en|de
Microsoft Purview · Data Loss Prevention

Detect sensitive data in Microsoft 365 and protect it against accidental disclosure

Microsoft Purview Data Loss Prevention helps detect sensitive information in Exchange, SharePoint, OneDrive, Teams, and on endpoints, and protect it against accidental or impermissible disclosure. This does not amount to complete protection against every kind of data loss – DLP is an effective, but not an absolute, building block.

  • Detect sensitive data before it is shared without control
  • Test policies in simulation mode first
  • Deliberately control warnings, blocks, and exceptions
Direct Microsoft Partner
Simulation Mode Before Activation
Personal Consulting
24-Hour Response
Starting Point

Sensitive data often leaves your company unnoticed

Without technical controls, it remains unclear where sensitive information is being shared, copied, or passed on.

01

External sharing without control

Files with sensitive content are shared with customers, partners, or service providers without this being monitored systematically.

02

Copying to USB or private cloud services

Sensitive files can be transferred unnoticed to removable media or unmanaged cloud storage.

03

Sensitive data in external AI tools

Confidential content is pasted into external AI applications without any check of whether that is permissible.

In Short

Does DLP prevent every data loss?

No. Data Loss Prevention detects defined sensitive content and responds, depending on the policy, with a warning, a block, or logging. Complete protection against every kind of data loss – for example in the case of deliberate circumvention – cannot be guaranteed. DLP is an effective, but not an absolute, building block of your data protection strategy.

How It Works

How Microsoft Purview DLP works

Details on sensitivity labels and information protection can be found on the main Purview page.

Detect sensitive information types

Content is identified as sensitive based on predefined patterns, keywords, and trainable classifiers.

Sensitivity labels as a trigger

An assigned sensitivity label can itself become a condition in a DLP policy.

Policies for Exchange, SharePoint, OneDrive, and Teams

Central Microsoft 365 workloads are monitored and protected according to the same rules.

Endpoint DLP for Windows & macOS

Microsoft Purview Endpoint DLP supports securing endpoints running Windows and macOS. The specific support depends on the platform versions released and the licensing prerequisites, and is verified within the project.

Extensions such as Microsoft Defender for Cloud Apps, on-premises data sources, Fabric, or Power BI are outside the focus of this service, but can be evaluated as an optional extension if required.
Response to a Policy Violation

Warnings, blocks, and exceptions

01

Policy tips & warnings

Affected users receive a notice that an action violates a policy.

02

Blocking with or without override

Sharing can be blocked – in some cases with the option to override the block with a justification.

03

Documented justification

An override is logged together with the justification provided by the user.

04

Logging & evidence

All activities feed into the audit log and Activity Explorer.

Scope of Services

Our services around Data Loss Prevention

By default, the service covers planning, configuration, validation, and handover of the solution.

01

Planning & policy design

Microsoft provides proven policy templates that are used as a starting point. Depending on requirements, these are adapted or developed entirely to your specifications.

02

Device onboarding (Endpoint DLP)

Endpoint DLP requires devices to be properly integrated into Microsoft Defender for Endpoint. Onboarding can be supported within the project; provisioning and management of the endpoints remain with the customer.

03

Simulation mode & test phase

New policies are first introduced in simulation mode and evaluated against real usage patterns.

04

Productive rollout & handover

After the evaluation, policies are activated, documented, and handed over to your team.

On request, organizational exception and escalation processes for DLP policies are also defined together; final approval and governance remain with the customer.

Explicitly not included in the standard scope: legal assessment or legal advice, final licensing advice and procurement, and ongoing DLP monitoring (alert dashboard, regular Activity Explorer evaluation). Ongoing operations can be agreed separately as an operations or managed service if desired.
Practical Scenarios

Typical DLP scenarios

Customer and contract data by email

A contract file containing personal or financial data is accidentally sent to the wrong or an external recipient.

HR files in SharePoint and OneDrive

HR documents are visible in a broader scope than intended.

Financial data and IBANs in Teams chats

Payment information is shared in a Teams channel that also includes external participants.

Data leakage by departing employees

Unusually large volumes of data are copied or transferred to external storage locations before someone leaves.

Sensitive data in external AI tools

Confidential content is pasted into an external AI application without any prior check.

Approach

How the collaboration works

01

Clarify the situation & goals

Data worth protecting, workloads, and risks are recorded together.

02

Design policies

Based on Microsoft templates or entirely to your specifications.

03

Simulation mode & evaluation

The impact on business processes is observed before any measures take effect.

04

Activate, document, hand over

Policies are set live and handed over to your team.

Results

Which results you receive

A documented picture of the sharing situation

An evaluation from simulation mode showing where sensitive data is currently being shared.

Tested and activated policies

DLP policies introduced in a controlled way for the agreed workloads.

An agreed exception process

Clear rules on how and by whom exceptions are approved – on request.

Good to Know

The limits of Data Loss Prevention

Microsoft Purview DLP reduces the risk of accidental or impermissible disclosure of sensitive data. It does not amount to complete, guaranteed protection against every kind of data loss – particularly in the case of deliberate circumvention. The actual scope of protection depends on the chosen configuration, the licensed capabilities, and device management.

  • On private or unmanaged devices, the scope of protection may be limited compared with fully managed corporate devices.
  • Capabilities for monitoring AI interactions may in part be in preview status and are only used with the corresponding Microsoft notice.
  • DLP does not replace legal advice or organizational rules for handling sensitive data.
  • No assurance is given against deliberate circumvention or false positives.
Decision Guide

Data Loss Prevention or a different Microsoft Purview service?

The overall Purview operating model

How do classification, protection, monitoring, and compliance fit together?

Go to main Purview page →
FAQ

Questions about Data Loss Prevention

Does DLP prevent every data loss?

No. DLP detects defined sensitive content and responds, depending on the policy, with a warning, a block, or logging. Complete protection against every kind of data loss cannot be guaranteed.

What happens if someone wants to share a sensitive file?

Depending on the configuration, a warning appears, sharing is blocked, or it is blocked with the option to override the action with a documented justification.

Can we allow exceptions for legitimate business cases?

Yes. On request, organizational processes for exceptions, escalations, and responsibilities in connection with DLP policies are defined together. Final approval and governance remain with the customer.

Do new DLP policies take effect immediately?

No. New policies are first introduced in simulation mode: actions are logged but not enforced. Blocking measures are only activated after evaluation and fine-tuning.

Does DLP also protect on private devices (BYOD)?

Enforcement on private or unmanaged devices depends on the Microsoft security mechanisms in use and on device management. The scope of protection may be limited compared with fully managed corporate devices.

Does DLP help against sensitive data being pasted into ChatGPT and similar tools?

Microsoft continuously develops protection mechanisms for AI applications, including within Microsoft Purview DSPM and DSPM for AI. Preview capabilities are only used with the corresponding Microsoft notice and may be limited in terms of availability and functionality.

Is Data Loss Prevention also worthwhile for smaller companies?

Yes. The service is aimed primarily at small and medium-sized companies that use Microsoft 365 productively. What matters is the actual risk of uncontrolled sharing, not company size.

Which licenses do we need for Data Loss Prevention?

Microsoft Purview DLP capabilities are available depending on the respective Microsoft 365 licensing model. Advanced capabilities such as Endpoint DLP, advanced compliance evaluations, or Premium eDiscovery may require additional licenses, Microsoft 365 E5, or add-on licenses. The specific evaluation is carried out based on your existing environment before the project starts (as of July 2026).

Initial Consultation

How well is your sensitive data protected against accidental disclosure?

In a free initial consultation, we clarify whether a targeted DLP configuration, a simulation phase, or a structured evaluation of your current sharing is the right next step.

Sebastian Kerssen, Managing Director of ReByteIT

You speak directly with Sebastian Kerssen – working in the Microsoft ecosystem since 2014, as a direct Microsoft partner with no intermediaries.