Skip to main content

DAT — Data Protection

Data sharing, retention and protection controls. 18 controls in total — 12 automatic, 6 attested.

How to read

Result: ✅ Pass · ⚠️ Warning · ❌ Fail · N/A Not evaluated. Status: Auto = Controlio measures it app-only · Attested = the customer marks it. Lv: L1 basic, L2 advanced.

ControlWhat it checksResult criteriaStatus
DAT-01 Data loss prevention (DLP) policies
L1
Checks whether rules that stop sensitive data from leaving without permission are turned on.✅ Policies active · ❌ Not activeAuto
Requires Business Premium (Entra P1); N/A without Global Reader or data
DAT-02 Sensitivity label publishing
L1
Checks whether sensitivity labels that tag data by confidentiality level are published.✅ Labels published · ⚠️ At least one label but not enough · ❌ No labels at allAuto
Requires Business Premium (Entra P1); N/A without Global Reader or data
DAT-04 SharePoint external sharing restriction
L1
Checks how far files in SharePoint can be shared with people outside the organization.✅ Off or existing guests only · ⚠️ Open to new guests · ❌ Anyone with the linkAuto
N/A if data is unavailable
DAT-07 OneDrive sync device/domain restriction
L2
Checks whether OneDrive sync is limited to company-owned devices only.✅ Sync restricted · ❌ No restrictionAuto
N/A if no data
DAT-08 Sensitivity labels defined and in use
L2
Checks whether enough sensitivity labels are defined and used to classify data.✅ 3 or more labels · ⚠️ 1–2 labels · ❌ No labelsAuto
Requires Microsoft 365 E5; N/A otherwise
DAT-09 Blocking guest resharing
L2
Checks whether external guest users are stopped from resharing files and sites they do not own.✅ Resharing off · ❌ OnAuto
N/A if data is unavailable
DAT-10 OneDrive sync on managed devices only
L2
Checks whether OneDrive sync is blocked on personal or unmanaged devices.✅ Restricted on unmanaged devices · ❌ No restrictionAuto
N/A if data is unavailable
DAT-11 Disabling legacy authentication in SharePoint
L1
Checks whether legacy authentication protocols that can bypass MFA are off in SharePoint.✅ Legacy auth off · ❌ OnAuto
N/A if data is unavailable
DAT-12 Automatic sign-out of idle sessions
L1
Checks whether the OneDrive or SharePoint session closes automatically when the user is idle. It prevents data access on shared devices.✅ Automatic sign-out on · ❌ OffAuto
N/A if data is unavailable
DAT-14 Restriction of OneDrive external sharing
L2
Checks how far each user can share their own OneDrive files with outsiders.✅ Off or existing guests only · ⚠️ Open to new guests · ❌ Guest or anyone sharingAttested
Customer attestation (not measured automatically)
DAT-15 Default sharing permission set to View
L1
Checks whether sharing links grant view-only permission by default instead of edit.✅ View · ⚠️ Unclear/undefined · ❌ EditAttested
Customer attestation (not measured automatically)
DAT-16 Guest account expiry (≤30 days) enforced
L1
Checks whether guest accounts are required to expire automatically after a set period, at most 30 days.✅ Expiry required and 30 days or fewer · ⚠️ Expiry required but longer than 30 days · ❌ Expiry not requiredAttested
Customer attestation (not measured automatically)
DAT-17 Guest verification code (≤15 days) renewal
L2
Checks whether guest users are required to re-enter their email verification code at set intervals, at most 15 days.✅ Renewal required and 15 days or fewer · ⚠️ Required but longer than 15 days · ❌ Not requiredAttested
Customer attestation (not measured automatically)
DAT-18 Default sharing link set to Specific people
L1
Checks whether sharing links are created by default for specific people or with broader access.✅ Specific people and view only · ⚠️ Specific people or internal · ❌ Anonymous / anyone with the linkAttested
Customer attestation (not measured automatically)
DAT-19 Anyone-link expiry (≤30 days) limited
L1
Checks whether anyone-with-the-link shares are required to expire after at most 30 days.✅ Expiry 30 days or fewer · ⚠️ Expiry set but longer than 30 days · ❌ No expiryAttested
Customer attestation (not measured automatically)
DAT-21 Sensitive data retention and disposal rules
L1
Checks whether rules for how long sensitive data is kept and when it is disposed of are defined.✅ Retention/disposal rule active · ⚠️ Rule defined but not active · ❌ No ruleAuto
N/A if no data
DAT-22 Domain restriction for external sharing
L2
Checks whether external sharing is limited to allowed or blocked domain lists.✅ Allow/block list defined · ⚠️ No restrictionAuto
N/A if data is unavailable
DAT-23 DLP policy for Microsoft Teams
L2
Checks whether an active data loss prevention (DLP) policy covers Microsoft Teams chats and channels. Without coverage, sensitive data can be shared through Teams unprotected.✅ At least one active DLP covers Teams · ❌ Not coveredAuto
Requires Microsoft 365 E5; N/A otherwise