Which Windows, Windows Server and macOS devices Endpoint DLP supports, the prerequisites, and how to onboard devices to Microsoft Purview.
From Ultra Transcenders SC-401 by Tony Rough (coming December 2026)
Endpoint DLP works only on devices that have been onboarded to Microsoft Purview, and onboarding is shared with Microsoft Defender for Endpoint. Knowing the supported platforms and what each one needs is the first design decision.
| Platform | Support and notes |
|---|---|
| Windows 10 and Windows 11 (x64) | Supported; the Endpoint DLP overview names Windows 10 1809 and later and Windows 11 |
| Windows 11 (ARM64) | Supported for most activities |
| Windows Server 2019 and later (x64) | Supported, but Endpoint DLP is off by default for servers; turn on Endpoint DLP support for onboarded servers in Endpoint settings. Not supported on domain controllers or Server Core |
| macOS | The three latest released major versions, x64 and Apple silicon (M1, M2, M3); onboarded through Intune, JAMF Pro or another MDM |
Common trap: Treating Endpoint DLP as Windows-only - it also supports the three latest macOS versions and Windows Server 2019 and later, although some settings (VPN settings, RDP and access by apps outside the restricted lists, for example) are Windows-only.
| Deployment method | Typical use |
|---|---|
| Local script | Testing; up to 10 machines |
| Group Policy | Domain-joined Windows devices |
| Configuration Manager | Devices managed by Configuration Manager |
| Mobile Device Management / Microsoft Intune | Cloud-managed devices (and macOS packages) |
| VDI onboarding scripts | Non-persistent virtual desktops |
Common trap: Re-onboarding devices that Defender for Endpoint already manages - onboarding is shared, so those devices already appear in Purview; just turn on device monitoring.
Common trap: Assigning a Purview role group so a helpdesk lead can onboard devices - device management supports only Microsoft Entra roles (Compliance admin, Security admin or Global admin); Purview role groups don’t grant it.
Because endpoint policies are scoped to users and a device can have several users, every onboarded device receives all Endpoint DLP policies. Policy updates generally take about an hour to synchronise (authorisation group changes take 24 hours). An offline Windows device keeps enforcing the policies it already has, but new or changed policies arrive only when it reconnects, and enforcement events appear in Activity explorer after it comes back online. Figure 8.1 shows the whole path from turning on onboarding to events in Activity explorer.
This note is one section of Ultra Transcenders SC-401: Administering Information Security in Microsoft 365, an independent study guide that explains every topic the exam covers by technology, with comparison tables, diagrams and the common traps, plus a glossary linked to Microsoft Learn.
Due on Amazon in December 2026, in Kindle and paperback editions.
About the book · SC-401 terms in the glossary · All SC-401 study notes
How EDM SITs match your own records: schema, primary and supporting elements, new and classic experiences, and hashing and uploading data.
How to design sensitivity labels: the four label scopes, label priority and order, sublabels and label groups, and label limits.
How to roll out a DLP policy safely with simulation mode and policy tips, and the four policy states with their PowerShell Mode values.
Which setting wins when several retention policies and labels apply to one item, with worked examples, and how to use Policy lookup.
Which Insider Risk Management policy template fits each scenario, with its triggering event, prerequisites and user limit.
What Audit (Premium) adds over Audit (Standard): default retention periods, 10-year retention, intelligent insights and the licences each needs.
How to build Microsoft Purview eDiscovery searches with the condition builder and KeyQL, with example queries and the search limits to know.