Data Loss Prevention (DLP): protection that mustn't get in the way
A sensitivity label says what's sensitive. DLP is what happens when someone tries to mishandle it. How to set up protection that guards your data — without stopping everyday work or teaching people how to bypass it.
Last time we said that a sensitivity label gives a document a name — “this is confidential, that is public.” But a name alone stops nobody. A label classifies; only DLP enforces. It’s the layer that steps in the moment someone tries to send the payroll spreadsheet out or upload a contract to a private drive.
And this is exactly where the biggest trap of the whole topic hides. DLP (Data Loss Prevention) can be set so strictly that it blocks ordinary work too — and at that point the very opposite of what you wanted happens: people learn to bypass the protection, send files via private e-mail and WhatsApp, and your data leaks even more than before. Good DLP isn’t the strictest. It’s the one that protects without most people even noticing.
The short version for the impatient
Before we get into detail, here’s the whole topic in five points:
- What it is: a set of rules that watch sensitive content and step in when someone handles it riskily — sends it out, shares it externally, copies it to a USB stick.
- How it recognises sensitive content: either by a sensitivity label (building on the last instalment), or by the content itself — Microsoft can recognise over 300 patterns like national ID numbers, card numbers or IBANs.
- What it can do: from the mildest to the toughest — just record, warn the user (“you’re sending this out, are you sure?”), or block the action outright.
- What you need: basic DLP for SharePoint, OneDrive and e-mail is already in Business Premium and E3. Endpoint and Teams protection is only in E5 (or an add-on).
- The main risk: overly strict DLP deployed all at once. That’s why you always start in a silent mode that blocks nothing — it only shows what it would have blocked.
If that’s enough for you, you have the big picture. For how to build the policies and where the traps are, read on.
What DLP really is
A DLP policy has two parts, and once you understand them you understand all of DLP: the condition (what to watch) and the action (what to do about it).
Condition — how DLP recognises that content is sensitive. It has two routes:
- By sensitivity label. This is where the last instalment plugs straight in. You tell DLP: “anything labelled Confidential must not go out.” The label is the condition, DLP is the enforcement. That’s why labels and DLP are a pair — one without the other is half a solution.
- By the content itself. DLP can look inside a document or e-mail and recognise sensitive patterns. Microsoft ships over 300 ready-made “sensitive information types” — national ID numbers, payment card numbers, IBANs for more than a hundred countries, passport numbers. So you don’t have to label anything up front: DLP spots a card number even when the document carries no label.
In practice both routes combine: the label covers what people deliberately classified, and content detection catches what got forgotten.
Action — what happens when the condition is met. And here’s the whole subtlety of DLP, because the action is a whole scale from invisible to hard:
- Just record — nobody notices anything, the event is only logged for an overview. The starting point of every policy.
- Warn the user (policy tip) — “This e-mail contains a card number, do you really want to send it out?” The user decides for themselves. The most powerful DLP tool that’s talked about least — it educates rather than punishes.
- Require justification — the user can proceed but has to write why. Excellent for borderline cases — you have a record, they aren’t blocked.
- Block — the action doesn’t go through. Reserved for the genuinely sensitive.
Where DLP operates
One of the things companies underestimate about DLP is its reach. It doesn’t operate in just one corner of Microsoft, but across the whole environment:
- SharePoint and OneDrive — watches file sharing, especially external.
- Exchange (e-mail) — the most common point of leakage: a sensitive attachment sent out.
- Teams — messages in chats and channels.
- Endpoints (devices) — copying to USB, printing, uploading to a foreign cloud service, pasting into a browser. Here DLP watches even what happens outside Microsoft.
- Microsoft 365 Copilot — the novelty we’ll come back to shortly: DLP can prevent AI from touching labelled sensitive content at all.
You don’t get all these areas in the basic licence — more on that in a moment.
What you need for it
The licensing split matters more with DLP than with labels, because “where DLP operates” depends directly on what you’ve paid for:
- Microsoft 365 Business Premium and E3 include basic DLP for Exchange, SharePoint and OneDrive. That covers the most common scenario — leakage via e-mail and external sharing — and for most smaller companies it’s a solid start.
- Microsoft 365 E5 (or the E5 Compliance add-on) extends DLP to endpoints (Endpoint) and Teams, adds automatic labelling and integration with foreign cloud apps. Endpoint DLP — that protection against USB and copying — is exactly what separates E3 from E5.
- On top of that, for Business Premium customers Microsoft has offered standalone add-on packs since autumn 2025 (Information Protection & DLP including Endpoint DLP), so even a smaller company can reach advanced protection today without going to E5.
And users without the relevant licence? DLP is enforced at the service level and attaches to content managed by a licensed user — not to whoever accesses it. When a licensed employee owns or shares a document, the policy guards it even when a guest without their own licence works with it. The only difference is where DLP operates: basic protection of e-mail and SharePoint (E3/Business Premium) reaches everyone affected, but Endpoint and Teams DLP activate only for users with E5 — because they’re licensed per individual user.
Everything is set up in the Microsoft Purview portal, the same console as sensitivity labels. It’s no coincidence — Microsoft deliberately builds them as one whole.
How DLP doesn’t block everyday work
Now the most important part, and the reason so many DLP projects end badly. There’s a temptation to switch DLP on “hard” on day one — block everything, get some peace. It’s the fastest road to disaster: within an hour you have blocked legitimate e-mails, angry salespeople and IT buried in tickets. And within a week people are sending sensitive files through private channels DLP can’t reach.
The proven approach goes exactly the opposite way — from invisible to strict:
- Simulation mode. DLP is switched on but blocks nothing — it only quietly logs what it would have blocked. You let it run for weeks against real traffic and see how many hits are genuine risk and how many are false alarms. Never skip this step.
- Policy tips — warnings. Once simulation tells you the policy is sound, you turn on notifications. The user can still do everything, but gets a message on a risky action. Most people stop themselves at that moment — and you’re collecting real data about what the policy does.
- Blocking last, and only where it makes sense. Keep the hard block for the genuinely sensitive and for scenarios where simulation and warnings have proven false alarms are minimal.
Two things hold this approach together: the option to override a block with a justification (in borderline cases a person writes why and proceeds — you have the record, they aren’t blocked) and a pilot with a small group before you release the policy to the whole company. False alarms aren’t a detail — every needless block undermines trust in the whole system.
DLP and AI: the new and most important scenario
Let’s return to Copilot, because here DLP has gained a whole new dimension. Since spring 2026, DLP for Microsoft 365 Copilot is generally available: a rule that says “content with this label must not be used as grounding for AI answers.” Copilot then won’t include a labelled document in an answer — regardless of where it’s stored.
That’s a fundamental shift. Until now the last safeguard against AI pulling out something sensitive was in permissions. DLP for Copilot adds a second: even if the user has the right to a document, DLP can prevent AI from using it. This is exactly where the fifth label from last time finally “activates” — No AI isn’t just a sticker but a rule enforceable through DLP.
As we wrote with labels: every AI solution handles labels its own way. Microsoft 365 Copilot through DLP for Copilot; our EP365 AI Chat today defines what AI will see through permissions and a defined scope of sources (and directly honouring labels is a direction we’re developing it in). What’s common is one rule: before you launch any AI over company data, be clear about what keeps sensitive content out of its reach.
A few policies to start with
Just as with labels, “less is more” applies here too. Don’t start with thirty policies — start with three or four that cover the most common risks:
- Block external sharing for the “Highly Confidential” label. The simplest link to the last instalment: what’s labelled highest must not go out. One policy, a clear rule.
- A warning for national ID and card numbers in outgoing e-mail. Content detection, action just a policy tip. It catches the most common accidental leak without blocking anyone.
- Exclude sensitive content from Copilot. DLP for Copilot on the “Highly Confidential” and “No AI” labels. So AI doesn’t reach where it shouldn’t.
- (optional, with E5) A warning when copying “Confidential” to USB. Endpoint DLP in a mild mode — it alerts people, and you see where data drains out of the company.
Deploy each of them first in simulation, then as a warning, and only then consider a block. Four well-tuned policies protect more than thirty that people bypass.
What to take away
Three sentences to close:
- A label classifies, DLP enforces. One without the other is half a solution — classification without enforcement is just a sticker.
- The best DLP isn’t the strictest, it’s the least noticeable. Simulation, then warnings, block last and only where it makes sense. Excessive strictness teaches people to bypass the protection.
- DLP is the last safeguard for AI too. DLP for Copilot keeps sensitive content out of AI’s reach even where permission alone wouldn’t be enough.
At EP365 we help companies set up DLP so it protects without slowing things down — from policy design through the simulation phase to integration with sensitivity labels and Copilot. We most often handle it as part of a governance design or security audit. If you’re not sure which three policies to start with, drop us a line — we’ll go through it over your specific environment.
In the next instalment we’ll move from protection to the content lifecycle: how to set up retention and archiving so that years of old clutter don’t pile up in SharePoint — and why it matters more than it seems, precisely because of AI.