A business unit leader objects to Microsoft Purview DLP policies blocking the emailing of certain file types, claiming it disrupts their workflow. What is the correct security team response process?
-
A
Review the business need, assess the risk, propose a least-privilege exception or alternative workflow, and obtain formal approval before any policy change
-
B
Immediately modify the DLP policy to allow the file type to avoid business disruption
-
C
Deny all requests to modify DLP policies without any review process
-
D
Escalate to Microsoft support to determine if the policy is misconfigured