Claremont SecurityManaged compliance ยท Enterprise AI protection
// Resources / Data_Loss_Prevention

How a Governed Tenant Blocks or Logs Silent Exfiltration

Ungoverned AI use is not a technology problem. It is a boundary problem. Client data lives inside your Microsoft 365 tenant; the tools your staff reach for live outside it.

A governed deployment draws that boundary in policy, enforces it on the requests its policies match, in both directions, and keeps a record of each decision.

Your Microsoft 365 tenantcontained, governed, evidenced
The open internetunbounded, unlogged, outside your control
Microsoft 365 CopilotChats stored in tenant
SharePoint / OneDriveClient files
Exchange OnlineMail
Allowedused · logged · reviewed
Staff workstationManaged · MDM
Sensitivity labels

Mark a file Confidential. The mark stays with the file.

DLP policy

Data loss rules: find client identifiers and block the paste or the send.

Conditional Access

Sign-in rules that turn away unmanaged devices.

Blocked at the boundary

paste containing client identifiers, bound for a free tool

the request never crosses; the user sees the policy notice

Personal webmailOutside tenant
File-sharing siteUnsanctioned
Public AI chatbotFree tier
Unmanaged laptopNo MDM
Out here, none of this exists.No boundary · No block · No record
The record
workstation → copilotPrompt captured · Output logged · Sources cited
workstation → external pasteBlocked · User, time, and policy recorded

Every prompt in, every answer out, every failed attempt to leave. Exports when an insurer or examiner asks.

The block is the visible part. The record is the part that matters at renewal.

When an auditor asks how AI use is governed, the answer is a report, not a promise.