How to roll out a DLP policy safely with simulation mode and policy tips, and the four policy states with their PowerShell Mode values.
From Ultra Transcenders SC-401 by Tony Rough (coming December 2026)
DLP is rolled out along three axes, state, scope and actions, moving from the least to the most disruptive. Simulation mode is what makes this possible. Figure 7.2 shows the states in rollout order.
| Policy state (portal) | PowerShell Mode value | Effect |
|---|---|---|
| Keep it off | Disable | Inactive; use while designing and reviewing |
| Run the policy in simulation mode | TestWithoutNotifications | No actions enforced, events audited, simulation dashboard populated |
| Run the policy in simulation mode and show policy tips | TestWithNotifications | No actions enforced, but users get policy tips and notification emails |
| Turn it on right away | Enable | Full enforcement (takes effect in about an hour) |
For actions, start with Allow (Devices only) or Audit only, then Block with override, then Block. Overrides during pilots generate justifications that reveal false positives.
Common trap: Assuming a policy created with New-DlpCompliancePolicy starts in test mode like a carefully staged portal policy - the Mode parameter defaults to Enable; set -Mode TestWithoutNotifications or TestWithNotifications explicitly to simulate first.
This note is one section of Ultra Transcenders SC-401: Administering Information Security in Microsoft 365, an independent study guide that explains every topic the exam covers by technology, with comparison tables, diagrams and the common traps, plus a glossary linked to Microsoft Learn.
Due on Amazon in December 2026, in Kindle and paperback editions.
About the book · SC-401 terms in the glossary · All SC-401 study notes
How EDM SITs match your own records: schema, primary and supporting elements, new and classic experiences, and hashing and uploading data.
How to design sensitivity labels: the four label scopes, label priority and order, sublabels and label groups, and label limits.
Which Windows, Windows Server and macOS devices Endpoint DLP supports, the prerequisites, and how to onboard devices to Microsoft Purview.
Which setting wins when several retention policies and labels apply to one item, with worked examples, and how to use Policy lookup.
Which Insider Risk Management policy template fits each scenario, with its triggering event, prerequisites and user limit.
What Audit (Premium) adds over Audit (Standard): default retention periods, 10-year retention, intelligent insights and the licences each needs.
How to build Microsoft Purview eDiscovery searches with the condition builder and KeyQL, with example queries and the search limits to know.