Knowledge Base
Engineer Login
Back to Knowledge Base

Data Loss Prevention (DLP) Basics

Security & antivirus DLP data loss prevention compliance sensitive data By Cade · Updated 03/05/26 07:41 AM
Data Loss Prevention (DLP) policies detect and prevent sensitive data (credit card numbers, Social Security numbers, health records) from being shared inappropriately — emailed to personal accounts, copied to USB drives, or uploaded to unauthorized cloud services. In Microsoft 365 Purview, DLP policies are configured under Policies > Data loss prevention. Create a policy targeting sensitive information types (Microsoft has hundreds of built-in types like Credit Card Numbers, US SSN, HIPAA data). Choose what to detect (email, Teams messages, SharePoint, OneDrive, endpoints) and what action to take (notify the user, block sharing, require justification, alert IT). Start in 'audit mode' to see what DLP would catch before enforcing — this avoids disrupting legitimate business processes. Review the DLP reports to understand where sensitive data flows in your organization. Common false positive sources: test data in spreadsheets that looks like SSNs, template documents with placeholder credit card numbers. Refine policies to exclude known-good locations or add exceptions for specific users. DLP is complementary to other security controls, not a replacement.