Microsoft Purview: Review DLP for Box, Dropbox and Salesforce

In August 2026, Microsoft extended Microsoft Purview Data Loss Prevention to non-Microsoft connected apps. Microsoft Learn says DLP policies can now detect, monitor, and protect sensitive data at rest in connected SaaS applications such as Box, Dropbox, Google Workspace, and Salesforce. For organizations that use cloud storage beyond Microsoft 365, this is a practical reason to review data coverage in Microsoft Purview.

What Microsoft added in August 2026

The Purview “What’s new” page lists the capability in the August 2026 section and marks it as preview. The detail page explains that Purview DLP for non-Microsoft apps uses the same classification engine and policy framework that are available for Microsoft 365 locations. DLP therefore no longer has to stop at SharePoint, OneDrive, or Exchange when sensitive files are stored elsewhere.

Microsoft lists Box, Dropbox, Google Workspace, and Salesforce as supported apps. Microsoft also notes that these apps are rolling out in phases. Not every app will necessarily be available in every tenant at the same time. For small IT teams, the first step is therefore an inventory and availability check, not a broad immediate rollout across every connected service or without a review of existing data classifications.

Which dates and limits apply

The relevant Microsoft Learn pages are dated 26 August 2026 and show an update timestamp of 28 August 2026 in the page metadata. Microsoft does not state a mandatory migration deadline. Planning should therefore refer to August 2026 and the documented preview status, not to a fixed enforcement date that Microsoft has not published.

The preview limits matter. Microsoft states that simulation mode is not supported for non-Microsoft connected app policies. A policy is either turned on immediately or left turned off. Microsoft also states that these app locations cannot be combined with SharePoint, OneDrive, Exchange, Fabric, or Devices in the same policy. For Data Loss Prevention, this usually means separate policies with a deliberately narrow scope.

Why this matters for small and midsize companies

Many organizations with 10 to 250 workplaces do not work only in Microsoft 365. Sales teams may use Salesforce, project teams may exchange files through Box or Dropbox, and external partners may bring Google Workspace into shared workspaces. Those locations often hold personal data, contracts, exports, or customer lists that are invisible in a Microsoft-365-only DLP design.

The new Purview option is not a replacement for a data strategy or a legal assessment. It can, however, help extend existing classifications to additional SaaS repositories. That fits a technical security and privacy implementation pattern: first identify where sensitive data actually resides, then build policies that trigger in a predictable way and do not unexpectedly interrupt business processes.

What to check before activation

Microsoft documents several prerequisites. The relevant app must be connected to Microsoft Defender for Cloud Apps through an API connector. Defender for Cloud Apps uses the cloud provider’s APIs, and the first scans can take time depending on tenant size, number of users, and volume of files. Conditions and actions also depend on the item attributes that each individual app exposes.

  • Only custom policies are supported for non-Microsoft app locations.
  • Policy tips and user overrides are not supported for these DLP policies.
  • Encrypted files and PDF files aren’t currently supported for classification.

These constraints should be part of the pilot plan. If they are only discovered after activation, missing matches can easily be mistaken for a fault even though Microsoft documents them as known limitations.

Concrete next steps

  • Inventory which supported apps are used in production and whether they store sensitive data.
  • Check in Defender for Cloud Apps whether the relevant API connectors are configured and have completed their initial scans.
  • Create separate custom DLP policies for non-Microsoft app locations instead of mixed Microsoft 365 and SaaS policies.
  • Begin with the policy left turned off and obtain business approval, because Microsoft says simulation mode isn’t supported.
  • Document known gaps such as encrypted files, PDF files, and app-specific attribute differences.

Official Microsoft sources

Whether your cloud repositories are missing from DLP coverage and how to build a low-risk pilot is something we can review as part of a Microsoft Security Assessmentget in touch.

Recommended Next Step

What does this mean for your environment?

Assess the topic in the context of your Microsoft 365 environment and define a practical next step.

Sebastian Kerssen, Managing Director of ReByteIT

You speak directly with Sebastian Kerssen – working in the Microsoft ecosystem since 2014, with personal consulting and a dedicated point of contact.

Leave a comment