Forum Discussion
Purview endpoint DLP cant block file upload to web.whatsapp on open in app mode chrome browser MacOS
we are using purview endpoint DLP to block file upload to web.whatsapp.com on browser for MacOS. its working fine on chrome browser when i try dirrectly upload file contain ssn pattern and its blocked by purview but if we upload using open in app mode (pwa) purview cant detect that activity and file is uploaded to web whatsapp susscessfully.
try to upload senstive file to web.whatsapp.com from chrome browser and its blocked.
but when i try to use "open in app" mode (pwa) dlp purview cant detect the sensitive upload to web.whatsapp.com
how to detect and block file uploaded to unwanted url if user using pwa especially on chrome browser?
try the same scenario on edge, purview able to detect pwa and can intercept the activity but why in chrome its not the same behaviour expected.
3 Replies
- Henric_WeitekampCopper Contributor
Hi,
I think your observation points more towards a limitation of the Chrome PWA context on macOS than an issue with the DLP policy itself.
The key indicator is that:
- Uploads to WhatsApp Web are blocked in a regular Chrome tab.
- The same upload is allowed when Chrome runs WhatsApp in "Open as App" (PWA) mode.
- The same PWA scenario is intercepted successfully in Microsoft Edge. [Purview en...munity Hub], https://learn.microsoft.com/en-us/purview/dlp-browser-dlp-learn
My assumption is that Purview Endpoint DLP does not get the same browser/app context from Chrome PWA on macOS that it gets from Edge, where Microsoft has much deeper native integration for DLP and browser protection. https://learn.microsoft.com/en-us/purview/dlp-browser-dlp-learn, https://learn.microsoft.com/en-us/deployedge/microsoft-edge-dlp-purview-configuration
For customers with strict data exfiltration requirements, I would not rely on Chrome PWA protection alone. A more robust approach would be:
- Use Microsoft Edge for Business as the corporate browser.
- Combine Endpoint DLP with Conditional Access and Defender for Cloud Apps.
- Treat WhatsApp Web as an unsanctioned or high-risk application if appropriate.
- Validate whether the behavior affects all Chrome PWAs or only WhatsApp Web before making policy decisions.
Also, before enforcing Edge organization-wide, I would check for business-critical Chrome extensions or application dependencies on macOS. In many environments, the browser change itself is easy, but the surrounding ecosystem needs to be assessed first.
Would be interested to hear whether Microsoft confirmed this as a known product gap or an unsupported Chrome PWA scenario.
- sheraz09Copper Contributor
Hi, i want to implement file upload block via whatsapp web can you provide me steps how you implement that
- milgo
Microsoft
Hello and thanks for reaching out.
Ideally it should apply to the macOs(the three latest versions) as described here Learn about data loss prevention | Microsoft Learn
Allow me to double check and revert on the status here.