When Windows or macOS computers are onboarded, Microsoft Purview data loss prevention can watch them too, logging or blocking risky moves like printing a sensitive document, saving it to removable USB storage or sending it to a website that has not been approved.
Also called Endpoint data loss prevention.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Endpoint DLP in context, with comparison tables and the common traps.
Terms in this definition
- Microsoft Purview Data Loss Prevention
Policies in Purview that look for sensitivity labels or sensitive information types in content held in many places, including Microsoft 365 Copilot, and respond by auditing, warning or blocking. You can simulate a policy before enforcing it.
- LIKE
Compares strings with a pattern that can contain the % and _ wildcards. Because it only understands character patterns, searching big volumes of text this way is much slower than using full-text search.
- USB
Universal Serial Bus, for connecting peripherals. A BitLocker startup key can live on a USB stick, and although Storage Spaces will take USB drives, using them is not advised.
- General-purpose v1
The older storage account kind (
Storage), which lacks access tiers, Archive and premium file shares and retires on 13 October 2026. Converting to ZRS requires first upgrading to GPv2, a one-way change.
Related terms
- A5
The highest Microsoft 365 plan for education, equivalent to E5 for schools and universities. It includes premium Purview and Defender capabilities, for example Endpoint DLP, Audit (Premium), Insider Risk Management and the premium eDiscovery features.
- Advanced classification scanning and protection
An Endpoint DLP option in which content from devices is classified by a cloud service, letting device policies use trainable classifiers, exact data match, named entities and credential classifiers. Admins can cap the bandwidth it uses.
- Advanced label-based protection for all files on devices
An Endpoint DLP option for onboarded Windows computers. Users can go on working with labelled files that are not Office or PDF files while the extension stays the same; the label's print, view and extract rights are enforced on the device, and the file is encrypted once it is moved off it.
- Auto-quarantine
When a restricted app such as a cloud sync client touches a sensitive file, this Endpoint DLP action relocates the file to a quarantine folder the admin picks, optionally leaving a .txt placeholder behind. That stops the app repeatedly retrying.
- Device onboarding
Brings Windows and macOS computers under Endpoint DLP and Insider Risk Management once device monitoring is switched on in Purview's settings. Computers already in Defender for Endpoint show up there with no extra work.
- Information Protection Admins
A role group in Microsoft Purview whose members create, change and remove DLP policies, sensitivity labels, label policies and every kind of classifier. They also look after endpoint DLP settings.
- Jamf Pro
An Apple device management product from a third party. It offers another route, besides Intune or a different MDM, for onboarding Macs to Endpoint DLP and Insider Risk Management in Purview.
- Just-in-time protection
An Endpoint DLP capability that holds back, or audits, attempts to move files out of a device when the file has never been classified or its classification is out of date, until the policy check finishes. If that check fails, a fallback action applies.