Skip to main content

AD_4nXdGL7Nq7voP30f282320Ql4MxlQUIe4Z3oQCLB9NO8fgb0Plxh512FWO7XGAnZAZMeJ71D0xDoGp3rtK3FJ4a38QquUlHgOtJzSYimviSJbZFFWbQIpJansTuLytaJ6u6WparoS?key=yZi9A8ENLseEesL_8AhwhQ

Netskope Global Technical Success (GTS)

Microsoft Teams: DLP Controls for Activity - 'Upload' & 'Download'

 

Netskope Cloud Version - 129

 

Objective

Implement DLP Controls for Activity ‘Upload’ & ‘Download’ on Microsoft Teams

 

Context

This document aims to provide a comprehensive guide on implementing DLP controls for Activity ‘Upload’ & ‘Download’ on Microsoft Teams Web & Native Application Access

 

Prerequisite

Netskope Next-Gen SWG license is required

 

Do You Know?

  • Netskope acknowledges Microsoft Teams as a Cloud Application and provides a pre-defined cloud app connector.
  • As of July 12, 2025 with Netskope’s Microsoft Teams predefined connector, customers can exercise control over the following activities: 

AD_4nXeMPZhBUZKIjWCbRYTVjIFA9cfx-ed_YdZ0B5OXUvXwipDAdwufpWVYOHHlcGKl21AQAO-8cvWI2IK_JYvVzxC2pUjzVeDjJffsGW3WBXs-OLp-y7s3RB9fs4NMgGK70S-wTt6nXw?key=yZi9A8ENLseEesL_8AhwhQ

 

  • Currently, Netskope does not support the 'Upload' activity for Microsoft Teams. However, based on the network logs, both upload and download activities are initiated through request URLs from the my.sharepoint.com domain

AD_4nXeVcFXkHlOtAKg8AzgGgon6v5p5LWkHEtDZB9dQ5PuwfL-giafc7gwrg_7TiGPho4WKH-w_-aZ4JB8mcqPNbPjnetvRZUc_AHzjKv40AxlA1U0c1eVRgjKkstLf2r456f1U9sSN-g?key=yZi9A8ENLseEesL_8AhwhQ

 

  • The domain my.sharepoint.com is associated with Microsoft Office 365 OneDrive for Business which supports Upload activity for DLP Protection.

AD_4nXdXVr-K1t0EA_9-JyndFKsXnWBQaZsCz-Cn41zW-Xhnhkz9TPMRUPZCx2wWQ5fxFmSlzOgpfKH4zaOsXijspMhMJ988YUS1ZrHPKqpqgCXZZzzqy_c9iZCV9i22Zfzrbu5yvrdf?key=yZi9A8ENLseEesL_8AhwhQ

 

AD_4nXdi4AtpkS_BLyjRG1aLG8rJJVKWYa5LRWr6f6ocN_rTbQtqedmyhvrGtTqWBthqBSHyUTg-EgWYTmdXYkJ2MRJwDQ_wg6AswKpK256vuKcnZrj0-RBUajE8bmBVw95uVNueQf8GJw?key=yZi9A8ENLseEesL_8AhwhQ

 

AD_4nXe44Q7DTSEOc2chrspWukgY4jnRelnU5J1rTPX9a5239_WH2GS3nAQ28CP7-7x7SgHdZIAsXRjb7PMdU4N1cRXY4XPOQXqW4GaY8wt_gWxVPwEf06hC9aBasKFdEEwkLDcMQPRIcg?key=yZi9A8ENLseEesL_8AhwhQ

 

Author Notes

For this lab recreation, a Pre-defined DLP Profile ‘DLP-PCI’  is used to detect the violation of Credit Card Numbers.

 

Pre-defined DLP profiles are recommended for use only during POCs and testing purposes. It is advised to use only the required pre-defined DLP identifiers within custom DLP profiles to minimize false-positive incidents.

 

Configuration

  • Create an HTTP Header profile

Path: Netskope Tenant UI >>> Policies >>> HTTP Header

AD_4nXeGI-lydLqCb7tMYlP2cnV7-7d-8oFJjN72nerZfNcBipKQrtinDPSIBFrXhHiL43qQqpi_JccuWy9wqNbAVDDTKK_EOoNo8UY0I9tMknz2lElK1vr86JiDYVhyD-q6CzcDlAt0oA?key=yZi9A8ENLseEesL_8AhwhQ

 

  • Create Custom URL Category for URL ‘my.sharepoint.com’

Path: Netskope Tenant UI >>> Profiles >>> URL Lists

AD_4nXdV1anU7aLgjzVdbTokmtJZS3MBYE7tyiSJh3FRkuO1inHOgxmBNiVsC_4I8ax2pm3qY3qRRUopcF7cLXkNep9VL7VB8hfEaxGctlHpsh1pZId3jMQKi0P_3n59sFBtUXTjuhJZ?key=yZi9A8ENLseEesL_8AhwhQ

 

Path: Netskope Tenant UI >>> Profiles >>> Custom Categories

AD_4nXfvEqRMOo2NWWGy5TmOaKZU67Km734Yi5wfMHSiIixmh98tSbVwW8EKlZpT6Z3OFLPuJKQ7pGUqW-Gxr6SXATlMmqzyiHSGl0Y8ejEzJ3t49-NYkyhaOhBCbaCLh9JReYzpdqWH?key=yZi9A8ENLseEesL_8AhwhQ

Create a Real-Time Protection Policy

Path: Netskope Tenant UI >>> Policies >>> Real-time Protection

AD_4nXf1c8A17J6YeKzy3L9rvJ1zLrsPV5C4ANdt0R3G3uC5G_NRQSJyrlKuuOW1M8SLysso-wG1--MFdijjzFHCQxySB6nXtkO1iob3O3giEOgElYmOvuVWd3tAcPmbAa7EBkoUpxfD?key=yZi9A8ENLseEesL_8AhwhQ

 

Verification

Access Microsoft Teams Web - https://teams.microsoft.com 

  • Try Uploading & Downloading the content violating DLP policy

AD_4nXfUl_2HMz8LdKn84xomEl2is48wteb3VDBoRbVpSmEeTsZzj2DvuSO7QXpTKNcyPAGzdoXde5dhHc92SzqYBEPF8yI-Ua1CUfpa0LBF_QQeH_sADyEaHCarE8RSEGxp53yukmusBw?key=yZi9A8ENLseEesL_8AhwhQ

 

AD_4nXcQr7Fnak1YHSOOHK-rD0243qj_yuhD4YjEK6xZdGz5XYNlrGY5gPTQ1RyPIsT2mnYLKWsTgwsdhzYRs3edyD5lOFbDBaiIkrD02FGn5aLU0NDVXF78yPgDUHIip_mBIu_wPeiD?key=yZi9A8ENLseEesL_8AhwhQ

 

Now, Access Microsoft Teams Native Application

  • Try Uploading & Downloading the content violating DLP policy

AD_4nXfTUMXaU9NlFHUfG5RBOvamhXRZgNzCjGoP5M66lx2EoJfgEPT-bXTh5L4JwfIh1y3uxwRGWEQsm9kp9FIKBr6bETvHEMU8VLSzdjR1wxIJSpXHGPtoPhvrWP64_bgY2wZDymLC2Q?key=yZi9A8ENLseEesL_8AhwhQ

 

AD_4nXfSXLPGoVutxPmkVyeiQOyUu9NSL7ltbi0WYlCveqcvYSb56qBMvAZWphxWxeu20STDjtEGG_TuCEUTdQIxrQU-4z6otrQBZcSew9kDsiXpHrIFqOiE1hqNgcjjIXqM8V1AbIUASQ?key=yZi9A8ENLseEesL_8AhwhQ

 

Note - User Notification format used above Link

 

  • Let’s review the transactions 

Path: Netskope Tenant UI >>> Policies >>> Realtime Protection Policies

AD_4nXdf6MkbjUj4Qe07Riro4E3UgrE7yiXwdiBGDJqP1Or-X7EHw37ixlv2Xn2CpLA1IsXK6kO80EA4vufyGO96Mew1WOdSku4pN-IqwbTBq5xy3UDZU7zF0y7Uko7f4q_v6uN6yyz7sg?key=yZi9A8ENLseEesL_8AhwhQ

 

AD_4nXe0W2-ly2RiQM6r0ffZ1CUSNy4neX6ddtaClGWrMZx9_rs4xJn7UL2jZNcUJdG4LzpPPtGM8_39sRPAdJRfLBVNqvZuqu6okhckfmbsN-mwLAm58HucqV7n7_ZHebXnZMnGw-ulWw?key=yZi9A8ENLseEesL_8AhwhQ

 

As you can see below, The alert is triggered by the Application ‘Microsoft Office 365 OneDrive for Business’ from the URL ‘my.sharepoint.com’ through the Referrer URL as ‘teams.microsoft.com’.

AD_4nXfhZ3Dr8uTk0M7nKPETCVpdrwacteYxMw7-M4aAsKX9okWr5qJNuv-n0Rj0w7qOxNVNzervneIsZxGQd6LlqQw68KmT4EFVjUgm2G_cqEwgHFjw-c9YQv0v_2tOCIzaEI6-EgnaAw?key=yZi9A8ENLseEesL_8AhwhQ

 

  • DLP Incidents

Path: Netskope Tenant UI >>> Incidents >>> DLP

Sample File ‘Employee Credit Card Info.xlsx’ was used for the upload & download activity

AD_4nXfSJFrd9tftwXkf4ky4eDKMMA_EvC2D9Zp5PB-YRRnsmBfrq6L78t0sWN-gCCu8Yh66QcZbypPG9-351SPjk-eWjDidf0afXy7JCYaFKw605Ym6ppUFf6pjUTm8Z5isq-MM35sTBg?key=yZi9A8ENLseEesL_8AhwhQ

 

Terms and Conditions

  • All documented information undergoes testing and verification to ensure accuracy.
  • In the future, it is possible that the application's functionality may be altered by the vendor. If any such changes are brought to our attention, we will promptly update the documentation to reflect them.

 

Notes

  • This article is authored by Netskope Global Technical Success (GTS).
  • For any further inquiries related to this article, please contact Netskope GTS by submitting a support case with 'Case Type – How To Questions'.
Be the first to reply!