Microsoft certification badges banner
Headshot of Michael Korting

Blog

Microsoft 365 • Security • Compliance

Microsoft Purview Data Loss Prevention (DLP): A Practical Guide for Microsoft 365 Administrators

A practical starter guide to protecting sensitive data across Microsoft 365, endpoints, and supported data locations.

Why Data Loss Prevention matters

Sensitive information is constantly moving through email, Teams chats, file sharing, cloud storage, and endpoint devices. Even with good user intent, accidental exposure happens: forwarding a spreadsheet to a personal email, sharing a OneDrive link externally, or pasting regulated data into an unmanaged app. Data Loss Prevention (DLP) exists to reduce that risk without bringing work to a halt.

Microsoft Purview Data Loss Prevention is a policy-based solution that helps organizations detect, monitor, and protect sensitive data, such as personally identifiable information (PII), financial identifiers, and health information, across Microsoft 365 services and connected endpoints. It enables organizations to enforce guardrails that align with regulatory obligations and internal data-handling requirements.

What is Microsoft Purview DLP?

Microsoft Purview DLP is designed to help prevent inappropriate sharing or leakage of sensitive information. It works by applying policies that can detect specific data types and then take actions such as warning the user, notifying administrators, restricting sharing, or applying additional protection controls. This coverage extends across key collaboration and productivity channels where data commonly moves.

One of the strengths of Purview DLP is that it works with broader information-protection capabilities, such as classification and sensitivity labels, allowing for more precise control and more consistent protection across the data lifecycle.

Key capabilities in plain English

  • Unified detection and protection: Identify and protect sensitive information across supported Microsoft 365 locations, Office apps, Windows and macOS devices, supported non-Microsoft cloud apps, and selected on-premises repositories, depending on licensing and deployment configuration.
  • Deep content analysis: Detect sensitive data using content inspection, machine learning, pattern matching, and regular-expression evaluation to identify items such as Social Security numbers, credit card numbers, and other regulated identifiers.
  • Adaptive controls: Balance security with productivity by warning users, displaying policy tips, allowing justified overrides where appropriate, or moving to enforced restrictions.
  • Centralized management: Configure and manage policies in the Microsoft Purview portal alongside other compliance and information-protection capabilities.
  • Microsoft 365 Copilot protection: A dedicated Microsoft 365 Copilot policy location (currently in preview) can help prevent Copilot and agents from using content with specified sensitivity labels or sensitive information types in their responses. This location is only available when you build a policy from the Custom template.
  • Security operations integration: Depending on licensing and configuration, DLP alerts can support investigation and response workflows involving Microsoft Defender XDR or Microsoft Sentinel.

How DLP policies typically work

A DLP policy generally consists of:

  • Where to look: Locations such as Exchange email, SharePoint sites, OneDrive accounts, Teams messages, and onboarded Windows and macOS devices.
  • What to detect: Sensitive information types (SITs), sensitivity labels, or other supported classifiers.
  • When to trigger: Conditions such as content being shared externally, sent outside the organization, or copied to removable media.
  • What to do: Actions such as displaying a policy tip, warning or blocking the user, restricting access, or notifying administrators.

Most organizations should start new policies in simulation mode, which lets you see what a policy would match without applying its actions. Use that period, optionally with policy tips turned on, to learn how data flows, tune detections, and reduce false positives. After validating policy behavior, administrators can move toward stronger enforcement for high-risk data types and scenarios.

Before you add templates: review the default policies

Every tenant includes a set of default DLP policies that provide baseline protection, including policies that detect credit card numbers in externally shared email and documents, in Teams messages, and on devices, plus a default policy for the Microsoft 365 Copilot location. Review what these defaults do before layering new policies on top, so you don't end up with overlapping rules or unexpected alerts. You can edit or delete them as needed.

Recommended U.S. starter templates

Microsoft provides DLP policy templates aligned with common regulations and business needs. For a typical U.S. organization, the following templates can provide a practical starting point. Treat them as starting configurations rather than complete compliance solutions, and validate each one against the organization's legal, regulatory, contractual, and operational requirements.

Several templates also have an Enhanced version that adds named-entity detection, such as full names and U.S. physical addresses. These can improve accuracy by looking for identifiers alongside the person they belong to.

1) U.S. Financial Data

Sensitive information types included:

  • Credit Card Number
  • U.S. Bank Account Number
  • ABA Routing Number

Depending on organizational requirements, consider adding other financial identifiers such as SWIFT codes or International Banking Account Numbers (IBAN) where applicable.

2) U.S. Personally Identifiable Information (PII) Data

Sensitive information types included:

  • U.S. Individual Taxpayer Identification Number (ITIN)
  • U.S. Social Security Number (SSN)
  • U.S./U.K. Passport Number

If your organization also handles identifiers such as U.S. driver's license numbers, add those sensitive information types to the policy yourself.

3) U.S. Health Insurance Act (HIPAA)

This template uses two groups of conditions joined by AND, so content must contain both to match:

  • An individual identifier, such as a U.S. Social Security Number or a Drug Enforcement Agency (DEA) number, and
  • Medical diagnosis information, detected through large keyword lists from the International Classification of Diseases (ICD-9-CM and ICD-10-CM).

Requiring both a person and a diagnosis is what makes this template more precise than a policy that simply looks for Social Security numbers.

Common settings for all three templates

By default, each template detects when covered content is shared with people outside the organization. Configure it to notify users and designated administrators of policy matches, and to display policy tips in supported applications and workloads. After testing in simulation mode, consider restricting access or applying other supported protection actions.

Going further: expand coverage as you mature

Once a baseline is stable, organizations can consider expanding DLP into:

  • Additional templates relevant to their footprint, including PCI DSS, GLBA, GDPR, or other applicable requirements.
  • Endpoint controls for supported activities on Windows and macOS devices, such as copying to removable media or network shares, printing, clipboard use, and uploads through browsers to cloud services.
  • Label-driven policies that align DLP with sensitivity labels and data classification. Note that not every location supports label conditions. Teams chat and channel messages, for example, can only match on sensitive information types, and combining locations in one policy limits you to the conditions they all support.
  • Inline protection for web and AI apps, such as limiting sensitive data pasted or uploaded into generative AI sites through Microsoft Edge for Business or network integrations, where licensed and supported.
  • Security operations workflows involving Microsoft Defender XDR or Microsoft Sentinel where supported.

Final thoughts

Purview DLP is most effective when implemented as a program rather than a single policy. Start with a few high-value scenarios, use user-visible policy tips to guide behavior, and iterate based on real-world telemetry. Over time, the organization can move from awareness and auditing into targeted enforcement that reduces risk while keeping collaboration productive.

References