お知らせ: このページは現在英語のみで提供されています。日本語版は準備中です。ご不便をおかけして申し訳ございません。

Supported Filter Criteria

The sections below list the filter criteria that you can use when creating filters.

Filter Criteria: Equals vs. Matches

When creating filters, you can choose from several conditions to define how values are compared. The two most commonly confused conditions are Equals/Does not equal and Matches/Does not match. Understanding the difference helps you choose the correct condition for your scenario.

Equals (Exact Match)

  • Behavior: The value must match exactly, character for character.

  • Wildcards: Not supported. The * and ? characters are treated as literal characters, not as wildcard symbols.

  • Use case: Use this condition when you need to match one specific, fixed value, such as a single site name.

  • Example:

    Condition: Equals

    Value: ProjectA

    Result: Only items named exactly ProjectA will match. Items such as ProjectA1, projecta, or ProjectA_ will not match.

Matches (Pattern Match)

  • Behavior: The value can include wildcard characters to represent one or more arbitrary characters.

  • Wildcards:

    • Asterisk (*): Matches zero or more characters, including spaces.

    • Question mark (?): Matches exactly one character, including spaces.

  • Use case: Use this condition when you need to match a group of items that follow the same pattern, such as all sites that start with Sales.

  • Examples:

    Condition: Matches

    Value: Project*

    Result: All items that begin with Project will match, such as ProjectAlpha, ProjectBeta, Project 2024, and Project.

    Condition: Matches

    Value: Site??

    Result: Items with exactly Site followed by any two characters will match, such as Site01, SiteAB, or Site A. In Site A, the space counts as one character.

Use Equals/Does not equal when you know the exact value you want to match. Use Matches/Does not match with wildcards * and ? when you need to match a pattern.

Object Type - SharePoint Sites

The sections below list the filter criteria to filter SharePoint and OneDrive sites.

Site Collection

The following table lists the filter criteria for site collections.

CriterionDescriptionCondition
Created timeManages site collections whose created time meets the configured condition.Before
Created timeManages site collections whose created time meets the configured condition.After
Created timeManages site collections whose created time meets the configured condition.Older than
Created timeManages site collections whose created time meets the configured condition.Within
Custom propertyManages site collections that have the specified custom property and the property value meets the configured condition.Contains
Custom propertyManages site collections that have the specified custom property and the property value meets the configured condition.Does not contain
Custom propertyManages site collections that have the specified custom property and the property value meets the configured condition.Equals
Custom propertyManages site collections that have the specified custom property and the property value meets the configured condition.Does not equal
Custom propertyManages site collections that have the specified custom property and the property value meets the configured condition.Matches
Custom propertyManages site collections that have the specified custom property and the property value meets the configured condition.Does not match
Exposure level (Insights)Manages site collections whose exposure level retrieved from Insights meets the configured condition.Matches any of these
Exposure level (Insights)Manages site collections whose exposure level retrieved from Insights meets the configured condition.Does not match
Geo locationManages site collections whose geo location meets the configured condition.Equals
Lock statusManages site collections whose lock status meets the configured condition.Equals
Modified timeManages site collections whose modified time meets the configured condition.Before
Modified timeManages site collections whose modified time meets the configured condition.After
Modified timeManages site collections whose modified time meets the configured condition.Older than
Modified timeManages site collections whose modified time meets the configured condition.Within
Renewal phase (Cloud Governance)Manages site collections whose renewal phase (Cloud Governance) is one of the selected values.Matches any of these
Risk level (Insights)Manages site collections whose risk level retrieved from Insights meets the configured condition.Matches any of these
Risk level (Insights)Manages site collections whose risk level retrieved from Insights meets the configured condition.Does not match
Sensitivity labelManages site collections whose sensitivity label meets the configured condition.Equals
Sensitivity level (Insights)Manages site collections whose sensitivity level retrieved from Insights meets the configured condition.Matches any of these
Sensitivity level (Insights)Manages site collections whose sensitivity level retrieved from Insights meets the configured condition.Does not match
TitleManages site collections whose title meets the configured condition.Contains
TitleManages site collections whose title meets the configured condition.Does not contain
TitleManages site collections whose title meets the configured condition.Equals
TitleManages site collections whose title meets the configured condition.Does not equal
TitleManages site collections whose title meets the configured condition.Matches
TitleManages site collections whose title meets the configured condition.Does not match
URLManages site collections whose URL meets the configured condition.Contains
URLManages site collections whose URL meets the configured condition.Does not contain
URLManages site collections whose URL meets the configured condition.Equals
URLManages site collections whose URL meets the configured condition.Does not equal
URLManages site collections whose URL meets the configured condition.Matches
URLManages site collections whose URL meets the configured condition.Does not match

Site

The following table lists the filter criteria for sites.

NOTE

Currently, site-level filter criteria do not work for auditor mode rules.

CriterionDescriptionCondition
Created timeManages sites whose created time meets the configured condition.Before
Created timeManages sites whose created time meets the configured condition.After
Created timeManages sites whose created time meets the configured condition.Older than
Created timeManages sites whose created time meets the configured condition.Within
Exposure level (Insights)Manages sites whose exposure level retrieved from Insights meets the configured condition.Matches any of these
Exposure level (Insights)Manages sites whose exposure level retrieved from Insights meets the configured condition.Does not match
Modified timeManages sites whose modified time meets the configured condition.Before
Modified timeManages sites whose modified time meets the configured condition.After
Modified timeManages sites whose modified time meets the configured condition.Older than
Modified timeManages sites whose modified time meets the configured condition.Within
Risk level (Insights)Manages sites whose risk level retrieved from Insights meets the configured condition.Matches any of these
Risk level (Insights)Manages sites whose risk level retrieved from Insights meets the configured condition.Does not match
Sensitivity level (Insights)Manages sites whose sensitivity level retrieved from Insights meets the configured condition.Matches any of these
Sensitivity level (Insights)Manages sites whose sensitivity level retrieved from Insights meets the configured condition.Does not match
TitleManages sites whose title meets the configured condition.Contains
TitleManages sites whose title meets the configured condition.Does not contain
TitleManages sites whose title meets the configured condition.Equals
TitleManages sites whose title meets the configured condition.Does not equal
TitleManages sites whose title meets the configured condition.Matches
TitleManages sites whose title meets the configured condition.Does not match
URLManages sites whose URL meets the configured condition.Contains
URLManages sites whose URL meets the configured condition.Does not contain
URLManages sites whose URL meets the configured condition.Equals
URLManages sites whose URL meets the configured condition.Does not equal
URLManages sites whose URL meets the configured condition.Matches
URLManages sites whose URL meets the configured condition.Does not match

File Property

Policies for Microsoft 365 supports granular, content‑level filter conditions, enabling you to target individual files based on file type.

The following table lists the filter criteria for file properties.

Property NameDescriptionCondition
File typeManages files whose file type meets the configured condition. You can choose from predefined file types or add custom file types.Matches any of these

Object Type - Microsoft 365 Groups

The sections below lists the filter criteria to filter Microsoft 365 Groups and Microsoft Teams, including group team sites.

Group Property

The following table lists the filter criteria for group properties.

Property NameDescriptionCondition
ClassificationManages Microsoft 365 Groups whose Classification property value meets the configured condition.Contains
ClassificationManages Microsoft 365 Groups whose Classification property value meets the configured condition.Does not contain
ClassificationManages Microsoft 365 Groups whose Classification property value meets the configured condition.Equals
ClassificationManages Microsoft 365 Groups whose Classification property value meets the configured condition.Does not equal
ClassificationManages Microsoft 365 Groups whose Classification property value meets the configured condition.Matches
ClassificationManages Microsoft 365 Groups whose Classification property value meets the configured condition.Does not match
Display nameManages Microsoft 365 Groups whose display name meets the configured condition.Contains
Display nameManages Microsoft 365 Groups whose display name meets the configured condition.Does not contain
Display nameManages Microsoft 365 Groups whose display name meets the configured condition.Equals
Display nameManages Microsoft 365 Groups whose display name meets the configured condition.Does not equal
Display nameManages Microsoft 365 Groups whose display name meets the configured condition.Matches
Display nameManages Microsoft 365 Groups whose display name meets the configured condition.Does not match
IDManages Microsoft 365 Groups whose ID meets the configured condition.Contains
IDManages Microsoft 365 Groups whose ID meets the configured condition.Does not contain
IDManages Microsoft 365 Groups whose ID meets the configured condition.Equals
IDManages Microsoft 365 Groups whose ID meets the configured condition.Does not equal
IDManages Microsoft 365 Groups whose ID meets the configured condition.Matches
IDManages Microsoft 365 Groups whose ID meets the configured condition.Does not match
PrivacyManages Microsoft 365 Groups whose privacy status meets the configured condition.Equals
Renewal phase (Cloud Governance)Manages Microsoft 365 Groups whose renewal phase (Cloud Governance) meets the configured condition.Matches any of these
Sensitivity labelManages Microsoft 365 Groups whose sensitivity label meets the configured condition.Equals
Team statusManages Microsoft 365 Groups whose team status meets the configured condition.Equals

Group Team Site Property

The following table lists the filter criteria for Microsoft 365 Group team site properties.

Property NameDescriptionCondition
Created timeManages Microsoft 365 Group team sites whose created time meets the configured condition.Before
Created timeManages Microsoft 365 Group team sites whose created time meets the configured condition.After
Created timeManages Microsoft 365 Group team sites whose created time meets the configured condition.Older than
Created timeManages Microsoft 365 Group team sites whose created time meets the configured condition.Within
Custom propertyManages Microsoft 365 Group team sites that have the specified custom property and the property value meets the configured condition.Contains
Custom propertyManages Microsoft 365 Group team sites that have the specified custom property and the property value meets the configured condition.Does not contain
Custom propertyManages Microsoft 365 Group team sites that have the specified custom property and the property value meets the configured condition.Equals
Custom propertyManages Microsoft 365 Group team sites that have the specified custom property and the property value meets the configured condition.Does not equal
Custom propertyManages Microsoft 365 Group team sites that have the specified custom property and the property value meets the configured condition.Matches
Custom propertyManages Microsoft 365 Group team sites that have the specified custom property and the property value meets the configured condition.Does not match
Exposure level (Insights)Manages Microsoft 365 Group team sites whose exposure level retrieved from Insights meets the configured condition.Matches any of these
Exposure level (Insights)Manages Microsoft 365 Group team sites whose exposure level retrieved from Insights meets the configured condition.Does not match
Geo LocationManages Microsoft 365 Group team sites whose geo location meets the configured condition.Equals
Lock/Archive statusManages Microsoft 365 Group team sites whose lock/archive status meets the configured condition.Equals
Modified timeManages Microsoft 365 Group team sites whose modified time meets the configured condition.Before
Modified timeManages Microsoft 365 Group team sites whose modified time meets the configured condition.After
Modified timeManages Microsoft 365 Group team sites whose modified time meets the configured condition.Older than
Modified timeManages Microsoft 365 Group team sites whose modified time meets the configured condition.Within
Risk level (Insights)Manages Microsoft 365 Group team sites whose risk level retrieved from Insights meets the configured condition.Matches any of these
Risk level (Insights)Manages Microsoft 365 Group team sites whose risk level retrieved from Insights meets the configured condition.Does not match
Sensitivity labelManages Microsoft 365 Group team sites whose sensitivity label meets the configured condition.Equals
Sensitivity level (Insights)Manages Microsoft 365 Group team sites whose sensitivity level retrieved from Insights meets the configured condition.Matches any of these
Sensitivity level (Insights)Manages Microsoft 365 Group team sites whose sensitivity level retrieved from Insights meets the configured condition.Does not match
TitleManages Microsoft 365 Group team sites whose title meets the configured condition.Contains
TitleManages Microsoft 365 Group team sites whose title meets the configured condition.Does not contain
TitleManages Microsoft 365 Group team sites whose title meets the configured condition.Equals
TitleManages Microsoft 365 Group team sites whose title meets the configured condition.Does not equal
TitleManages Microsoft 365 Group team sites whose title meets the configured condition.Matches
TitleManages Microsoft 365 Group team sites whose title meets the configured condition.Does not match
URLManages Microsoft 365 Group team sites whose URL meets the configured condition.Contains
URLManages Microsoft 365 Group team sites whose URL meets the configured condition.Does not contain
URLManages Microsoft 365 Group team sites whose URL meets the configured condition.Equals
URLManages Microsoft 365 Group team sites whose URL meets the configured condition.Does not equal
URLManages Microsoft 365 Group team sites whose URL meets the configured condition.Matches
URLManages Microsoft 365 Group team sites whose URL meets the configured condition.Does not match

Object Type - Microsoft 365 Users

The following table lists the filter criteria Microsoft 365 users.

Property NameDescriptionCondition
Company nameManages Microsoft 365 users whose company name meets the configured condition.Contains
Company nameManages Microsoft 365 users whose company name meets the configured condition.Does not contain
Company nameManages Microsoft 365 users whose company name meets the configured condition.Equals
Company nameManages Microsoft 365 users whose company name meets the configured condition.Does not equal
Company nameManages Microsoft 365 users whose company name meets the configured condition.Matches
Company nameManages Microsoft 365 users whose company name meets the configured condition.Does not match
Country or regionManages Microsoft 365 users whose country or region meets the configured condition.Contains
Country or regionManages Microsoft 365 users whose country or region meets the configured condition.Does not contain
Country or regionManages Microsoft 365 users whose country or region meets the configured condition.Equals
Country or regionManages Microsoft 365 users whose country or region meets the configured condition.Does not equal
Country or regionManages Microsoft 365 users whose country or region meets the configured condition.Matches
Country or regionManages Microsoft 365 users whose country or region meets the configured condition.Does not match
DepartmentManages Microsoft 365 users whose department meets the configured condition.Contains
DepartmentManages Microsoft 365 users whose department meets the configured condition.Does not contain
DepartmentManages Microsoft 365 users whose department meets the configured condition.Equals
DepartmentManages Microsoft 365 users whose department meets the configured condition.Does not equal
DepartmentManages Microsoft 365 users whose department meets the configured condition.Matches
DepartmentManages Microsoft 365 users whose department meets the configured condition.Does not match
Custom Microsoft Entra attributeManages Microsoft 365 users who have the custom Microsoft Entra attribute and the attribute value meets the configured condition.Contains
Custom Microsoft Entra attributeManages Microsoft 365 users who have the custom Microsoft Entra attribute and the attribute value meets the configured condition.Does not contain
Custom Microsoft Entra attributeManages Microsoft 365 users who have the custom Microsoft Entra attribute and the attribute value meets the configured condition.Equals
Custom Microsoft Entra attributeManages Microsoft 365 users who have the custom Microsoft Entra attribute and the attribute value meets the configured condition.Does not equal
Custom Microsoft Entra attributeManages Microsoft 365 users who have the custom Microsoft Entra attribute and the attribute value meets the configured condition.Matches
Custom Microsoft Entra attributeManages Microsoft 365 users who have the custom Microsoft Entra attribute and the attribute value meets the configured condition.Does not match
DepartmentManages Microsoft 365 users whose department meets the configured condition.Contains
DepartmentManages Microsoft 365 users whose department meets the configured condition.Does not contain
DepartmentManages Microsoft 365 users whose department meets the configured condition.Equals
DepartmentManages Microsoft 365 users whose department meets the configured condition.Does not equal
DepartmentManages Microsoft 365 users whose department meets the configured condition.Matches
DepartmentManages Microsoft 365 users whose department meets the configured condition.Does not match
Display nameManages Microsoft 365 users whose display name meets the configured condition.Contains
Display nameManages Microsoft 365 users whose display name meets the configured condition.Does not contain
Display nameManages Microsoft 365 users whose display name meets the configured condition.Equals
Display nameManages Microsoft 365 users whose display name meets the configured condition.Does not equal
Display nameManages Microsoft 365 users whose display name meets the configured condition.Matches
Display nameManages Microsoft 365 users whose display name meets the configured condition.Does not match
DomainManages Microsoft 365 users whose domain meets the configured condition.Contains
DomainManages Microsoft 365 users whose domain meets the configured condition.Does not contain
DomainManages Microsoft 365 users whose domain meets the configured condition.Equals
DomainManages Microsoft 365 users whose domain meets the configured condition.Does not equal
DomainManages Microsoft 365 users whose domain meets the configured condition.Matches
DomainManages Microsoft 365 users whose domain meets the configured condition.Does not match
Job titleManages Microsoft 365 users whose job title meets the configured condition.Contains
Job titleManages Microsoft 365 users whose job title meets the configured condition.Does not contain
Job titleManages Microsoft 365 users whose job title meets the configured condition.Equals
Job titleManages Microsoft 365 users whose job title meets the configured condition.Does not equal
Job titleManages Microsoft 365 users whose job title meets the configured condition.Matches
Job titleManages Microsoft 365 users whose job title meets the configured condition.Does not match
Last activity timeManages Microsoft 365 users whose last activity time meets the configured condition.Before
Last activity timeManages Microsoft 365 users whose last activity time meets the configured condition.After
Last activity timeManages Microsoft 365 users whose last activity time meets the configured condition.Older than
Last activity timeManages Microsoft 365 users whose last activity time meets the configured condition.Within
Mailbox recipient typeManages Microsoft 365 users whose mailbox recipient type meets the configured condition.Contains
Mailbox recipient typeManages Microsoft 365 users whose mailbox recipient type meets the configured condition.Does not contain
Mailbox recipient typeManages Microsoft 365 users whose mailbox recipient type meets the configured condition.Equals
Mailbox recipient typeManages Microsoft 365 users whose mailbox recipient type meets the configured condition.Does not equal
Mailbox recipient typeManages Microsoft 365 users whose mailbox recipient type meets the configured condition.Matches
Mailbox recipient typeManages Microsoft 365 users whose mailbox recipient type meets the configured condition.Does not match
OfficeManages Microsoft 365 users whose office meets the configured condition.Contains
OfficeManages Microsoft 365 users whose office meets the configured condition.Does not contain
OfficeManages Microsoft 365 users whose office meets the configured condition.Equals
OfficeManages Microsoft 365 users whose office meets the configured condition.Does not equal
OfficeManages Microsoft 365 users whose office meets the configured condition.Matches
OfficeManages Microsoft 365 users whose office meets the configured condition.Does not match
On-premises security identifierManages Microsoft 365 users whose on-premises security identifier meets the configured condition.Contains
On-premises security identifierManages Microsoft 365 users whose on-premises security identifier meets the configured condition.Does not contain
On-premises security identifierManages Microsoft 365 users whose on-premises security identifier meets the configured condition.Equals
On-premises security identifierManages Microsoft 365 users whose on-premises security identifier meets the configured condition.Does not equal
On-premises security identifierManages Microsoft 365 users whose on-premises security identifier meets the configured condition.Matches
On-premises security identifierManages Microsoft 365 users whose on-premises security identifier meets the configured condition.Does not match
Password last changed timeManages Microsoft 365 users whose password last changed time meets the configured condition.Before
Password last changed timeManages Microsoft 365 users whose password last changed time meets the configured condition.After
Password last changed timeManages Microsoft 365 users whose password last changed time meets the configured condition.Older than
Password last changed timeManages Microsoft 365 users whose password last changed time meets the configured condition.Within
Usage locationManages Microsoft 365 users whose usage location meets the configured condition.Equals
User creation timeManages Microsoft 365 users whose creation time meets the configured condition.Before
User creation timeManages Microsoft 365 users whose creation time meets the configured condition.After
User creation timeManages Microsoft 365 users whose creation time meets the configured condition.Older than
User creation timeManages Microsoft 365 users whose creation time meets the configured condition.Within
User principal nameManages Microsoft 365 users whose user principal name meets the configured condition.Contains
User principal nameManages Microsoft 365 users whose user principal name meets the configured condition.Does not contain
User principal nameManages Microsoft 365 users whose user principal name meets the configured condition.Equals
User principal nameManages Microsoft 365 users whose user principal name meets the configured condition.Does not equal
User principal nameManages Microsoft 365 users whose user principal name meets the configured condition.Matches
User principal nameManages Microsoft 365 users whose user principal name meets the configured condition.Does not match
User typeManages Microsoft 365 users whose user type meets the configured condition.Equals
NOTE

To use Last activity time and Mailbox recipient type, a subscription for Cense will be required.