SKYPE DLP Solutions

Server-side DLP inspection for Skype for Business traffic, helping detect, block, mask, notify, or monitor sensitive content across IM, files, federation, and unified communication channels.

Skype for Business DLP
Skype for Business DLP

Data loss prevention for unified communication channels

Many companies invest significant effort and resources in their Data Loss Prevention systems, covering main content channels such as email and web services. At the same time, many fail to cover data moving through unified communication channels such as Skype for Business.

As Skype for Business extends outside network boundaries through federation and meetings, communication with external parties can create security and data protection risks.

  • Server-side inspection covers traffic regardless of the client in use.

  • Content can be blocked, masked, monitored, alerted on or followed by sender notification.

  • Works with built-in SphereShield DLP or commercial DLP vendors through ICAP or REST API.

Skype for Business traffic

Server-side content inspection module

DLP provider or built-in engine
IM content scan Inspect
Binary file scan Inspect
Sensitive data detected Policy
Policy actions
Block
Mask
Notify
Monitor
Challenge and approach

Preventing data leaks through Skype for Business is challenging because of the variety of mobile, web and desktop clients, as well as the SIP protocol used by the clients.

Skype for Business requires content and data transfer inspection outside the regular inspection areas of most vendors.

SphereShield uses a server-side inspection approach, covering all possible Skype for Business infrastructure channels regardless of the client being used.

The solution is based on a content inspection module with an adapter that can send content through ICAP to a DLP provider.

Server-side adapter

Inspects Skype for Business content at the infrastructure level instead of relying on the client device.

Any client type

Inspects traffic from PC, mobile and web clients.

Incident response

Modifies messages based on the DLP incident response from the DLP provider.

Built-in and commercial DLP

Flexible protection with built-in rules or commercial integrations

For companies without an existing DLP product, SphereShield offers a built-in DLP engine that inspects content going through Skype for Business IM and binary files.

The engine can prevent content from exiting the network based on out-of-the-box and configurable rules that detect sensitive information such as credit card numbers and social security numbers.

Sensitive data detection

Detect credit card numbers, social security numbers and other configured data types.

Workplace safety policy

Use DLP rules for anti-harassment and workplace safety policy compliance.

ICAP
REST API
Commercial DLP vendors

Commercial DLP adapter

Pass content for inspection by commercial DLP vendors such as ForcePoint, McAfee or Symantec through ICAP or REST API.

User notification

Send an IM warning notification to the sender when an incident is detected.

Highlights

Server-side adapter for content control.

Inspect traffic from any Skype for Business client type, including PC, mobile and web.

Built-in DLP engine with configurable policy rules.

Support for blocking, masking or notifying on DLP incidents.

IM notification can be sent to the user when an incident is detected.

Integration with commercial DLP vendors through ICAP, including Websense and Symantec.

AGAT DLP rules can support anti-harassment and workplace safety policy compliance.

Content can be scanned on the fly, with action taken according to the defined policy.

Keep Skype for Business conversations and file transfers protected with server-side inspection and flexible DLP policy actions.

Secure Your Collaboration Environment

Protect Microsoft 365, Webex, Teams, OneDrive, SharePoint,
and Skype for Business with SphereShield’s policy-driven security, compliance, and governance controls.

Create your account