Forum Discussion

Mzwa's avatar
Mzwa
Copper Contributor
Sep 23, 2026

DLP Controls Not Enforced for Outlook Attachments Opened in Protected View

 

Good day,

We are experiencing an inconsistency with Microsoft Purview Endpoint DLP enforcement and would appreciate guidance from the community.

Environment

  • Sensitivity labels: Confidential and Secret
  • DLP policy configured to block copy and print activities
  • Policy scope includes both Devices and Exchange Online

Observed Behaviour

When a labeled document is received via Outlook and opened directly from the email:

  1. The document initially opens in Protected View.
  2. If the user selects "Enable Editing" and/or "Enable Printing", the DLP controls are not enforced.
  3. The user is able to print or copy content despite the DLP policy being configured to block these actions.

However, if the exact same document is first saved locally to the device and then opened from the local file system, the DLP policy is enforced correctly and the copy/print restrictions work as expected.

Troubleshooting Performed

As part of troubleshooting, we disabled the recommended Endpoint DLP file path exclusions for:

  • %AppData%
  • %LocalAppData%

These locations are commonly used by Office Protected View and Outlook temporary files. Despite removing these exclusions, the behaviour remains unchanged.

Question

Has anyone encountered a similar issue where Endpoint DLP controls are not applied to Outlook attachments opened directly from Protected View but work correctly once the file is saved locally?

Could this be related to:

  • How Office Protected View handles temporary files?
  • The file's classification state while opened from Outlook?
  • Endpoint DLP monitoring limitations for transient Outlook/Office cache locations?
  • Another known product limitation or configuration requirement?

Any insights, known limitations, or recommended diagnostic steps would be greatly appreciated.

Thank you.

No RepliesBe the first to reply