Applying a DLP policy to Defender for Cloud Apps to control third-party uploads

Evaluate solutions for securing Microsoft 365
Answer Correct answer: D — Defender for Cloud Apps as the DLP location governs uploads to third-party sites while allowing OneDrive.

You have a Microsoft 365 tenant that uses Microsoft SharePoint Online and Microsoft Purview. Microsoft Purview has a sensitivity label named Label1 that is applied to the files stored on SharePoint Online sites. You need to recommend a Microsoft Purview Data Loss Prevention (DLP) policy that meets the following requirements: • Prevents users from uploading the files to third-party external websites • Allows users to upload the files to Microsoft OneDrive for Business To which location should you apply the DLP policy?

  1. Devices
  2. OneDrive accounts
  3. SharePoint sites
  4. Microsoft Defender for Cloud Apps Correct Answer

Community Votes

D
100%

100% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Defender for Cloud Apps as a DLP location can control uploads to third-party sites (via app connectors/session policies) and allow OneDrive; device, OneDrive, and SharePoint scopes cannot govern third-party external site uploads.

To block uploads of labeled files to third-party external websites while allowing OneDrive uploads, apply the Microsoft Purview DLP policy to the Microsoft Defender for Cloud Apps location, which can govern uploads to both third-party and Microsoft apps.

Applying the policy to Devices (A) — device DLP controls endpoints but does not govern uploads to arbitrary third-party external websites the way Defender for Cloud Apps does.

Community Discussion (3 comments)

oscarpopi 👍 1 Selected: D
Defender for Cloud Apps is the right answer
Ali96 👍 3 Selected: D
The most suitable choice is Option D: Microsoft Defender for Cloud Apps. This will allow the DLP policy to monitor and manage uploads to both OneDrive for Business and third-party websites as needed.
AlbertE1nstein 👍 2 Selected: D
D. Microsoft Defender for Cloud Apps

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Applying the Microsoft Purview DLP policy to the Microsoft Defender for Cloud Apps location lets you govern file uploads across both Microsoft apps (OneDrive for Business) and third-party external websites, satisfying both requirements from a single DLP location.

Why the Other Options Are Wrong

Devices (A) scopes DLP to endpoints but cannot control uploads to arbitrary third-party external sites as precisely as Defender for Cloud Apps. OneDrive accounts (B) and SharePoint sites (C) cover only Microsoft locations and cannot block third-party external website uploads.

Community Comment Notes

The community favored D (100 votes). Comments confirm Defender for Cloud Apps is the location that monitors and manages uploads to both OneDrive and third-party websites.

Official Reference

Related Analysis

Practice All SC-100 Questions

Access 110 questions with complete answers and detailed explanations.

View Full SC-100 Practice Test →

← Back to SC-100 Study Guide