Data Loss Prevention
Microsoft Purview Data Loss Prevention (DLP) helps you detect, warn, and block sensitive information from leaving your organization inappropriately. DLP monitors content across email, files, chat, and endpoints—protecting against accidental exposure and intentional exfiltration.
What is DLP?
DLP policies scan content for sensitive information and take action:
| Location | What DLP Monitors |
|---|---|
| Exchange Online | Email messages and attachments |
| SharePoint/OneDrive | Documents and file shares |
| Teams | Chat messages and channel files |
| Endpoints | Windows devices (copy to USB, print, upload) |
| Power Platform | Power BI, Power Apps data flows |
How DLP Works
| Action | When to Use | User Experience |
|---|---|---|
| Audit | Testing policies | No notification, logged only |
| Warn | Low-risk matches | User sees tip, can proceed |
| Block with Override | Medium risk, justification needed | User provides reason |
| Block | High risk (SSN, credit cards) | Hard stop, cannot proceed |
What DLP Detects
Built-in Sensitive Information Types
- Social Security Numbers
- Credit card numbers
- Passport numbers
- Bank account numbers
- Driver's license numbers
Regulatory Templates
- FERPA — Student educational records
- HIPAA — Health information
- PCI-DSS — Payment card data
- GDPR — Personal data (EU residents)
Custom Detection
- Student UIN patterns
- Employee ID formats
- Research grant numbers
- Custom keywords and phrases
DLP + Sensitivity Labels
DLP becomes more powerful when combined with Information Protection:
| Condition | Example |
|---|---|
| Label = "Restricted" + External recipient | Block email |
| Label = "Confidential - FERPA" + USB copy | Block with override |
| Any sensitive data + Public sharing link | Warn user |
Use sensitivity labels as DLP conditions whenever possible. Labels are more reliable than content scanning and reduce false positives.
Key Capabilities
Email Protection
Block or encrypt emails containing sensitive data before they leave your organization.
File Protection
Prevent sharing of sensitive documents to external users or public links.
Teams Protection
Monitor chat messages and channel posts for sensitive information.
Endpoint Protection (E5/A5)
Extend DLP to Windows devices—monitor USB copies, printing, and cloud uploads.
Quick Links
| Resource | Description |
|---|---|
| Purview DLP | DLP policy management |
| DLP Policy Reference | Microsoft documentation |
| Email DLP & Encryption | Detailed email protection guide |
| Implementation Guide | Enterprise deployment guide |
Related Solutions
- Information Protection — Labels that DLP can use as conditions
- Insider Risk Management — DLP alerts feed risk scoring
- Communication Compliance — Monitor message content