Skip to main content

DAT — Data Protection

Data sharing, retention and protection controls. 17 controls in total — 11 automatic, 6 attested.

How to read

Result: ✅ Pass · ⚠️ Warning · ❌ Fail · N/A Not evaluated. Status: Auto = Controlio measures it app-only · Attested = the customer marks it. Lv: L1 basic, L2 advanced.

ControlWhat it checksResult criteriaStatus
DAT-01 Data loss prevention (DLP) policies
L1
Checks whether rules that stop sensitive data from leaving without permission are turned on.✅ Policies active · ❌ Not activeAuto
Requires Business Premium (Entra P1); N/A without Global Reader or data
DAT-02 Sensitivity label publishing
L1
Checks whether sensitivity labels that tag data by confidentiality level are published.✅ Labels published · ⚠️ At least one label but not enough · ❌ No labels at allAuto
Requires Business Premium (Entra P1); N/A without Global Reader or data
DAT-04 SharePoint external sharing restriction
L1
Checks how far files in SharePoint can be shared with people outside the organization.✅ Off or existing guests only · ⚠️ Open to new guests · ❌ Anyone with the linkAuto
N/A if data is unavailable
DAT-07 OneDrive sync device/domain restriction
L2
Checks whether OneDrive sync is limited to company-owned devices only.✅ Sync restricted · ❌ No restrictionAuto
N/A if no data
DAT-08 Sensitivity labels defined and in use
L2
Checks whether enough sensitivity labels are defined and used to classify data.✅ 3 or more labels · ⚠️ 1–2 labels · ❌ No labelsAuto
Requires Microsoft 365 E5; N/A otherwise
DAT-09 Blocking guest resharing
L2
Checks whether external guest users are stopped from resharing files and sites they do not own.✅ Resharing off · ❌ OnAuto
N/A if data is unavailable
DAT-10 OneDrive sync on managed devices only
L2
Checks whether OneDrive sync is blocked on personal or unmanaged devices.✅ Restricted on unmanaged devices · ❌ No restrictionAuto
N/A if data is unavailable
DAT-11 Disabling legacy authentication in SharePoint
L1
Checks whether legacy authentication protocols that can bypass MFA are off in SharePoint.✅ Legacy auth off · ❌ OnAuto
N/A if data is unavailable
DAT-12 Automatic sign-out of idle sessions
L1
Checks whether the OneDrive or SharePoint session closes automatically when the user is idle. It prevents data access on shared devices.✅ Automatic sign-out on · ❌ OffAuto
N/A if data is unavailable
DAT-14 Restriction of OneDrive external sharing
L2
Checks how far each user can share their own OneDrive files with outsiders.✅ Off or existing guests only · ⚠️ Open to new guests · ❌ Guest or anyone sharingAttested
Customer attestation (not measured automatically)
DAT-15 Default sharing permission set to View
L1
Checks whether sharing links grant view-only permission by default instead of edit.✅ View · ⚠️ Unclear/undefined · ❌ EditAttested
Customer attestation (not measured automatically)
DAT-16 Guest account expiry (≤30 days) enforced
L1
Checks whether guest accounts are required to expire automatically after a set period, at most 30 days.✅ Expiry required and 30 days or fewer · ⚠️ Expiry required but longer than 30 days · ❌ Expiry not requiredAttested
Customer attestation (not measured automatically)
DAT-17 Guest verification code (≤15 days) renewal
L2
Checks whether guest users are required to re-enter their email verification code at set intervals, at most 15 days.✅ Renewal required and 15 days or fewer · ⚠️ Required but longer than 15 days · ❌ Not requiredAttested
Customer attestation (not measured automatically)
DAT-18 Default sharing link set to Specific people
L1
Checks whether sharing links are created by default for specific people or with broader access.✅ Specific people and view only · ⚠️ Specific people or internal · ❌ Anonymous / anyone with the linkAttested
Customer attestation (not measured automatically)
DAT-19 Anyone-link expiry (≤30 days) limited
L1
Checks whether anyone-with-the-link shares are required to expire after at most 30 days.✅ Expiry 30 days or fewer · ⚠️ Expiry set but longer than 30 days · ❌ No expiryAttested
Customer attestation (not measured automatically)
DAT-21 Sensitive data retention and disposal rules
L1
Checks whether rules for how long sensitive data is kept and when it is disposed of are defined.✅ Retention/disposal rule active · ⚠️ Rule defined but not active · ❌ No ruleAuto
N/A if no data
DAT-22 Domain restriction for external sharing
L2
Checks whether external sharing is limited to allowed or blocked domain lists.✅ Allow/block list defined · ⚠️ No restrictionAuto
N/A if data is unavailable