Skip to main content

Microsoft Purview Information Barriers

Microsoft Purview Information Barriers (IB) is used to restrict communication and collaboration between users or groups when the organization has conflict-of-interest, segregation-of-duty, internal control or regulated collaboration requirements.

IB should not be treated as a simple user blocking feature. It should be designed as a control model that connects collaboration restriction matrix, segments, policies, workload validation, exception management and audit evidence.

Executive lens: Information Barriers are not just a Teams chat restriction. They are a segmentation model across users, groups, sites and collaboration workloads that must be validated with both allowed and blocked communication evidence.

Purview Information Barriers

Design collaboration boundaries with evidence, not guesswork

Information Barriers should connect business restriction matrix, segment design, policy activation, workload validation, exceptions, rollback and audit evidence.
MatrixSegmentPolicyEvidence

적용 시나리오​

ScenarioTypical RequirementDesign Focus
이해상충 분리특정 부서 간 커뮤니케이션 제한Segment Matrix, symmetric policy, exception users
M&A / 계열 분리조직 단위별 협업 경계 분리multi-segment design, Teams/SPO/ODfB validation
금융 / 투자 업무분장Chinese Wall 및 정보 장벽 통제audit evidence, approval flow, policy change history
민감 프로젝트프로젝트별 접근 및 공유 제한SharePoint site segment, owner moderated review
Copilot 데이터 보호Copilot 확산 전 협업 경계 정비Graph permission, Purview, DLP, IB alignment

구현 아키텍처​

구현 아키텍처Restriction matrix to audit-ready evidence package
01MatrixDefine who can collaborate, who must be blocked and who approves exceptions.
02SegmentCreate IB segments based on business boundaries, attributes and exception model.
03PolicyConfigure policy direction, activation state and application process.
04WorkloadsValidate Teams, SharePoint, OneDrive and Exchange-specific behavior.
05EvidencePackage allowed and blocked tests, status, exceptions, rollback and owner approval.

설계 원칙​

PrincipleGuidance
Matrix First정책을 만들기 전에 부서/사용자 간 허용 및 차단 Matrix를 먼저 확정합니다.
Symmetric PolicyA에서 B를 차단했다면 B에서 A를 차단하는 대칭 정책도 검토합니다.
Exception by Segment예외 사용자가 필요하면 개별 예외 사용자를 별도 Segment로 분리합니다.
Workload ValidationTeams, SharePoint, OneDrive는 정책 적용 방식과 검증 항목이 다릅니다.
Evidence Ready정책 설정, 테스트 결과, 오류 화면, 로그를 감사 대응 패키지로 보관합니다.
Rollback PlannedSegment/Policy 삭제보다 비활성화, 영향 검증, application 재실행 순서를 먼저 정의합니다.

Prerequisites​

  • Microsoft Purview Information Barriers를 지원하는 라이선스
  • Purview Information Barriers 관리 권한
  • ExchangeOnlineManagement module
  • IPPSSession 연결 가능 관리자 계정
  • SharePoint Online Management Shell
  • 테스트 사용자 2명 이상
  • 테스트 사용자별 department 또는 정책 기준 속성
  • Teams, SharePoint, OneDrive 검증 환경

Segment Design​

Segment는 단순 부서명이 아니라 정책 경계를 표현하는 단위입니다.

Segment TypeExampleNotes
Department SegmentFinance, Investment, Advisory가장 일반적인 업무분장 기준
Project SegmentProject A, Project B민감 프로젝트 또는 제한된 협업 공간
Subsidiary SegmentCompany A, Company B계열사 또는 인수합병 시나리오
Exception SegmentApproved exception users예외 승인 및 만료일 관리 필요
Regulated SegmentCompliance restricted group감사 증적과 승인 이력 필수

Workload Control Pattern​

Workload Control PatternOne segment model, multiple workload validation paths
01User segmentSegment membership expresses the business restriction boundary.
02TeamsValidate chat, group chat, team membership and allowed collaboration paths.
03SharePoint / OneDriveValidate site access, sharing links, membership and direct file access.
04ExchangeReview separate mail flow, transport rule, moderation and DLP design.
05EvidenceKeep screenshots and logs for both allowed and blocked collaboration paths.

Teams 검증​

Teams는 IB 정책 적용 후 사용자가 가장 먼저 체감하는 workload 중 하나입니다.

Test CaseExpected Result
차단 대상 사용자 간 1:1 chat대화 시작 또는 메시지 전송 차단
차단 대상 사용자가 포함된 group chat초대 또는 대화 참여 차단
Team member 추가정책에 맞지 않는 사용자는 추가 차단
동일 Segment 사용자 chat정상 허용
예외 Segment 사용자승인된 방향과 상대에 대해서만 허용

검증 시에는 허용 시나리오와 차단 시나리오를 모두 캡처해야 합니다. 차단 화면만 남기면 운영팀이 정상 협업 영향도를 판단하기 어렵습니다.

SharePoint / OneDrive 검증​

Test CaseExpected Result
사이트 멤버 추가Segment 불일치 사용자는 추가 차단
사이트 접근Segment 불일치 사용자는 접근 차단
문서 라이브러리 접근기존 권한이 있어도 IB 정책에 따라 차단
파일 직접 링크 접근링크를 보유해도 Segment 불일치 시 접근 차단
파일/폴더 공유공유 대상 검증 후 차단 또는 허용
People Picker / Search상대 Segment 사용자가 검색 결과에서 제한
동일 Segment 사용자 접근정상 허용
사이트 소유자 권한소유자 권한으로 IB를 우회할 수 없는지 확인

Exchange 고려사항​

IB를 설계할 때 Exchange Online까지 동일한 방식으로 제어된다고 가정하면 안 됩니다. 메일 흐름 기반의 송수신 제한은 Exchange mail flow rule 또는 transport rule 기반 설계를 별도로 검토해야 합니다.

  • Collaboration boundary: Teams, SharePoint, OneDrive 중심의 IB 통제
  • Messaging boundary: Exchange mail flow rule, transport rule, moderation, DLP 중심의 메일 통제

Evidence Package​

정보보호팀 또는 감사 대응을 위해 다음 증적을 하나의 패키지로 보관합니다.

EvidencePurpose
Segment Matrix비즈니스 승인 기준
Policy ListSegment별 차단/허용 정책 확인
Policy Application Status정책 적용 완료 여부 확인
Teams Validation Screenshotchat, group chat, member add 테스트
SharePoint Validation Screenshotsite access, member add, file sharing 테스트
OneDrive Validation Screenshotdirect link, folder sharing, same Segment access 테스트
Exception Register예외 사용자, 승인자, 만료일 관리
Rollback Plan장애 발생 시 영향 최소화

증적 이미지에는 실제 UPN, 이메일 주소, tenant domain, 사용자 이름 등 개인정보가 노출되지 않도록 마스킹해야 합니다.

Troubleshooting​

SymptomLikely CauseResponse
Teams에서 차단되지 않음Policy가 Active가 아니거나 application start 미완료policy state와 application status 확인
SharePoint 사이트 접근 가능site mode 또는 Segment 연결 누락site mode, assigned Segment, 기존 권한 재검토
OneDrive 반영 지연Segment 변경 후 propagation 지연최대 24시간 지연 가능성을 고려하고 재검증
People Picker에는 보이지만 공유 실패검색 단계와 실제 공유 검증 단계 차이실제 공유/접근 결과 기준으로 판단
예외 사용자가 차단됨예외 Segment 또는 대칭 허용 Policy 누락예외 Segment와 양방향 Policy 확인
기존 공유 링크가 우회처럼 보임기존 권한과 링크 캐시 영향직접 접근, 새 세션, 정책 상태를 함께 확인

Rollback Pattern​

운영 장애가 발생했을 때 바로 Segment를 삭제하면 추적성이 떨어질 수 있습니다. 다음 순서로 접근하는 것이 안전합니다.

  1. 영향 사용자와 workload를 확인합니다.
  2. 정책을 비활성화할지, 예외 Segment를 추가할지 결정합니다.
  3. 변경 승인자를 기록합니다.
  4. Policy 변경 후 Start-InformationBarrierPoliciesApplication을 다시 실행합니다.
  5. Teams, SharePoint, OneDrive 검증을 반복합니다.
  6. 최종 변경 사항과 잔여 리스크를 evidence package에 반영합니다.

Consulting Deliverables​

  • Information Barrier design workshop material
  • Segment and collaboration restriction Matrix
  • IB Policy design sheet
  • SharePoint / OneDrive IB mode decision table
  • Teams validation checklist
  • SharePoint / OneDrive validation checklist
  • Evidence package template
  • Rollback and exception management procedure

Frequently Asked Questions​

Is Information Barriers only a Teams feature?​

No. Information Barriers should be treated as a collaboration boundary model. Teams behavior is important, but SharePoint, OneDrive, group membership and workload-specific validation must also be reviewed.

What should be designed first?​

Start with a collaboration restriction matrix. Define which groups can communicate or collaborate, which exceptions are allowed and who approves changes.

How does Information Barriers affect Copilot readiness?​

Copilot follows Microsoft 365 permissions and collaboration boundaries. Information Barriers can help reduce unintended collaboration paths in regulated or conflict-of-interest scenarios, but they must be validated with workload-specific tests.

What evidence is required?​

Prepare segment matrix, policy list, policy application status, allowed/blocked Teams tests, SharePoint/OneDrive validation, exception register and rollback plan.

Common Mistakes​

  • Creating segments before the business restriction matrix is approved
  • Testing only Teams chat and ignoring SharePoint or OneDrive behavior
  • Forgetting symmetric policy requirements
  • Keeping exception users without expiry or owner
  • Publishing screenshots with real UPNs, domains or customer identifiers

Search Keywords​

  • Microsoft Purview Information Barriers
  • Information Barrier implementation
  • Microsoft 365 Chinese Wall
  • Teams Information Barriers
  • SharePoint Information Barriers
  • OneDrive Information Barriers
  • Purview Segment Policy
  • Microsoft 365 collaboration restriction
  • Microsoft 365 정보 장벽
  • Microsoft 365 협업 제한
  • SharePoint OneDrive Information Barrier
  • Teams Segment Communication validation

Microsoft References​

Contact / Asset Request​

For security baseline workbooks, control matrices, exception registers, executive security reports or operations handover templates, use Contact and Asset Request.