Hi..
I'll try and answer your questions.
1. This depends on your Identity Source. If the Identity Source is Azure AD (not common), then you would have to add Azure AD as Identity Source in Verify. The easier thing to do if you are starting from scratch is to use Verify Cloud as your Identity Source.
2. In Verify, on a per-app basis, you can add Groups to which an Access Policy would apply. These Groups would be imported from your Identity Source (AD, Azure AD, etc) or from within the Verify Cloud Directory.
3. DLP is a separate thing entirely. For MS apps, you will have to use Intune App Protection to control data flow in and out of O365 apps. See
https://www.ibm.com/docs/en/maas360?topic=miapp-configuring-microsoft-intune-app-protection-integration-in-maas360-portal. Be aware that the Groups you target will again be a function of the Groups in your Identity Source. Note that App Protection policies have to be targeted at Azure AD Groups, so you will either have to use Azure AD as your identity Source or use Azure AD Connect to replicate users and groups to Azure AD.
There are a couple of blogs that may help:
https://community.ibm.com/community/user/security/blogs/margaret-radford/2021/06/28/migrating-to-office-365-exchange-online-with-ibm-shttps://community.ibm.com/community/user/security/blogs/margaret-radford/2021/09/09/migrating-from-on-premise-ad-to-azure-ad-with-ibmThanks...
------------------------------
Clinton Adams
------------------------------