Understand data protection and governance tasks for Microsoft 365 and Copilot
Data Loss Prevention
Use DLP policies to detect sensitive content and govern risky activities across supported locations.
What you need to know
- DLP rules combine conditions, actions, notifications, overrides, and incident reporting.
- DLP can audit, warn, restrict, or block supported activities depending on policy configuration and location.
- DLP alerts show policy matches that require administrative investigation and response.
Objects and administrative surfaces
- DLP policies, alerts, and Activity explorer — Microsoft Purview portal.
- Sensitive information types, sensitivity labels, and trainable classifiers can serve as DLP conditions.
How it works
- A rule evaluates content and context; matching activity triggers the configured action and may create an alert.
- Policy tips educate users at the point of action; administrator alerts support triage.
When to use it
- Use DLP to prevent or monitor sharing a file with regulated identifiers outside the organization.
- Use audit or simulation modes to validate impact before blocking users.
Security and governance implications
- Scope policies and investigation permissions carefully, and document justified overrides.
- Tune false positives using the appropriate classifier, confidence, count, and context.
Troubleshooting signals
- Inspect the matched rule, location, classifier evidence, action, and user activity.
- Confirm the policy is enabled, in scope, and has completed distribution.
Exam traps
- DLP controls risky data activity; it is not a workplace-conduct review tool.
- A DLP alert is evidence to investigate, not proof of malicious intent.
Key takeaways
- Sensitive data + risky activity → DLP.
- Use alerts for triage and Activity explorer for supporting activity evidence.
Related objectives
- D2.1.a
- D2.3.d
- D2.3.f