentage similarity to the original.

Policy Violation Management

Offers a unified interface to review DLP violations, take manual action, and rollback an automatic remediation action to restore a file.

Closed-Loop Policy Enforcement

Optionally leverages policies in on-premises DLP systems, enforces policies, and registers enforcement actions in the DLP system where the policy is managed.

Secure Collaboration

Enforces external sharing policies based on shared links and content and educates users on acceptable collaboration policies.

Structured Data Fingerprinting

Fingerprints billions of unique values stored in enterprise databases and systems of record and supports exact match detection of each value.

Multi-Tier Remediation

Provides coach user, notify administrator, block, apply rights management, quarantine, tombstone, and delete options and enables tiered response based on severity.

Match Highlighting

Displays an excerpt with content that triggered a DLP violation. Enterprises, not MVISION Cloud, store excerpts, meeting stringent privacy requirements.

Shadow IT Discovery

Discovers all shadow IT cloud services employees are using in place of the corporate standard, Microsoft Teams.

Guest User Management

Securely enable guest access to your Teams channels while enforcing DLP policies, ensuring guests never see your sensitive data.

Usage Analytics

Identifies all users and groups accessing Microsoft Teams and reveals which users are accessing sensitive data.

Coaching and Enforcement

Displays just-in-time coaching messages guiding users from unapproved services to Microsoft Teams and enforces granular policies such as read-only access.

User Groups

Discovers and groups users from directory services and Microsoft Teams. User groups can be leveraged for analytics and policy enforcement.

Microsoft Teams SOC

Delivers a threat dashboard and incident-response workflow to review and remediate insider threats, privileged user threats, and compromised accounts.

User Behavior Analytics

Automatically builds a self-learning model based on multiple heuristics and identifies patterns of activity indicative of a malicious or negligent insider threat.

Privileged User Analytics

Identifies excessive user permissions, inactive accounts, inappropriate access, and unwarranted escalation of privileges and user provisioning.

Cloud Phishing Protection

Detects URLs associated with phishing and malware in Microsoft Teams messages and blocks high-risk URLs to protect enterprise users.

Cloud Activity Monitoring

Provides a comprehensive audit trail of all user and administrator activities to support post-incident investigations and forensics.

Account Compromise Analytics

Analyzes login attempts to identify impossible cross-region access, brute-force attacks, and untrusted locations indicative of compromised accounts.

Malware Protection

Identifies and blocks known signatures, sandboxes suspicious files, and detects behavior indicative of malware exfiltrating data via cloud services and ransomware.

Guided Learning

Provides human input to machine learning models with real-time preview showing the impact of a sensitivity change on anomalies detected by the system.

Contextual Access Control

Enforces policies based on user, managed/unmanaged device, personal/corporate account, and geography with coarse and activity-level enforcement.

Encryption and Tokenization

Delivers peer-reviewed, function-preserving encryption schemes using enterprise-controlled keys, and tokenization for data at rest and in transit.

Contextual Authentication

Forces additional authentication steps in real-time via integration with identity management solutions based on pre-defined access control policies.

MVISION Cloud Gateway

Enforces policies with an inline proxy and steers traffic via device agent, proxy chaining, DNS, and identity providers to cover all access scenarios.

MVISION Cloud Enterprise Connector

Facilitates integration with firewalls, proxies, SIEMs, directory services via LDAP, on-premises DLP, HSMs, and EMM/MDM solutions and tokenizes sensitive data.

Integration with SIEMs

Collects log files from SIEMs and provides the ability to report on incidents and events from MVISION in SIEM solutions via syslog and API integration.

Integration with EMM/MDM

Integrates with enterprise mobility management solutions to enforce access control policies based on whitelisted devices and EMM/MDM certificates.

MVISION Cloud Connector

Connects to cloud services via cloud provider APIs to provide visibility and enforce security and compliance policies for all users and cloud-to-cloud activity.

Integration with On-Premises DLP

Provides integration and closed-loop remediation with existing on-premises DLP solutions such as McAfee, Symantec, and Forcepoint.

Integration with IDM

Leverages identity management (IDM) solutions for pervasive and seamless traffic steering through MVISION's proxy and contextual authentication.

Free Demo

Request