DAT — Data Protection
Data sharing, retention and protection controls. 17 controls in total — 11 automatic, 6 attested.
How to read
Result: ✅ Pass · ⚠️ Warning · ❌ Fail · N/A Not evaluated. Status: Auto = Controlio measures it app-only · Attested = the customer marks it. Lv: L1 basic, L2 advanced.
| Control | What it checks | Result criteria | Status |
|---|---|---|---|
DAT-01 Data loss prevention (DLP) policies L1 | Checks whether rules that stop sensitive data from leaving without permission are turned on. | ✅ Policies active · ❌ Not active | Auto Requires Business Premium (Entra P1); N/A without Global Reader or data |
DAT-02 Sensitivity label publishing L1 | Checks whether sensitivity labels that tag data by confidentiality level are published. | ✅ Labels published · ⚠️ At least one label but not enough · ❌ No labels at all | Auto Requires Business Premium (Entra P1); N/A without Global Reader or data |
DAT-04 SharePoint external sharing restriction L1 | Checks how far files in SharePoint can be shared with people outside the organization. | ✅ Off or existing guests only · ⚠️ Open to new guests · ❌ Anyone with the link | Auto N/A if data is unavailable |
DAT-07 OneDrive sync device/domain restriction L2 | Checks whether OneDrive sync is limited to company-owned devices only. | ✅ Sync restricted · ❌ No restriction | Auto N/A if no data |
DAT-08 Sensitivity labels defined and in use L2 | Checks whether enough sensitivity labels are defined and used to classify data. | ✅ 3 or more labels · ⚠️ 1–2 labels · ❌ No labels | Auto Requires Microsoft 365 E5; N/A otherwise |
DAT-09 Blocking guest resharing L2 | Checks whether external guest users are stopped from resharing files and sites they do not own. | ✅ Resharing off · ❌ On | Auto N/A if data is unavailable |
DAT-10 OneDrive sync on managed devices only L2 | Checks whether OneDrive sync is blocked on personal or unmanaged devices. | ✅ Restricted on unmanaged devices · ❌ No restriction | Auto N/A if data is unavailable |
DAT-11 Disabling legacy authentication in SharePoint L1 | Checks whether legacy authentication protocols that can bypass MFA are off in SharePoint. | ✅ Legacy auth off · ❌ On | Auto N/A if data is unavailable |
DAT-12 Automatic sign-out of idle sessions L1 | Checks whether the OneDrive or SharePoint session closes automatically when the user is idle. It prevents data access on shared devices. | ✅ Automatic sign-out on · ❌ Off | Auto N/A if data is unavailable |
DAT-14 Restriction of OneDrive external sharing L2 | Checks how far each user can share their own OneDrive files with outsiders. | ✅ Off or existing guests only · ⚠️ Open to new guests · ❌ Guest or anyone sharing | Attested Customer attestation (not measured automatically) |
DAT-15 Default sharing permission set to View L1 | Checks whether sharing links grant view-only permission by default instead of edit. | ✅ View · ⚠️ Unclear/undefined · ❌ Edit | Attested Customer attestation (not measured automatically) |
DAT-16 Guest account expiry (≤30 days) enforced L1 | Checks whether guest accounts are required to expire automatically after a set period, at most 30 days. | ✅ Expiry required and 30 days or fewer · ⚠️ Expiry required but longer than 30 days · ❌ Expiry not required | Attested Customer attestation (not measured automatically) |
DAT-17 Guest verification code (≤15 days) renewal L2 | Checks whether guest users are required to re-enter their email verification code at set intervals, at most 15 days. | ✅ Renewal required and 15 days or fewer · ⚠️ Required but longer than 15 days · ❌ Not required | Attested Customer attestation (not measured automatically) |
DAT-18 Default sharing link set to Specific people L1 | Checks whether sharing links are created by default for specific people or with broader access. | ✅ Specific people and view only · ⚠️ Specific people or internal · ❌ Anonymous / anyone with the link | Attested Customer attestation (not measured automatically) |
DAT-19 Anyone-link expiry (≤30 days) limited L1 | Checks whether anyone-with-the-link shares are required to expire after at most 30 days. | ✅ Expiry 30 days or fewer · ⚠️ Expiry set but longer than 30 days · ❌ No expiry | Attested Customer attestation (not measured automatically) |
DAT-21 Sensitive data retention and disposal rules L1 | Checks whether rules for how long sensitive data is kept and when it is disposed of are defined. | ✅ Retention/disposal rule active · ⚠️ Rule defined but not active · ❌ No rule | Auto N/A if no data |
DAT-22 Domain restriction for external sharing L2 | Checks whether external sharing is limited to allowed or blocked domain lists. | ✅ Allow/block list defined · ⚠️ No restriction | Auto N/A if data is unavailable |