lightupdifire I spent a few weeks looking at this. From what we found, there is no 1:1 drop-in replacement, and certainly nothing free. To get a reasonably similar experience, it seems you need this:
1. Get Microsoft 365 E5 Information Protection and Governance licenses to enable Endpoint Data Loss Prevention.
2. Configure DLP policies to protect actions and data types on your endpoints. Unfortunately, I couldn't find a template for "all work stuff", so I had to cludge one together. Make sure these policies are scoped to devices as well as cloud locations AND they include user actions such as copy/paste, file copy, etc.
3. Ensure all PCs are onboarded to M365 Defender and have synced the Endpoint DLP policies. (this took almost 5 days the first time around)
4. Educate users that certain behavior is now different.
I found it to be VERY complex. Maybe suitable for enterprises with dedicated compliance and privacy teams, but not really for smaller orgs.
Not happy with it tbh, so we disabled it again.