Policies in Purview that look for sensitivity labels or sensitive information types in content held in many places, including Microsoft 365 Copilot, and respond by auditing, warning or blocking. You can simulate a policy before enforcing it.
Also called DLP, DLP.
Read more: Microsoft Learn
In the Ultra Transcenders books
SC-500SC-900AB-900SC-200DP-600DP-700SC-401
Each book explains Microsoft Purview Data Loss Prevention in context, with comparison tables and the common traps.
Terms in this definition
- Sensitivity labels
Purview's way of classifying, and if needed encrypting, content in Office apps and services. They take over from the classic labels of AIP.
- Microsoft 365 Copilot
Assistant built into Microsoft 365 apps that grounds its answers in an organisation's data via Microsoft Graph. Because it respects existing permissions, content that has been overshared can appear in responses.
- Auditing
Azure SQL capability that sends database audit logs to Log Analytics, Event Hubs or a storage account; that account is allowed to be in a different region.
- Exclusions
Scopes taken out of a policy assignment; they can only narrow its coverage, never widen it.
Related terms
- Activity explorer
A Microsoft Purview view of the last 30 days of events involving sensitive or labelled items, for example a label being added, altered or taken off, or a DLP rule being triggered. Its data comes from the unified audit log.
- Adaptive Protection
A Microsoft Purview capability in which Insider Risk Management rates each person as Minor, Moderate or Elevated risk. DLP, Conditional Access and data lifecycle policies then adjust automatically, so the tightest restrictions fall on the highest-risk people only.
- Alert Triage Agent
A preview Security Copilot agent that sorts DLP alerts for you, weighing the risk each one carries and placing it in groups like Needs attention or Less urgent. Running it uses security compute units.
- Block with override
A DLP action that stops an activity but lets the user choose to go ahead anyway, for instance from a device's pop-up notification. Each override is audited, and the reasons users give help to spot false positives.
- Communication Compliance
Purview insider-risk tool that flags messages in email, Teams or Copilot interactions that may be inappropriate or breach regulations so reviewers can respond; DLP policies sit elsewhere.
- Content scan job
The settings for the information protection scanner, set up in the Purview portal under a scanner cluster, that list which repositories to scan (SharePoint Server libraries or file shares) and which DLP and labelling settings to use.
- Contextual summary
A brief extract showing the words either side of what set off a DLP rule or classifier. Admins can read it in alerts and the explorers, and use it to mark an item as Match or Not a match.
- Copilot security dashboard
Collects Purview signals about Copilot in one Microsoft 365 admin center page (Copilot > Overview > Security), offering shortcuts to set up DLP, deal with oversharing and tighten compliance. Global Readers may view it; an AI Administrator is needed to change anything.
See Microsoft Purview Data Loss Prevention in the full glossary