FREE STUDY NOTES · SC-401

Endpoint DLP device requirements and onboarding in Microsoft Purview

Which Windows, Windows Server and macOS devices Endpoint DLP supports, the prerequisites, and how to onboard devices to Microsoft Purview.

From Ultra Transcenders SC-401 by Tony Rough (coming December 2026)

Endpoint DLP works only on devices that have been onboarded to Microsoft Purview, and onboarding is shared with Microsoft Defender for Endpoint. Knowing the supported platforms and what each one needs is the first design decision.

Platform Support and notes
Windows 10 and Windows 11 (x64) Supported; the Endpoint DLP overview names Windows 10 1809 and later and Windows 11
Windows 11 (ARM64) Supported for most activities
Windows Server 2019 and later (x64) Supported, but Endpoint DLP is off by default for servers; turn on Endpoint DLP support for onboarded servers in Endpoint settings. Not supported on domain controllers or Server Core
macOS The three latest released major versions, x64 and Apple silicon (M1, M2, M3); onboarded through Intune, JAMF Pro or another MDM

Common trap: Treating Endpoint DLP as Windows-only - it also supports the three latest macOS versions and Windows Server 2019 and later, although some settings (VPN settings, RDP and access by apps outside the restricted lists, for example) are Windows-only.

Windows prerequisites

Onboarding

  1. In the Microsoft Purview portal go to Settings > Device onboarding > Devices and select Turn on device onboarding (usually about 60 seconds; allow up to 30 minutes).
  2. Choose Onboarding, pick a deployment method and download the package.
  3. Deploy it with the chosen method.
Deployment method Typical use
Local script Testing; up to 10 machines
Group Policy Domain-joined Windows devices
Configuration Manager Devices managed by Configuration Manager
Mobile Device Management / Microsoft Intune Cloud-managed devices (and macOS packages)
VDI onboarding scripts Non-persistent virtual desktops

Common trap: Re-onboarding devices that Defender for Endpoint already manages - onboarding is shared, so those devices already appear in Purview; just turn on device monitoring.

Common trap: Assigning a Purview role group so a helpdesk lead can onboard devices - device management supports only Microsoft Entra roles (Compliance admin, Security admin or Global admin); Purview role groups don’t grant it.

Why policies reach every device

Because endpoint policies are scoped to users and a device can have several users, every onboarded device receives all Endpoint DLP policies. Policy updates generally take about an hour to synchronise (authorisation group changes take 24 hours). An offline Windows device keeps enforcing the policies it already has, but new or changed policies arrive only when it reconnects, and enforcement events appear in Activity explorer after it comes back online. Figure 8.1 shows the whole path from turning on onboarding to events in Activity explorer.

Three onboarding steps in the Microsoft Purview portal (turn on device onboarding, choose a method and download the package, deploy it by local script, Group Policy, Configuration Manager, Intune or another MDM, or VDI scripts) lead to the onboarded device list. Devices already onboarded to Defender for Endpoint appear there automatically. Every onboarded device then receives all Endpoint DLP policies, and its enforcement events show in Activity explorer.
Figure 8.1: Onboarding devices for Endpoint DLP

Get the whole book

This note is one section of Ultra Transcenders SC-401: Administering Information Security in Microsoft 365, an independent study guide that explains every topic the exam covers by technology, with comparison tables, diagrams and the common traps, plus a glossary linked to Microsoft Learn.

Amazon.co.ukKindle: coming soonPaperback: coming soon
Amazon.comKindle: coming soonPaperback: coming soon

Due on Amazon in December 2026, in Kindle and paperback editions.

About the book · SC-401 terms in the glossary · All SC-401 study notes

More SC-401 study notes