Office 365 Incident generates on owner instead of actual user who initiated share activity
search cancel

Office 365 Incident generates on owner instead of actual user who initiated share activity

book

Article ID: 415947

calendar_today

Updated On:

Products

CASB Securlet SAAS CASB Security Advanced CASB Security Premium CASB Security Standard

Issue/Introduction

If the file has risk and violated DLP policy through share event, the incident generates on owner instead of actual user who initiated share activity. 

Resolution

This is a limitation by Microsoft. Currently, the Office 365 Securlet will report the actual action performer performer in only 2 activities - Rename & Edit . All other activities will have owner information only. (Activity logs/ Policy logs/ DLP Incidents).