Understand data protection and governance tasks for Microsoft 365 and Copilot
Data Loss Prevention
ImportantUse DLP to detect sensitive data in context and control risky movement or use without confusing it with classification, lifecycle, or conduct review.
Aligned to the current AB-900 guide, verified July 22, 2026.
Why this matters
AB-900 tests whether you can recognize a risky data-use scenario, apply the correct DLP response, and investigate a match without confusing DLP with classification or retention.
Must Know
- DLP asks whether sensitive information is being used or moved in a way that violates policy.
- A DLP rule combines conditions—such as data type, label, destination, or activity—with responses such as audit, warn, justify, restrict, block, or alert.
- Sensitive information types, labels, and classifiers identify content; DLP decides what happens in a risky context.
- Policy tips guide users at the point of action; alerts and incident details support administrator triage.
- Activity explorer shows broader historical activity, while a DLP alert focuses on a policy match that needs review.
- Deploy and tune DLP proportionately: validate matches and business workflows before broad enforcement.
- DLP controls risky movement or use; retention controls keep/delete lifecycle; Communication Compliance reviews message conduct.
Compare and Distinguish
- Classification vs DLP: identify what the content is vs control what happens in a risky context.
- Sensitivity vs DLP: persistent label/protection vs conditional control of an activity.
- Retention vs DLP: lifecycle keep/delete vs risky movement/use.
- DLP vs Communication Compliance: sensitive-data handling vs message-content conduct/policy review.
- DLP alert vs Activity explorer: a policy match needing triage vs a broader historical activity view.
Scenario examples
- Scenario: A user tries to email payment-card data externally. Think: A DLP rule can detect the data and warn, justify, or block based on policy.
- Scenario: A message contains threatening language but no sensitive identifiers. Think: Communication Compliance, not DLP, is the direct solution.
- Scenario: A seven-year keep requirement exists with no movement restriction. Think: Configure retention, not a DLP deletion block.
- Scenario: A new DLP policy blocks legitimate finance work. Think: Inspect the matched rule and evidence, then tune confidence, count, exceptions, or enforcement instead of disabling all DLP.
Exam traps
- DLP is not a retention schedule, encryption label, or employee-conduct investigation tool.
- A DLP alert is a starting point for investigation, not proof of malicious exfiltration.
- A classifier match alone does not block activity; the DLP rule and enforcement mode determine the response.
- Turning off the policy may hide the symptom while leaving sensitive-data risk unresolved.
Key takeaways
- Content/context condition + risky action + configured response = DLP.
- Simulate, inspect, tune, then enforce.
- Alert for triage; Activity explorer for supporting activity evidence.
How it works
- The service evaluates an in-scope activity against policy rules. Matching conditions select the rule, and the configured action records, warns, restricts, or blocks the activity and may generate an alert.
- Rules can use confidence, instance count, location, sharing context, and exceptions to reduce false positives and avoid blocking ordinary work.
- Triage starts with the matched policy/rule and evidence, then determines whether the event is expected, a false positive, a policy exception, accidental exposure, or a possible incident.
Objects and administrative surfaces
- DLP policies, rules, alerts, incidents, policy tips, simulation, and Activity explorer — Microsoft Purview portal.
- Sensitive information types, trainable classifiers, and sensitivity labels — shared Purview classification capabilities.
- Supported locations and endpoint controls require the corresponding onboarding, licensing, and permissions.
When to use it
- Use DLP when regulated or sensitive data should be audited, warned about, restricted, or blocked during a supported activity.
- Use simulation/audit before enforcement when a new rule could interrupt important business processes.
- Use an adjacent solution when the real question is lifecycle, persistent protection, employee conduct, or a broad user-risk pattern.
Security and governance implications
- Use least-privileged DLP roles, document override reasons, and restrict access to item evidence.
- Tune rules against representative content and business workflows before enforcing a block.
- Balance data protection with user education and proportionate response; a match can be accidental or legitimate.
Troubleshooting signals
- Open the alert or activity, identify the exact policy and rule, inspect classifier evidence, user/action/location, configured action, exception, and policy mode.
- Confirm the workload or device is supported, onboarded, in scope, licensed, and that policy distribution has completed.
- For false positives, adjust the detector, confidence, instance count, context, scope, or exception rather than ignoring all alerts.
More detail
- DLP addresses the question “Is sensitive information being used or moved in a way that violates policy?” It evaluates both content and activity across supported Microsoft 365, endpoint, and other locations.
- A DLP policy contains rules. A rule defines conditions—such as a sensitive information type, label, classifier, recipient, destination, or activity—and the response. Responses can include auditing, policy tips, user justification, restriction/blocking, alerts, and incident reports.
- Policy tips educate users at the point of action and can support justified exceptions when configured. Alerts help administrators triage higher-value matches. Activity explorer and alert details provide evidence such as user, item, rule, location, and action.
- DLP is most effective when deployed gradually: identify the requirement, use simulation or audit where supported, validate matches and business workflows, tune conditions, then enforce proportionately.
- DLP can consume classification signals but does not replace them. A sensitive information type detects data; a DLP rule decides what to do when that data appears in a risky context.
Ready for the quiz?
- How is identifying sensitive data different from enforcing DLP?
- When would a policy tip be preferable to an immediate block?
- Why is a DLP alert different from Activity explorer?
- Which clues point to DLP rather than retention or Communication Compliance?
Related objectives
- D2.1.a — Understand features and capabilities of Microsoft Purview Information Protection, Microsoft Purview Data Loss Prevention (DLP), Microsoft Purview Insider Risk Management, Microsoft Purview Communication Compliance, Microsoft Purview Data Security Posture Management (DSPM) for AI, and Microsoft Purview Data Lifecycle Management
- D2.3.d — Identify and respond to alerts generated by Microsoft Purview DLP
- D2.3.f — Identify user activities reported by Microsoft Purview activity explorer