Detect sensitive data in Microsoft 365 and protect it against accidental disclosure
Microsoft Purview Data Loss Prevention helps detect sensitive information in Exchange, SharePoint, OneDrive, Teams, and on endpoints, and protect it against accidental or impermissible disclosure. This does not amount to complete protection against every kind of data loss – DLP is an effective, but not an absolute, building block.
- Detect sensitive data before it is shared without control
- Test policies in simulation mode first
- Deliberately control warnings, blocks, and exceptions
Sensitive data often leaves your company unnoticed
Without technical controls, it remains unclear where sensitive information is being shared, copied, or passed on.
External sharing without control
Files with sensitive content are shared with customers, partners, or service providers without this being monitored systematically.
Copying to USB or private cloud services
Sensitive files can be transferred unnoticed to removable media or unmanaged cloud storage.
Sensitive data in external AI tools
Confidential content is pasted into external AI applications without any check of whether that is permissible.
Does DLP prevent every data loss?
No. Data Loss Prevention detects defined sensitive content and responds, depending on the policy, with a warning, a block, or logging. Complete protection against every kind of data loss – for example in the case of deliberate circumvention – cannot be guaranteed. DLP is an effective, but not an absolute, building block of your data protection strategy.
How Microsoft Purview DLP works
Details on sensitivity labels and information protection can be found on the main Purview page.
Detect sensitive information types
Content is identified as sensitive based on predefined patterns, keywords, and trainable classifiers.
Sensitivity labels as a trigger
An assigned sensitivity label can itself become a condition in a DLP policy.
Policies for Exchange, SharePoint, OneDrive, and Teams
Central Microsoft 365 workloads are monitored and protected according to the same rules.
Endpoint DLP for Windows & macOS
Microsoft Purview Endpoint DLP supports securing endpoints running Windows and macOS. The specific support depends on the platform versions released and the licensing prerequisites, and is verified within the project.
Warnings, blocks, and exceptions
Policy tips & warnings
Affected users receive a notice that an action violates a policy.
Blocking with or without override
Sharing can be blocked – in some cases with the option to override the block with a justification.
Documented justification
An override is logged together with the justification provided by the user.
Logging & evidence
All activities feed into the audit log and Activity Explorer.
Our services around Data Loss Prevention
By default, the service covers planning, configuration, validation, and handover of the solution.
Planning & policy design
Microsoft provides proven policy templates that are used as a starting point. Depending on requirements, these are adapted or developed entirely to your specifications.
Device onboarding (Endpoint DLP)
Endpoint DLP requires devices to be properly integrated into Microsoft Defender for Endpoint. Onboarding can be supported within the project; provisioning and management of the endpoints remain with the customer.
Simulation mode & test phase
New policies are first introduced in simulation mode and evaluated against real usage patterns.
Productive rollout & handover
After the evaluation, policies are activated, documented, and handed over to your team.
On request, organizational exception and escalation processes for DLP policies are also defined together; final approval and governance remain with the customer.
Typical DLP scenarios
Customer and contract data by email
A contract file containing personal or financial data is accidentally sent to the wrong or an external recipient.
HR files in SharePoint and OneDrive
HR documents are visible in a broader scope than intended.
Financial data and IBANs in Teams chats
Payment information is shared in a Teams channel that also includes external participants.
Data leakage by departing employees
Unusually large volumes of data are copied or transferred to external storage locations before someone leaves.
Sensitive data in external AI tools
Confidential content is pasted into an external AI application without any prior check.
How the collaboration works
Clarify the situation & goals
Data worth protecting, workloads, and risks are recorded together.
Design policies
Based on Microsoft templates or entirely to your specifications.
Simulation mode & evaluation
The impact on business processes is observed before any measures take effect.
Activate, document, hand over
Policies are set live and handed over to your team.
Which results you receive
A documented picture of the sharing situation
An evaluation from simulation mode showing where sensitive data is currently being shared.
Tested and activated policies
DLP policies introduced in a controlled way for the agreed workloads.
An agreed exception process
Clear rules on how and by whom exceptions are approved – on request.
The limits of Data Loss Prevention
Microsoft Purview DLP reduces the risk of accidental or impermissible disclosure of sensitive data. It does not amount to complete, guaranteed protection against every kind of data loss – particularly in the case of deliberate circumvention. The actual scope of protection depends on the chosen configuration, the licensed capabilities, and device management.
- On private or unmanaged devices, the scope of protection may be limited compared with fully managed corporate devices.
- Capabilities for monitoring AI interactions may in part be in preview status and are only used with the corresponding Microsoft notice.
- DLP does not replace legal advice or organizational rules for handling sensitive data.
- No assurance is given against deliberate circumvention or false positives.
Data Loss Prevention or a different Microsoft Purview service?
The overall Purview operating model
How do classification, protection, monitoring, and compliance fit together?
Go to main Purview page →GDPR & Compliance
Retention, evidence, and legal delimitation in detail.
View GDPR & Compliance →Access and identities
Who may access what, and under which conditions?
Microsoft Entra ID →Overall security posture
How should our Microsoft security posture be assessed overall?
Security Assessment →Questions about Data Loss Prevention
Does DLP prevent every data loss?
No. DLP detects defined sensitive content and responds, depending on the policy, with a warning, a block, or logging. Complete protection against every kind of data loss cannot be guaranteed.
What happens if someone wants to share a sensitive file?
Depending on the configuration, a warning appears, sharing is blocked, or it is blocked with the option to override the action with a documented justification.
Can we allow exceptions for legitimate business cases?
Yes. On request, organizational processes for exceptions, escalations, and responsibilities in connection with DLP policies are defined together. Final approval and governance remain with the customer.
Do new DLP policies take effect immediately?
No. New policies are first introduced in simulation mode: actions are logged but not enforced. Blocking measures are only activated after evaluation and fine-tuning.
Does DLP also protect on private devices (BYOD)?
Enforcement on private or unmanaged devices depends on the Microsoft security mechanisms in use and on device management. The scope of protection may be limited compared with fully managed corporate devices.
Does DLP help against sensitive data being pasted into ChatGPT and similar tools?
Microsoft continuously develops protection mechanisms for AI applications, including within Microsoft Purview DSPM and DSPM for AI. Preview capabilities are only used with the corresponding Microsoft notice and may be limited in terms of availability and functionality.
Is Data Loss Prevention also worthwhile for smaller companies?
Yes. The service is aimed primarily at small and medium-sized companies that use Microsoft 365 productively. What matters is the actual risk of uncontrolled sharing, not company size.
Which licenses do we need for Data Loss Prevention?
Microsoft Purview DLP capabilities are available depending on the respective Microsoft 365 licensing model. Advanced capabilities such as Endpoint DLP, advanced compliance evaluations, or Premium eDiscovery may require additional licenses, Microsoft 365 E5, or add-on licenses. The specific evaluation is carried out based on your existing environment before the project starts (as of July 2026).
How well is your sensitive data protected against accidental disclosure?
In a free initial consultation, we clarify whether a targeted DLP configuration, a simulation phase, or a structured evaluation of your current sharing is the right next step.

You speak directly with Sebastian Kerssen – working in the Microsoft ecosystem since 2014, as a direct Microsoft partner with no intermediaries.