Msgraph
codemie-ai/codemie-code
Work with Microsoft 365 services via the Graph API — emails, calendar events, SharePoint sites (read and write), Teams chats and channel messages, OneDrive files, OneNote notebooks, Planner task…
Agent skill
Implements DLP policies using Microsoft Purview PowerShell cmdlets and the Graph API to protect data across Exchange Online, SharePoint, OneDrive, Teams, endpoints, and Power BI, including…
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-data-loss-prevention-with-microsoft-purview -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills implementing-data-loss-prevention-with-microsoft-purview --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/implementing-data-loss-prevention-with-microsoft-purview .claude/skills/implementing-data-loss-prevention-with-microsoft-purview && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "implementing-data-loss-prevention-with-microsoft-purview" agent skill from https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/main/skills/implementing-data-loss-prevention-with-microsoft-purview into .claude/skills/implementing-data-loss-prevention-with-microsoft-purview/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "implementing-data-loss-prevention-with-microsoft-purview", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/main/skills/implementing-data-loss-prevention-with-microsoft-purviewType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-data-loss-prevention-with-microsoft-purview -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills implementing-data-loss-prevention-with-microsoft-purview --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/implementing-data-loss-prevention-with-microsoft-purview .agents/skills/implementing-data-loss-prevention-with-microsoft-purview && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "implementing-data-loss-prevention-with-microsoft-purview" agent skill from https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/main/skills/implementing-data-loss-prevention-with-microsoft-purview into .agents/skills/implementing-data-loss-prevention-with-microsoft-purview/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "implementing-data-loss-prevention-with-microsoft-purview", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-data-loss-prevention-with-microsoft-purview -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills implementing-data-loss-prevention-with-microsoft-purview --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/implementing-data-loss-prevention-with-microsoft-purview .cursor/skills/implementing-data-loss-prevention-with-microsoft-purview && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "implementing-data-loss-prevention-with-microsoft-purview" agent skill from https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/main/skills/implementing-data-loss-prevention-with-microsoft-purview into .cursor/skills/implementing-data-loss-prevention-with-microsoft-purview/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "implementing-data-loss-prevention-with-microsoft-purview", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git --path skills/implementing-data-loss-prevention-with-microsoft-purview--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-data-loss-prevention-with-microsoft-purview -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills implementing-data-loss-prevention-with-microsoft-purview --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/implementing-data-loss-prevention-with-microsoft-purview .gemini/skills/implementing-data-loss-prevention-with-microsoft-purview && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "implementing-data-loss-prevention-with-microsoft-purview" agent skill from https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/main/skills/implementing-data-loss-prevention-with-microsoft-purview into .gemini/skills/implementing-data-loss-prevention-with-microsoft-purview/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "implementing-data-loss-prevention-with-microsoft-purview", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills implementing-data-loss-prevention-with-microsoft-purviewInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-data-loss-prevention-with-microsoft-purview -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/implementing-data-loss-prevention-with-microsoft-purview .github/skills/implementing-data-loss-prevention-with-microsoft-purview && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "implementing-data-loss-prevention-with-microsoft-purview" agent skill from https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/main/skills/implementing-data-loss-prevention-with-microsoft-purview into .github/skills/implementing-data-loss-prevention-with-microsoft-purview/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "implementing-data-loss-prevention-with-microsoft-purview", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-data-loss-prevention-with-microsoft-purview -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills implementing-data-loss-prevention-with-microsoft-purview --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/implementing-data-loss-prevention-with-microsoft-purview .opencode/skills/implementing-data-loss-prevention-with-microsoft-purview && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "implementing-data-loss-prevention-with-microsoft-purview" agent skill from https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/main/skills/implementing-data-loss-prevention-with-microsoft-purview into .opencode/skills/implementing-data-loss-prevention-with-microsoft-purview/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "implementing-data-loss-prevention-with-microsoft-purview", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
implementing-data-loss-prevention-with-microsoft-purviewImplements DLP policies using Microsoft Purview PowerShell cmdlets and the Graph API to protect data across Exchange Online, SharePoint, OneDrive, Teams, endpoints, and Power BI, including…
Implementing Data Loss Prevention With Microsoft Purview is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Implements DLP policies using Microsoft Purview PowerShell cmdlets and the Graph API to protect data across Exchange Online, SharePoint, OneDrive, Teams, endpoints, and Power BI, including sensitivity labels, custom sensitive information types with regex, endpoint DLP rules, and Activity Explorer monitoring. Use when stopping PII/PHI/PCI exfiltration, configuring sensitivity labels, or investigating DLP incidents for policy tuning.
Its SKILL.md is about 7.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including scripts and reference files (for example `references/api-reference.md` and `scripts/agent.py`).
It sits in Documents & Office, covering Cloud office suites. It works with PowerShell, Microsoft OneDrive, Microsoft SharePoint and Power BI. The repository describes itself as: 817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io…. The licence is Apache-2.0.
5 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 54a7988. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/ (Python), which the agent can run.
From the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
graph.microsoft.comschemas.microsoft.comcontoso.sharepoint.comlogin.microsoftonline.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Implementing Data Loss Prevention With Microsoft Purview loads about 7.9k tokens when it runs, and up to ~9.2k if it reads all its reference files. Until then it costs about 123 tokens; SKILL.md has 1,989 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from mukul975/Anthropic-Cybersecurity-Skills at commit 54a7988, republished under its Apache-2.0 licence (© mukul975). 1,989 words, ~7,851 tokens.
.claude/skills/implementing-data-loss-prevention-with-microsoft-purview/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.Do not use without appropriate Microsoft 365 E5, E5 Compliance, or E5 Information Protection licensing. Do not deploy DLP policies directly to production enforcement mode without a simulation period. Do not configure endpoint DLP without coordinating with the endpoint management team responsible for device onboarding.
Define the classification hierarchy that maps to organizational data handling requirements:
Public -> No protection, external sharing allowed
General -> No encryption, internal watermark "GENERAL"
Confidential -> Encryption (all employees), header/footer marking
├─ Confidential - All Employees
├─ Confidential - Finance
└─ Confidential - HR
Highly Confidential -> Encryption (specific users/groups), watermark, no forwarding
├─ Highly Confidential - Project X
└─ Highly Confidential - Board Only# Connect to Security & Compliance PowerShell
Connect-IPPSSession -UserPrincipalName admin@contoso.com
# Create parent label
New-Label -DisplayName "Confidential" `
-Name "Confidential" `
-Tooltip "Business data that could cause damage if disclosed to unauthorized parties" `
-Comment "Apply to internal business documents, financial reports, and customer data"
# Create sub-label with encryption
New-Label -DisplayName "Confidential - Finance" `
-Name "Confidential-Finance" `
-ParentId (Get-Label -Identity "Confidential").Guid `
-Tooltip "Financial data restricted to Finance department" `
-EncryptionEnabled $true `
-EncryptionProtectionType "Template" `
-EncryptionRightsDefinitions "finance-group@contoso.com:VIEW,VIEWRIGHTSDATA,DOCEDIT,EDIT,PRINT,EXTRACT,OBJMODEL" `
-ContentType "File, Email"Set-Label -Identity "Confidential-Finance" `
-HeaderEnabled $true `
-HeaderText "CONFIDENTIAL - FINANCE" `
-HeaderFontSize 10 `
-HeaderFontColor "#FF0000" `
-HeaderAlignment "Center" `
-FooterEnabled $true `
-FooterText "This document contains confidential financial information" `
-WatermarkEnabled $true `
-WatermarkText "CONFIDENTIAL" `
-WatermarkFontSize 36New-LabelPolicy -Name "Corporate Label Policy" `
-Labels "Public","General","Confidential","Confidential-Finance",
"Confidential-HR","HighlyConfidential","HighlyConfidential-ProjectX" `
-ExchangeLocation "All" `
-ModernGroupLocation "All" `
-Comment "Standard corporate sensitivity labels"
# Require justification for label downgrade
Set-LabelPolicy -Identity "Corporate Label Policy" `
-AdvancedSettings @{RequireDowngradeJustification="True";
DefaultLabelId="General"}Configure DLP policies that detect and protect sensitive content across Microsoft 365 workloads:
# Create DLP policy scoped to Exchange, SharePoint, OneDrive
New-DlpCompliancePolicy -Name "Financial Data Protection" `
-ExchangeLocation "All" `
-SharePointLocation "All" `
-OneDriveLocation "All" `
-TeamsLocation "All" `
-Mode "TestWithNotifications" `
-Comment "Protects credit card numbers, bank account numbers, and financial identifiers"
# Create rule for high-volume credit card detection
New-DlpComplianceRule -Name "Block Bulk Credit Card Sharing" `
-Policy "Financial Data Protection" `
-ContentContainsSensitiveInformation @{
Name = "Credit Card Number";
MinCount = 5;
MinConfidence = 85
} `
-BlockAccess $true `
-BlockAccessScope "All" `
-NotifyUser "SiteAdmin","LastModifier" `
-NotifyUserType "NotSet" `
-GenerateIncidentReport "SiteAdmin" `
-IncidentReportContent "All" `
-ReportSeverityLevel "High"
# Create rule for low-volume with user override
New-DlpComplianceRule -Name "Warn on Credit Card Sharing" `
-Policy "Financial Data Protection" `
-ContentContainsSensitiveInformation @{
Name = "Credit Card Number";
MinCount = 1;
MaxCount = 4;
MinConfidence = 75
} `
-NotifyUser "LastModifier" `
-NotifyUserType "NotSet" `
-GenerateAlert "Low" `
-NotifyOverride "WithJustification"# Create custom SIT for employee ID format (EMP-XXXXXX)
$rulePackXml = @"
<RulePackage xmlns="http://schemas.microsoft.com/office/2011/mce">
<RulePack id="$(New-Guid)">
<Version major="1" minor="0" build="0" revision="0"/>
<Publisher id="$(New-Guid)"/>
</RulePack>
<Rules>
<Entity id="$(New-Guid)" patternsProximity="300"
recommendedConfidence="85">
<Pattern confidenceLevel="85">
<IdMatch idRef="EmployeeId_Regex"/>
</Pattern>
<Pattern confidenceLevel="95">
<IdMatch idRef="EmployeeId_Regex"/>
<Match idRef="EmployeeId_Keyword"/>
</Pattern>
</Entity>
<Regex id="EmployeeId_Regex">EMP-[0-9]{6}</Regex>
<Keyword id="EmployeeId_Keyword">
<Group matchStyle="word">
<Term>employee</Term>
<Term>employee id</Term>
<Term>emp id</Term>
<Term>staff number</Term>
</Group>
</Keyword>
<LocalizedStrings>
<Resource idRef="EmployeeId_Regex">
<Name default="true" langcode="en-us">Contoso Employee ID</Name>
<Description default="true" langcode="en-us">
Detects Contoso employee IDs in format EMP-XXXXXX
</Description>
</Resource>
</LocalizedStrings>
</Rules>
</RulePackage>
"@
# Save and import the rule package
$rulePackXml | Out-File -FilePath "EmployeeID_SIT.xml" -Encoding utf8
New-DlpSensitiveInformationTypeRulePackage -FileData (
[System.IO.File]::ReadAllBytes("EmployeeID_SIT.xml")
)New-DlpCompliancePolicy -Name "Highly Confidential Sharing Control" `
-ExchangeLocation "All" `
-SharePointLocation "All" `
-OneDriveLocation "All" `
-Mode "Enable"
New-DlpComplianceRule -Name "Block External Sharing of HC Content" `
-Policy "Highly Confidential Sharing Control" `
-ContentContainsSensitiveInformation $null `
-ContentPropertyContainsWords "MSIP_Label_$(
(Get-Label -Identity 'HighlyConfidential').Guid
)_Enabled=True" `
-BlockAccess $true `
-BlockAccessScope "NotInOrganization" `
-NotifyUser "LastModifier" `
-GenerateIncidentReport "SiteAdmin" `
-ReportSeverityLevel "High"Extend DLP protection to managed Windows and macOS endpoints to control file operations:
# Check onboarding status via Intune Graph API
# GET https://graph.microsoft.com/beta/deviceManagement/managedDevices
# Filter for complianceState and dlpOnboardingStatus
# Local verification on Windows endpoint
# Check registry key:
# HKLM\SOFTWARE\Microsoft\Windows Advanced Threat Protection\Status
# OnboardingState should be 1# Configure unallowed apps (browsers, cloud sync clients)
Set-PolicyConfig -EndpointDlpGlobalSettings `
-UnallowedApps @(
@{Name="Chrome"; Executable="chrome.exe"},
@{Name="Firefox"; Executable="firefox.exe"},
@{Name="PersonalDropbox"; Executable="Dropbox.exe"}
)
# Configure unallowed Bluetooth apps
Set-PolicyConfig -EndpointDlpGlobalSettings `
-UnallowedBluetoothApps @(
@{Name="BluetoothFileTransfer"; Executable="fsquirt.exe"}
)
# Configure network share groups
Set-PolicyConfig -EndpointDlpGlobalSettings `
-NetworkShareGroups @(
@{
Name = "Authorized Shares";
NetworkPaths = @("\\server01\approved$", "\\server02\secure$")
}
)
# Configure sensitive service domains (allowed cloud destinations)
Set-PolicyConfig -EndpointDlpGlobalSettings `
-SensitiveServiceDomains @(
@{
Name = "Approved Cloud Storage";
Domains = @("sharepoint.com", "onedrive.com")
MatchType = "Allow"
},
@{
Name = "Blocked Cloud Storage";
Domains = @("dropbox.com", "box.com", "drive.google.com")
MatchType = "Block"
}
)# Add endpoint location to existing policy
Set-DlpCompliancePolicy -Identity "Financial Data Protection" `
-EndpointDlpLocation "All"
# Create endpoint-specific rule
New-DlpComplianceRule -Name "Block USB Copy of Financial Data" `
-Policy "Financial Data Protection" `
-ContentContainsSensitiveInformation @{
Name = "Credit Card Number";
MinCount = 1;
MinConfidence = 85
} `
-EndpointDlpRestrictions @(
@{Setting="CopyToRemovableMedia"; Value="Block"},
@{Setting="CopyToNetworkShare"; Value="Audit"},
@{Setting="CopyToClipboard"; Value="Block"},
@{Setting="Print"; Value="Warn"},
@{Setting="UploadToCloudService"; Value="Block"},
@{Setting="UnallowedBluetoothApp"; Value="Block"}
) `
-NotifyUser "LastModifier" `
-GenerateIncidentReport "SiteAdmin"# Define authorized USB devices by vendor/product ID
Set-PolicyConfig -EndpointDlpGlobalSettings `
-RemovableMediaGroups @(
@{
Name = "Approved Encrypted USBs";
Devices = @(
@{VendorId="0781"; ProductId="5583"; SerialNumber="*"} # SanDisk Extreme
)
}
)
# Define authorized printers
Set-PolicyConfig -EndpointDlpGlobalSettings `
-PrinterGroups @(
@{
Name = "Corporate Printers";
Printers = @(
@{PrinterName="*Corporate*"; PrinterType="Corporate"},
@{PrinterName="PDF Printer"; PrinterType="Print to PDF"}
)
}
)Deploy service-side auto-labeling to automatically classify content at rest and in transit:
New-AutoSensitivityLabelPolicy -Name "Auto-Label Financial Emails" `
-ExchangeLocation "All" `
-Mode "TestWithNotifications" `
-Comment "Automatically labels emails containing financial data as Confidential-Finance"
New-AutoSensitivityLabelRule -Name "Financial SIT Match" `
-Policy "Auto-Label Financial Emails" `
-SensitiveInformationType @{
Name = "Credit Card Number";
MinCount = 1;
MinConfidence = 85
},@{
Name = "U.S. Bank Account Number";
MinCount = 1;
MinConfidence = 85
} `
-WorkloadDomain "Exchange" `
-ApplySensitivityLabel "Confidential-Finance"New-AutoSensitivityLabelPolicy -Name "Auto-Label SP Financial Docs" `
-SharePointLocation "https://contoso.sharepoint.com/sites/finance" `
-OneDriveLocation "All" `
-Mode "TestWithNotifications"
New-AutoSensitivityLabelRule -Name "Financial Docs SIT Match" `
-Policy "Auto-Label SP Financial Docs" `
-SensitiveInformationType @{
Name = "Credit Card Number"; MinCount = 1; MinConfidence = 85
} `
-WorkloadDomain "SharePoint" `
-ApplySensitivityLabel "Confidential-Finance"# Check simulation results
Get-AutoSensitivityLabelPolicy -Identity "Auto-Label Financial Emails" |
Select-Object Name, Mode, WhenCreated, DistributionStatus
# Switch to enforcement after validation
Set-AutoSensitivityLabelPolicy -Identity "Auto-Label Financial Emails" `
-Mode "Enable"Use Activity Explorer and the DLP alerts dashboard to monitor policy effectiveness and investigate incidents:
Activity Explorer filter:
Activity type = DLPRuleMatch
Action = Override
Date range = Last 30 days
Policy name = Financial Data Protection
Export to CSV for analysis of override justifications and
affected file types to refine SIT confidence thresholds.# DLP alerts are configured within the DLP rule itself
# Adjust alert volume thresholds on high-traffic rules
Set-DlpComplianceRule -Identity "Block Bulk Credit Card Sharing" `
-GenerateAlert "High" `
-AlertProperties @{
AggregationType = "SimpleAggregation";
Threshold = 1;
TimeWindow = "00:05:00"
}import requests
# Authenticate with Microsoft Graph (client credentials flow)
token_url = "https://login.microsoftonline.com/{tenant_id}/oauth2/v2.0/token"
token_response = requests.post(token_url, data={
"client_id": client_id,
"client_secret": client_secret,
"scope": "https://graph.microsoft.com/.default",
"grant_type": "client_credentials"
})
access_token = token_response.json()["access_token"]
headers = {"Authorization": f"Bearer {access_token}"}
# Retrieve DLP alerts
alerts_url = "https://graph.microsoft.com/v1.0/security/alerts_v2"
params = {
"$filter": "serviceSource eq 'microsoftDataLossPrevention'",
"$top": 50,
"$orderby": "createdDateTime desc"
}
response = requests.get(alerts_url, headers=headers, params=params)
alerts = response.json().get("value", [])
for alert in alerts:
print(f"Alert: {alert['title']}")
print(f" Severity: {alert['severity']}")
print(f" Status: {alert['status']}")
print(f" Created: {alert['createdDateTime']}")
print(f" User: {alert.get('userStates', [{}])[0].get('userPrincipalName', 'N/A')}")# Search unified audit log for DLP policy matches
Search-UnifiedAuditLog -StartDate (Get-Date).AddDays(-7) `
-EndDate (Get-Date) `
-RecordType "DLP" `
-ResultSize 1000 |
Select-Object CreationDate, UserIds, Operations,
@{N='PolicyName';E={($_.AuditData | ConvertFrom-Json).PolicyDetails.PolicyName}},
@{N='RuleName';E={($_.AuditData | ConvertFrom-Json).PolicyDetails.Rules.RuleName}},
@{N='SITMatched';E={($_.AuditData | ConvertFrom-Json).SensitiveInfoDetections.SensitiveType}} |
Export-Csv -Path "DLP_Audit_Report.csv" -NoTypeInformation| Term | Definition |
|---|---|
| Sensitivity Label | A classification tag applied to documents and emails that can enforce encryption, content marking (headers/footers/watermarks), and access restrictions. Labels persist with the content and travel with files when shared externally. |
| Sensitive Information Type (SIT) | A pattern-based classifier that detects specific data patterns (credit card numbers, SSNs, custom regex) in content. Each SIT has a confidence level (low/medium/high) determined by primary pattern match plus corroborating evidence (keywords, proximity). |
| DLP Policy | A set of rules that detect sensitive information in Microsoft 365 locations (Exchange, SharePoint, OneDrive, Teams, Endpoints) and apply protective actions (audit, warn with override, block) based on the sensitivity of matched content and the sharing context. |
| Endpoint DLP | Extension of DLP protection to managed Windows and macOS devices that monitors and controls file operations including copy-to-USB, print, upload-to-cloud, copy-to-clipboard, and access by unallowed applications for files containing sensitive information. |
| Activity Explorer | A monitoring dashboard in Microsoft Purview that displays a historical view (up to 30 days) of labeled content activities, DLP policy matches, and user interactions with classified data across all monitored locations. |
| Auto-Labeling | Service-side automatic classification that applies sensitivity labels to documents and emails matching specified SIT patterns without requiring user interaction. Runs in simulation mode first to preview matches before enforcement. |
| Content Marking | Visual indicators (headers, footers, watermarks) applied by sensitivity labels to documents and emails. Markings persist in the file and are visible when printed or shared, serving as a visual classification reminder. |
| DLP Alert | A notification generated when a DLP rule match meets the configured severity threshold. Alerts appear in the Microsoft Purview DLP alerts dashboard and can be routed to Microsoft Sentinel or other SIEM platforms. |
Context: A financial services company with 15,000 users across 12 countries needs to prevent credit card numbers, bank account details, and financial statements from being shared externally through email, Teams, SharePoint, and endpoint file operations. The company must comply with PCI-DSS and GDPR.
Approach:
Pitfalls:
Context: A pharmaceutical company needs to prevent research data identified by internal project codes (format: RX-YYYY-NNNN) and compound identifiers from being shared outside the research department. The data appears in lab reports, research presentations, and email communications.
Approach:
RX-20[2-3][0-9]-[0-9]{4} with corroborating keywords ("compound", "trial", "formulation", "assay", "efficacy") within 300-character proximity. Set primary pattern at 85% confidence and keyword-corroborated pattern at 95%.CPD-[A-Z]{3}-[0-9]{5} with keywords ("molecule", "synthesis", "pharmacokinetics") for higher confidence matching.RX-202[4-6]-[0-9]{4} to target only active project codes and reduce false positives by 60%.Pitfalls:
## DLP Policy Deployment Report
**Policy Name**: PCI-DSS Financial Data Protection
**Deployment Date**: 2026-03-19
**Current Mode**: Simulation (TestWithNotifications)
**Locations**: Exchange Online, SharePoint Online, OneDrive, Teams, Endpoints
---
### Simulation Results (14-Day Period)
**Total Policy Matches**: 4,287
**Unique Users Affected**: 892
**Unique Files/Messages**: 3,641
| Rule | Matches | Action | Override Rate |
|------|---------|--------|---------------|
| Block Bulk Credit Card Sharing (5+) | 47 | Block | N/A |
| Warn on Credit Card Sharing (1-4) | 4,240 | Warn | 12.3% |
### Sensitive Information Type Breakdown
| SIT | Matches | Avg Confidence | False Positive Est. |
|-----|---------|----------------|---------------------|
| Credit Card Number | 3,891 | 87% | 8.2% |
| U.S. Bank Account Number | 312 | 82% | 15.1% |
| ABA Routing Number | 84 | 79% | 22.6% |
### Recommendations
1. **Enable enforcement** for "Block Bulk Credit Card Sharing" rule -
47 matches are all true positives involving bulk credit card data in
spreadsheet attachments.
2. **Increase confidence threshold** for ABA Routing Number from 75 to 85 -
22.6% false positive rate driven by 9-digit numbers in invoice references
matching the routing number pattern.
3. **Add file type exception** for password-protected ZIP attachments that
trigger false positives when the credit card SIT matches encrypted content
metadata.
4. **Deploy endpoint DLP** in audit mode for 7 additional days before
enabling block actions on USB copy and cloud upload.
---
### DLP Alert Summary (Last 7 Days)
| Severity | Count | Top Policy | Top User |
|----------|-------|------------|----------|
| High | 12 | Financial Data Protection | j.smith@contoso.com |
| Medium | 89 | IP Protection - Research | r.chen@contoso.com |
| Low | 234 | General PII Protection | (distributed) |
### Activity Explorer Insights
- Peak DLP match activity: Monday 09:00-11:00 UTC (weekly report distribution)
- Top matched location: Finance SharePoint site (62% of all matches)
- Most overridden rule: "Warn on Credit Card Sharing" (523 overrides, 12.3%)
- Override justification analysis: 78% "Business requirement", 15% "False positive",
7% "Other"© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 3 other files (scripts, references) in skills/implementing-data-loss-prevention-with-microsoft-purview of mukul975/Anthropic-Cybersecurity-Skills.
Open the folder on GitHubat commit 54a7988
Implementing Data Loss Prevention With Microsoft Purview next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Implementing Data Loss Prevention With Microsoft Purview this skillmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~7.9k | Automated safety check: Pass | Apache-2.0 | |
| Msgraphcodemie-ai/codemie-code | 294 | — | ~4.1k | Automated safety check: Pass | Apache-2.0 | |
| aai-cli Microsoft 365aai-labs/agent-barn | 109 | — | ~1.2k | Automated safety check: Pass | Apache-2.0 | |
| Workiqmicrosoft/work-iq | 1k | — | ~15k | Automated safety check: Pass | Custom licence | |
| Workiq Previewmicrosoft/work-iq | 1k | — | ~3.3k | Automated safety check: Pass | Custom licence | |
| Sync Blocker Auditorpnp/sharepoint-skills | 132 | — | ~3.9k | Automated safety check: Pass | MIT |
codemie-ai/codemie-code
Work with Microsoft 365 services via the Graph API — emails, calendar events, SharePoint sites (read and write), Teams chats and channel messages, OneDrive files, OneNote notebooks, Planner task…
aai-labs/agent-barn
Guides work with Outlook, OneDrive, SharePoint, Teams, Excel, To Do and Planner through aai-cli's Microsoft Graph commands, starting from which service owns the data.
microsoft/work-iq
WorkIQ tools for Microsoft 365 workplace data and actions. An agent skill from microsoft/work-iq.
microsoft/work-iq
WorkIQ tools for Microsoft 365 workplace data and actions. An agent skill from microsoft/work-iq.
pnp/sharepoint-skills
Audits a SharePoint document library for names and paths that break OneDrive sync, File Explorer, and Teams file access.
microsoft/power-platform-skills
Adds Excel Online (Business) connector to a Power Apps code app.
mukul975/Anthropic-Cybersecurity-Skills
Weighs infrastructure, TTP, malware code and timing evidence with the Diamond Model and competing hypotheses to reach a confidence-rated attribution.
mukul975/Anthropic-Cybersecurity-Skills
Walks through reverse engineering Go-compiled malware in Ghidra: parsing buildinfo and pclntab, recovering stripped function names and extracting dependencies.
mukul975/Anthropic-Cybersecurity-Skills
Guides forensic analysis of Windows LNK shortcut files and Jump Lists with LECmd, JLECmd and manual parsing to show file access and program execution.
mukul975/Anthropic-Cybersecurity-Skills
Hunts Windows malware persistence with Sysinternals Autoruns, covering run keys, services, scheduled tasks and drivers, with baseline comparison.
mukul975/Anthropic-Cybersecurity-Skills
Guides a Windows forensic examination of the NTFS Master File Table to recover deleted-file evidence, build timelines and spot timestomping.
mukul975/Anthropic-Cybersecurity-Skills
Detects DNS tunneling, ICMP exfiltration and HTTP-based covert channels in packet captures and DNS logs when hunting for hidden command-and-control traffic.
Categories
Implements DLP policies using Microsoft Purview PowerShell cmdlets and the Graph API to protect data across Exchange Online, SharePoint, OneDrive, Teams, endpoints, and Power BI, including…. Implementing Data Loss Prevention With Microsoft Purview is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Implements DLP policies using Microsoft Purview PowerShell cmdlets and the Graph API to protect data across Exchange Online, SharePoint, OneDrive, Teams, endpoints, and Power BI, including sensitivity labels, custom sensitive information types with regex, endpoint DLP rules, and Activity Explorer monitoring.
Implementing Data Loss Prevention With Microsoft Purview fits situations like: stopping PII/PHI/PCI exfiltration; configuring sensitivity labels; investigating DLP incidents for policy tuning.
Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-data-loss-prevention-with-microsoft-purview -a claude-code`. Or copy the skill folder (skills/implementing-data-loss-prevention-with-microsoft-purview in mukul975/Anthropic-Cybersecurity-Skills) into .claude/skills/implementing-data-loss-prevention-with-microsoft-purview in your project. Claude Code loads it when a task matches its description.
Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-data-loss-prevention-with-microsoft-purview -a codex`. Or copy the skill folder (skills/implementing-data-loss-prevention-with-microsoft-purview in mukul975/Anthropic-Cybersecurity-Skills) into .agents/skills/implementing-data-loss-prevention-with-microsoft-purview in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-data-loss-prevention-with-microsoft-purview -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/implementing-data-loss-prevention-with-microsoft-purview, .gemini/skills/implementing-data-loss-prevention-with-microsoft-purview, .github/skills/implementing-data-loss-prevention-with-microsoft-purview and .opencode/skills/implementing-data-loss-prevention-with-microsoft-purview in your project.
Going by SKILL.md and its folder, Implementing Data Loss Prevention With Microsoft Purview needs Python for the scripts in its folder. Our summary lists: Python 3.
SKILL.md names 4 domains. In commands or code: graph.microsoft.com, schemas.microsoft.com, contoso.sharepoint.com and login.microsoftonline.com; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Implementing Data Loss Prevention With Microsoft Purview is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 7.9k tokens (SKILL.md is roughly 31k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.3k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Implementing Data Loss Prevention With Microsoft Purview: Msgraph (codemie-ai/codemie-code, 294 stars), aai-cli Microsoft 365 (aai-labs/agent-barn, 109 stars), Workiq (microsoft/work-iq, 1k stars) and Workiq Preview (microsoft/work-iq, 1k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
mukul975 (a GitHub user) maintains it in mukul975/Anthropic-Cybersecurity-Skills, which has 33,993 GitHub stars. The repository holds 644 skills in this directory. The repository was last updated on August 31, 2026.
Source: mukul975/Anthropic-Cybersecurity-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.