Forum Discussion

gumilaris2's avatar
gumilaris2
Copper Contributor
Apr 19, 2025

Purview endpoint DLP cant block file upload to web.whatsapp on open in app mode chrome browser MacOS

we are using purview endpoint DLP to block file upload to web.whatsapp.com on browser for MacOS. its working fine on chrome browser when i try dirrectly upload file contain ssn pattern and its blocked by purview but if we upload using open in app mode (pwa) purview cant detect that activity and file is uploaded to web whatsapp susscessfully.

 

 

try to upload senstive file to web.whatsapp.com from chrome browser and its blocked.

 

but when i try to use "open in app" mode (pwa) dlp purview cant detect the sensitive upload to web.whatsapp.com

how to detect and block file uploaded to unwanted url if user using pwa especially on chrome browser? 

try the same scenario on edge, purview able to detect pwa and can intercept the activity but why in chrome its not the same behaviour expected.

3 Replies

  • Hi,

    I think your observation points more towards a limitation of the Chrome PWA context on macOS than an issue with the DLP policy itself.

    The key indicator is that:

    • Uploads to WhatsApp Web are blocked in a regular Chrome tab.
    • The same upload is allowed when Chrome runs WhatsApp in "Open as App" (PWA) mode.
    • The same PWA scenario is intercepted successfully in Microsoft Edge. [Purview en...munity Hub], https://learn.microsoft.com/en-us/purview/dlp-browser-dlp-learn

    My assumption is that Purview Endpoint DLP does not get the same browser/app context from Chrome PWA on macOS that it gets from Edge, where Microsoft has much deeper native integration for DLP and browser protection. https://learn.microsoft.com/en-us/purview/dlp-browser-dlp-learn, https://learn.microsoft.com/en-us/deployedge/microsoft-edge-dlp-purview-configuration

    For customers with strict data exfiltration requirements, I would not rely on Chrome PWA protection alone. A more robust approach would be:

    • Use Microsoft Edge for Business as the corporate browser.
    • Combine Endpoint DLP with Conditional Access and Defender for Cloud Apps.
    • Treat WhatsApp Web as an unsanctioned or high-risk application if appropriate.
    • Validate whether the behavior affects all Chrome PWAs or only WhatsApp Web before making policy decisions.

    Also, before enforcing Edge organization-wide, I would check for business-critical Chrome extensions or application dependencies on macOS. In many environments, the browser change itself is easy, but the surrounding ecosystem needs to be assessed first.

    Would be interested to hear whether Microsoft confirmed this as a known product gap or an unsupported Chrome PWA scenario.

  • sheraz09's avatar
    sheraz09
    Copper Contributor

    Hi, i want to implement file upload block via whatsapp web can you provide me steps how you implement that