Forum Discussion

lannamal's avatar
lannamal
Copper Contributor
Dec 11, 2025

Test DLP Policy: On-Prem

We have DLP policies based on SIT and it is working well for various locations such as Sharepoint, Exchange and Endpoint devices. But the DLP policy for On-Prem Nas shares is not matching when used with Microsoft Information Protection Scanner. 

 

DLP Rule:

Conditions

Content contains any of these sensitive info types:

Credit Card Number

U.S. Bank Account Number

U.S. Driver's License Number

U.S. Individual Taxpayer Identification Number (ITIN)

U.S. Social Security Number (SSN)

 

 

The policy is visible to the Scanner and it is being logged as being executed 

MSIP.Lib    MSIP.Scanner (30548)    Executing policy: Data Discovery On-Prem, policyId: 85........................

 

and the MIP reports are listing files with these SITs

The results 

 Information Type Name - Credit Card Number

                                          U.S. Social Security Number (SSN) 
                                          U.S. Bank Account Number

 Action - Classified

 Dlp Mode -- Test

 Dlp Status  -- Skipped

 Dlp Comment -- No match

 

There is no other information in logs. Why is the DLP policy not matching and how can I test the policy ? 

thanks

1 Reply

  • Hello lannamal,

    Looking at the logs, looks like the DLP policy is configured to run in simulation/test mode. That could be the reason why it is not enforced. Please confirm if "Turn the policy on immediately” is set and try again. 

    Hope this helps!

    Please mark as solution, if you find the answer helpful. This will assist others in the community who encounter a similar issue, enabling them to quickly find the solution and benefit from the guidance provided

Resources