Skip to main content
Cloud / Azure / Products / Microsoft Purview Data Loss Prevention - Prevent Data Leakage

Microsoft Purview Data Loss Prevention - Prevent Data Leakage

Microsoft Purview Data Loss Prevention identifies, monitors and protects sensitive data across Microsoft 365, devices, cloud apps and inline web traffic.

security
Pricing Model Licensed through Microsoft 365; see the Microsoft 365 service descriptions for details
Availability Policies are created and maintained in the Microsoft Purview portal; some locations and features are marked preview
Data Sovereignty Covers Microsoft 365 services, devices, on-premises file shares and non-Microsoft cloud apps
Reliability SLA per vendor / see the official SLA page SLA

What is Microsoft Purview Data Loss Prevention?

Organizations control sensitive information such as financial data, proprietary data, credit card numbers, health records and social security numbers. To protect this data and reduce the risk from oversharing, they need a way to prevent users from inappropriately sharing it. That practice is called data loss prevention.

In Microsoft Purview you implement DLP by defining and applying DLP policies. A DLP policy helps you identify, monitor and automatically protect sensitive data in enterprise applications & devices and in inline web traffic. Policies act on a variety of locations, methods of data transmission and types of user activities. DLP is part of Microsoft Purview; for an overview of the whole platform, see our page on Microsoft Purview.

Core Features

Deep content analysis: DLP evaluates keywords, regular expressions, internal function validation and secondary matches in proximity to a primary match, complemented by machine learning algorithms.

Broad location coverage: Microsoft 365 services, Office applications, Windows and macOS devices, non-Microsoft cloud apps, on-premises file shares and SharePoint, Fabric and Power BI workspaces, and Microsoft 365 Copilot and Copilot chat in preview.

Inline web traffic (preview): Together with collection policies, DLP monitors data transmitted on your network and in Microsoft Edge for Business to unmanaged cloud apps, including several generative AI services.

Graduated protective actions: From a policy tip through blocking with override to hard blocking, quarantine for data at rest, and hiding content in Teams chat.

Simulation mode and tuning: Policies can be rolled out without effect, evaluated and adjusted, for example on locations, conditions, sensitive information definitions and restricted apps or sites.

Typical Use Cases

Preventing misdirected sharing: A policy triggers when a defined number of sensitive records is about to be sent to external recipients.

Endpoint protection: On Windows and macOS devices, copying sensitive items to removable media can be audited or restricted.

On-premises repositories: Files in file shares are moved to a quarantine folder; this requires the Microsoft Purview Information Protection scanner.

Limiting AI usage: Inline web traffic policies address transfers to unmanaged AI applications.

Benefits

  • Consistent policies across Microsoft 365, endpoints, cloud apps and on-premises storage
  • Native integration into the applications your users work in every day
  • Low-risk rollout through simulation mode before enabling blocking actions
  • Full logging in the Microsoft 365 audit log and analysis in activity explorer
  • Incident investigation in both the Purview dashboard and the Microsoft Defender portal

Integration with innFactory

As a Microsoft Solutions Partner, innFactory supports you in adopting Microsoft Purview DLP: capturing the categories of sensitive information to protect, designing and scoping policies, rolling out through simulation mode, tuning based on results, and building alert and investigation processes.

Contact us for a no-obligation consultation on data loss prevention with Microsoft Purview.

Typical Use Cases

Prevent inadvertent sharing of sensitive data in Exchange, SharePoint, OneDrive and Teams
Audit or restrict copying sensitive items to USB devices on Windows and macOS
Move sensitive files in on-premises file shares to a quarantine location
Limit sharing of sensitive data with unmanaged AI applications
Evaluate the impact of new policies in simulation mode

Technical Specifications

0th Two policy scopes: enterprise applications & devices, and inline web traffic
1st Covered locations: Microsoft 365 services such as Exchange, SharePoint, OneDrive and Teams, Office applications, devices running Windows 10, Windows 11 and the three most recent versions of macOS, non-Microsoft cloud apps, on-premises file shares and on-premises SharePoint, Microsoft Fabric and Power BI workspaces, Microsoft 365 Copilot and Copilot chat (preview), and managed cloud apps
2nd Inline web traffic (preview) targets unmanaged cloud apps through Microsoft Edge for Business and network activity, including OpenAI ChatGPT, Google Gemini, DeepSeek, Microsoft Copilot and over 34,000 apps in the Defender for Cloud Apps catalog
3rd Deep content analysis rather than a simple text scan: keyword matches, regular expressions, internal function validation, proximity matches and machine learning algorithms
4th Policy components: what to monitor through predefined templates or custom policies using sensitive information types, retention labels and sensitivity labels, administrative scoping through administrative units, locations, conditions and actions
5th Protective actions: show a policy tip, block sharing with an override option and justification capture, block sharing without override, lock and move data at rest to a secure quarantine, and hide sensitive information in Teams chat
6th Simulation mode to evaluate impact before enabling blocking actions; note that 'stop processing more rules' doesn't work in simulation mode
7th All DLP monitored activities are recorded to the Microsoft 365 audit log by default and routed to activity explorer
8th DLP alerts are available in the Microsoft Defender portal for six months and in the Purview DLP alerts dashboard for 30 days
9th Reporting through the overview page, alerts dashboard, activity explorer and PowerShell cmdlets in Security & Compliance PowerShell and Exchange PowerShell
10th On-premises repositories require the Microsoft Purview Information Protection scanner; policies generally take effect about an hour after being turned on

Frequently Asked Questions

What is Microsoft Purview Data Loss Prevention?

Data loss prevention is the practice of preventing users from inappropriately sharing sensitive data. In Microsoft Purview you implement DLP by defining and applying DLP policies that identify, monitor and automatically protect sensitive content. DLP is part of Microsoft Purview; for an overview of the whole platform see our page on [Microsoft Purview](/en/cloud/azure/products/purview/).

Which locations does DLP cover?

Microsoft names Microsoft 365 services such as Exchange, SharePoint, OneDrive accounts and Teams chat and channel messages, Office applications such as Word, Excel and PowerPoint, devices running Windows 10, Windows 11 and the three most recent versions of macOS, non-Microsoft cloud apps, on-premises file shares and on-premises SharePoint, Microsoft Fabric and Power BI workspaces, Microsoft 365 Copilot and Copilot chat as preview, and managed cloud apps.

How does DLP detect sensitive content?

DLP uses deep content analysis rather than a simple text scan. It evaluates primary matches to keywords, regular expressions, internal function validation, and secondary matches in proximity to a primary match. It also uses machine learning algorithms and other methods.

Which protective actions can a DLP policy take?

Microsoft names showing a policy tip as a warning, blocking sharing with an override option and justification capture, blocking without an override option, locking data at rest and moving it to a secure quarantine location, and not displaying sensitive information in Teams chat.

What is simulation mode for?

In simulation mode, the actions defined in a policy aren't applied. This lets you evaluate the impact before enabling blocking actions. Microsoft recommends deploying policies in simulation mode first and evaluating them. Note that 'stop processing more rules' doesn't work in simulation mode.

How long are DLP alerts available?

DLP alerts are available in the Microsoft Defender portal for six months. In the Microsoft Purview DLP alerts dashboard they are available for 30 days.

Note: All product information on this page has been compiled with care, but is provided without guarantee and may be outdated or incomplete. Cloud services evolve rapidly — features, pricing, SLAs, and availability change frequently. Authoritative and up-to-date information can only be found on the official product page of Azure (official documentation). This page does not represent an offer by Azure.

Microsoft Solutions Partner

innFactory is a Microsoft Solutions Partner. We provide expert consulting, implementation, and managed services for Azure.

Microsoft Solutions Partner Microsoft Data & AI

Ready to start with Microsoft Purview Data Loss Prevention - Prevent Data Leakage?

Our certified Azure experts help you with architecture, integration, and optimization.

Schedule Consultation