At first, you should not use SMB but use IIS WevDAV file sharerings. That make log more fine.
And secondary, you should do to edit domain policies with OU to prevent from using media connect and copying files to external strages.
Finally, deploy secure contents management system and check the outbound traffics.
Hiroaki Kondo
Network Security Consultant in Japan
hackman a venus.dti.ne.jp