Pinned Posts
Forum Widgets
Latest Discussions
Microsoft Purview | Share block at external users
Hello community. I have an issue with Microsoft Purview DLP policies. I am trying to create a policy that prevents documents from being shared through OneDrive with external users, while allowing certain exceptions. However, when I select the option "Block Access to external domains and users" and assign a specific email address to be blocked, it does not work. The configured email address is not being blocked. I was reviewing this with Copilot, and it mentioned that if the external user you are sharing with already exists in Entra ID, the tenant may treat the user differently (not necessarily as an external user). My external user exists in Entra ID as a Guest account. The external user is registered as follows: Displayname: User Name Userprincipalname: user.name_external.domain#EXT#@company.onmicrosoft.com User Type: Guest Has anyone else experienced this issue? I am sharing evidence of the policy configuration.SNRCAug 19, 2026Copper Contributor78Views0likes4CommentsInsider Risk Level not being correctly picked up by DLP
I have two users currently with assigned Insider Risk levels, one elevated and one minor. I have taken the templated DLP policy (DSPM for AI - Block sensitive info from AI sites) which looks for sensitive information being pasted to generative AI sites, and applies a block if the user is an elevated risk user, and a block with override for a moderate/minor risk user (this was audit only originally). For each advanced DLP rule within that policy, I have a separate policy tip which shows so I know which Advanced DLP rule has been hit. However, I'm having some discrepancies with the correct insider risk level being identified by Purview and therefore the wrong advanced DLP rule is being applied. Testing examples: Logged into a Windows 11 PC with the account, and using Medium confidence UK NINO's I try pasting the content into ChatGPT: Elevated risk user: Block with Override Minor Risk user: Block with Override If I try the exact same scenario on a different PC, I can sometimes get to the point where even though its the same set of data, Purview allows me to paste it at after checking the data. Or in another scenario, I was getting both users hitting the "elevated risk" advanced DLP rule. The Devices are all showing as up to date sync wise with DLP policies, and the policy itself is showing as fully synced. Assigned insider risk levels: DLP Rules: Elevated: Moderate/Minor:Solved59Views0likes2CommentsDeleted labels showing pending deletion status
Hi All, We encountered an issue after deleting a sensitivity label through the Microsoft Purview portal. When we tried to recreate the same label a few hours later, a message indicated that a label with the same name still exists. We also attempted to remove it using PowerShell with the label GUID but received the error: “We cannot remove rule ‘label name’ since it is already in a pending deletion state.” Anyone comes across similar Thank younvisa1090Aug 18, 2026Copper Contributor7Views0likes0CommentsMicrosoft Fabric metadata in Microsoft Purview
I’ve been mapping how Microsoft Fabric metadata is surfaced in Microsoft Purview through Data Map scanning, and I’ve created this visual to make the relationship easier to understand. The diagram separates: Documented mappings – such as Fabric items, Lakehouse tables, schema and item-level lineage. Metadata known to be scanned, but where the exact Purview UI location needs confirmation. ? Areas still needing validation – particularly Lakehouse table/column descriptions and tags. The principle I’m exploring is: Microsoft Fabric → Purview Data Map Scan → Purview Data Asset → Purview governance enrichment Importantly, a Fabric asset does not automatically become a Purview Data Product. It is first represented as a Data Asset, which can then be governed, enriched and associated with a Data Product. I’d really appreciate feedback from anyone working hands-on with Microsoft Fabric and Microsoft Purview: Does this mapping match what you are seeing in your environment? I’m particularly interested in confirming: Lakehouse table descriptions → Purview Asset Description? Lakehouse column descriptions → Purview Schema → Column Description? Lakehouse table/column tags → where exactly are these surfaced in Purview? Corrections, screenshots or practical experience would be very welcome.sashakorniakUKAug 13, 2026Brass Contributor169Views3likes4CommentsPurview DLP Behaviours in SharePoint and OneDrive
We are currently testing Microsoft Purview DLP policies for user awareness across SharePoint Online, and OneDrive. The policy is configured such that sensitive information (based on a sensitivity label-OFFICIAL Sensitive) shared externally triggers a policy tip, with override allowed (justification options enabled) and no blocking action configured. In SharePoint Online and OneDrive, users are not experiencing any DLP-related behaviour. When attempting to share labelled content externally: No policy tips are displayed No override prompts are presented No indication of DLP enforcement is shown Users are able to share content externally without any awareness prompt or restriction. Expected behaviour: Users should receive a policy tip during the sharing process Users should be prompted for justification when overriding, aligned with the DLP configuration Has anyone observed similar behaviour with DLP in SharePoint Online and OneDrive, particularly in scenarios where no blocking action is configured? Keen to understand if this is expected behaviour, a known limitation, or if there are any configuration considerations or workarounds to achieve a consistent user experience across workloads.302Views1like5CommentsPurview Endpoint DLP "Turn on Device onboarding" Query
Hello Microsoft Community, We are planning to enable device onboarding in Microsoft Purview as a prerequisite for deploying Microsoft Purview Endpoint DLP. Our environment uses CrowdStrike Falcon as the primary antivirus/EDR solution. However, we have identified a significant number of Windows 11 devices where Microsoft Defender Antivirus is currently reporting: AMRunningMode : Normal This is occurring even though CrowdStrike is installed and is expected to be the primary antivirus provider. Our understanding is that, when a supported third-party antivirus such as CrowdStrike is correctly registered with Windows Security Center, Microsoft Defender Antivirus should normally operate in Passive mode after the device is onboarded to Microsoft Defender for Endpoint. We are investigating why these devices are showing Normal mode. One suspicion is that there may have been an incomplete or unsuccessful Microsoft Defender for Endpoint deployment in the past, or an issue with CrowdStrike registration, Windows Security Center, Defender policies, or the existing MDE onboarding state. We would like clarification on the impact of enabling Purview device onboarding in this situation. Environment Windows 11 devices CrowdStrike Falcon is intended to be the primary antivirus/EDR Microsoft Purview Endpoint DLP is planned Device onboarding has not yet been broadly enabled through Purview Some devices report Microsoft Defender Antivirus in Passive mode Large number of devices report Microsoft Defender Antivirus in Normal mode We are separately troubleshooting the Normal-mode devices Questions Does enabling Turn on device onboarding in the Microsoft Purview portal make any immediate configuration change to Windows devices, or is it only a tenant-side setting until the onboarding package is deployed? After “Turn on device onboarding” When the Purview onboarding package/script is deployed when the device is in “Normal mode”, does it modify the Microsoft Defender Antivirus operating mode? Is there any risk of performance degradation, duplicate file scanning, application impact, or antivirus conflict on devices where: CrowdStrike is active, and Microsoft Defender Antivirus is also reporting Normal mode? If we enable device onboarding? We are mainly trying to determine whether Purview device onboarding itself introduces any negative impact, as there is a pre-existing condition where both CrowdStrike and Microsoft Defender Antivirus may be operating actively. Thank you.Afsar_ShariffAug 10, 2026Brass Contributor50Views0likes2CommentsPurview DSPM navigation difficulty
Purview DSPM show many stats which are difficult to relate. Even supporting data are often partial. For e.g. Unprotected Asset, Unlabeled Asset, Classified unlabeled. If Unprotected asset is combination of labelled+unlabelled+classified+unclassified all types? While showing count of unprotected asset, why the scope or denominator is not shown. So many categories are pretty confusing and the stats never tally as scope considered, logic considered are often different which is not clearly articulated. I see Sensitivity label coverage is 100% but at the same time it also shows unlabeled sensitive Assets.dsudip1Aug 07, 2026Copper Contributor9Views0likes0CommentsMicrosoft Purview Data Map Sensitivity Labelling
I'm testing the new Microsoft Purview Data Map Sensitivity Labelling capability against Azure SQL and have a question about the relationship between Data Map classifications and Information Protection auto-labelling. My goal is to automatically apply a sensitivity label such as PERSONAL DATA to Data Map assets and columns when PII is detected. Examples of the PII classifications I'm interested in include: All Full Names Email Address Date of Birth Ethnic Group Person Age Person Gender Personal IP Address UK Driving Licence Number UK Electoral Roll Number UK NHS Number UK Passport Number UK UTR National Insurance Number Payment Card Number Other common personal identifiers From my testing, it appears that Data Map classifications and Microsoft Purview Information Protection auto-labelling use different detection engines and different supported rule sets. For example: Data detected Data Map classification Can directly trigger the Data Map Sensitivity Label? Full Name Yes No Date of Birth Yes, or detected through schema and context No Email Address Yes Not available in my tenant's rule picker National Insurance Number Yes Yes UK Passport Number Yes Yes Payment Card Number Yes Yes This suggests that Purview can classify many types of personal data during scanning, but only a subset of those classifications are available as conditions in the Data Map auto-labelling policy. My questions are: Is this the expected behaviour, or am I missing additional configuration? Is there a published mapping between Data Map classifications and the supported Sensitive Information Types (SITs) that can trigger Data Map sensitivity labels? Can custom Sensitive Information Types be used for Data Map auto-labelling, or are only Microsoft prebuilt SITs supported? Is there a roadmap for supporting classifications such as All Full Names, Date of Birth, Email Address, Person Age, Person Gender and similar PII as auto-labelling triggers? How are other organisations implementing a consistent PII handling model when many common personal-data classifications cannot currently trigger a Data Map sensitivity label? At present, my understanding is that the practical approach is: Use supported auto-labelling for eligible identifiers, such as National Insurance numbers and passport numbers. For classifications that cannot trigger a sensitivity label, such as Full Name or Date of Birth, use governance metadata such as custom attributes, glossary terms or Critical Data Elements (CDEs), together with governance policies and access controls. I'd be interested to hear how others are implementing this in enterprise Purview environments and whether there are any recommended patterns from the Microsoft product team.sashakorniakUKAug 06, 2026Brass Contributor97Views0likes4Comments[HELP] "Action required for browser protections" alert
Hello! I have an Endpoint DLP policy with Device location. After several scoping changes (device groups, inclusions/exclusions) to narrow it to a specific target group, the orange alert appeared: Action required for browser protections. One or more policies were not applied in Edge for Business. This could be due to a policy sync issue, lack of required permissions, or an issue with the server. Either resync these policies or contact an admin with the required permissions to resync. After resyncing, you might still see this message for up to 1 day while the system completes the sync and activates protections. The policies were working before. Clicked Resync multiple times, only for the error to return. Please help!DevincitAug 05, 2026Copper Contributor258Views1like4CommentsMicrosoft purview exchange online DLP duplicate events and alerts
Hello Everyone, We have Microsoft purview DLP policy for exchange online, We dont have any other exchange policy apart from this. there are three rules High (51- Any), Medium (10-50), Low( 2-9). Whenever any rule matches there are two events in activity explorer and alerts getting generated. Does anybody has encountered this issue? Kindly provide the feedback. Thank you.Afsar_ShariffAug 05, 2026Brass Contributor56Views0likes1Comment
Tags
- purview158 Topics
- microsoft purview107 Topics
- Information Protection35 Topics
- Sensitivity Labels31 Topics
- data loss prevention20 Topics
- ediscovery18 Topics
- api18 Topics
- Azure Purview17 Topics
- endpoint dlp15 Topics
- Retention Policy14 Topics