Microsoft's Data-Leak Protection Now Reaches Salesforce and Dropbox, If Your Plan Covers It

Microsoft's Data-Leak Protection Now Reaches Salesforce and Dropbox, If Your Plan Covers It

· by IDE Solutions

Short answer: Microsoft Purview Data Loss Prevention now reaches beyond Microsoft 365 into Salesforce, Google Workspace, Box, Dropbox, ServiceNow, AWS and Cisco Webex, reaching general availability in September 2026. It works through Microsoft Defender for Cloud Apps connectors and needs Enterprise-tier Purview licensing plus a Defender for Cloud Apps license, which most Microsoft 365 Business plans do not include. If your company runs on Business Basic, Standard or Premium, this feature exists but your current plan almost certainly cannot turn it on.

Most business owners picture their company's sensitive data as whatever sits inside Microsoft 365: the SharePoint library, the shared mailbox, the Teams channel where the finance team drops spreadsheets. That picture stopped being accurate a while ago. Customer records live in Salesforce. Contracts get shared through Dropbox because a client insists on it. Support tickets sit in ServiceNow. None of that was ever migrated into Microsoft 365, so none of it was ever covered by the data protection tools built for Microsoft 365.

Microsoft has now closed part of that gap. Its data loss prevention engine, previously limited to Exchange, SharePoint, OneDrive and Teams, can now watch a set of non-Microsoft apps for the same thing: a customer list about to be emailed to a personal address, a contract shared outside the company, a spreadsheet full of card numbers uploaded somewhere it should not be. The catch is who actually gets to use it.

Quick answers

What apps does this cover? Google Workspace, Box, Dropbox, Salesforce, ServiceNow, Amazon Web Services and Cisco Webex, connected through Microsoft Defender for Cloud Apps.

Do I already have this in my Microsoft 365 plan? Almost certainly not. It needs Enterprise-tier Purview licensing and a separate Defender for Cloud Apps license, neither of which comes with Business Basic, Standard or Premium.

Is this the same as Microsoft 365 backup? No. Backup restores data after it is lost or encrypted. This stops sensitive data from leaving the company in the first place.

Should a small business buy the license just for this? Rarely on its own. It usually makes sense as part of a wider security upgrade, not a standalone purchase.

What Microsoft actually changed

Support for non-Microsoft applications in Purview DLP and auto-labeling entered preview in July 2026 and reached general availability this month, according to Microsoft's own documentation. Administrators build a policy the same way they would for SharePoint or OneDrive: pick the sensitive information types to look for (card numbers, national ID numbers, a custom pattern for a client contract number), pick an action (block, warn the user, or just log it), and point the policy at one or more of the connected apps instead of a Microsoft 365 location.

The connection itself runs through Defender for Cloud Apps, which is Microsoft's separate tool for watching what happens inside third-party cloud services. Purview borrows that connector rather than building its own, which is efficient for Microsoft and mostly invisible to the end user, but it means the feature quietly depends on a second product with its own license.

Auto-labeling moved with it. That is the part of Purview that stamps a file "Confidential" or "Internal only" automatically based on its content, rather than waiting for a person to set the label by hand. Before this update, a spreadsheet full of customer data uploaded to Box carried no label at all once it left Microsoft 365, because the labeling engine had nothing to inspect it. Now the same classification rules that tag a sensitive file in SharePoint can tag the equivalent file sitting in a connected non-Microsoft app, which matters for any company that has to prove, after the fact, that sensitive files were identified and handled correctly.

Why this matters even if you never touch Salesforce

The relevant number is not which specific apps made the list. It is how many apps a typical company already runs. Small businesses use somewhere between 25 and 55 separate SaaS applications on average, according to SaaS management data from Zylo, and that count keeps climbing as teams sign up for tools directly instead of asking IT first. Every one of those apps is a place company data can sit, and until now, exactly zero of them were covered by the same protection as an Outlook mailbox.

This is the same problem a security assessment usually surfaces in the first meeting: the owner assumes protection follows the data, when in practice it only follows the platform IT originally set up. A customer database in Salesforce, a client folder in Dropbox and a support queue in ServiceNow can each leak in exactly the way a SharePoint file can, just without anyone watching for it.

It is worth being precise about what "leak" means here, because it is rarely a hacker. In the tenants we manage, the far more common event is an employee attaching the wrong export to an email, sharing a Dropbox link with "anyone with the link" instead of a named client, or a departing staff member downloading a customer list on their last day because nobody had set a rule to stop it. None of those require an attacker. They require a gap between where data sits and where anyone is watching, which is exactly the gap this update narrows, for the businesses that can license it.

What it costs to actually turn on

Plan tier DLP inside Microsoft 365 DLP for Salesforce, Dropbox, etc.
Business Basic / StandardNot includedNot available
Business PremiumBasic DLP includedNot available
E3 + Purview add-onFull DLPNot available on its own
E5 / Purview Enterprise + Defender for Cloud AppsFull DLPAvailable

The step that trips most small businesses up is not the Purview licensing itself, it is Defender for Cloud Apps sitting next to it as a second, separate line item. Two licenses, two consoles, one policy. Budget for both or the feature simply will not connect to anything.

Do you need this, or is Business Premium's version enough?

For most companies with under fifty staff, the honest answer is that plain Purview DLP inside Microsoft 365 Business Premium already covers the highest-risk path: email and file sharing inside Microsoft's own apps, which is where the large majority of accidental leaks still happen. The extension to Salesforce and friends earns its keep once a company has genuinely sensitive data living in one of those specific apps and a compliance reason to prove it is protected, a client contract clause, an insurance requirement, or a framework like ISO 27001 or NIS2 that names data protection outside the core platform explicitly.

If none of that applies yet, the better first move is usually confirming Business Premium's built-in DLP is actually switched on and configured, not upgrading toward a feature aimed at larger environments. We see the reverse mistake regularly: a client pays for capability sitting unused because the free-with-your-plan version was never turned on in the first place. A short assessment answers that question in a day, well before anyone signs up for a second license.

If you already run Defender for Cloud Apps, read this before enabling it

Companies that already own Defender for Cloud Apps, usually because it came bundled with an E5 tenant, often have older file policies pointed at the same apps: a rule in Defender for Cloud Apps watching Dropbox for shared links, say, alongside a brand-new Purview policy watching the same folder for card numbers. Microsoft's own guidance is to turn off or delete the old Defender for Cloud Apps file policy for a location before switching on the matching Purview policy, because running both at once on the same app can produce duplicate or conflicting enforcement, one rule blocking a file the other rule already allowed.

This is a five-minute check for whoever manages your tenant, but it is the kind of five minutes that gets skipped when a feature launches with a press cycle and everyone wants to flip it on the same afternoon. Worth confirming before rollout, not after a user reports a file that mysteriously will not upload.

A short checklist for this week

Whether or not this specific feature applies to your business, the announcement is a reasonable prompt to check four things:

List where sensitive data actually lives. Not where IT set it up to live, where staff actually put it. Ask the finance and sales teams directly; the answer usually includes at least one app nobody officially sanctioned.

Check what your current Microsoft 365 plan includes. Business Premium ships with usable DLP for Exchange, SharePoint, OneDrive and Teams. Confirm it is switched on, not just licensed.

Decide if any app outside Microsoft 365 holds regulated or contractually sensitive data. If one does, that is the specific case where the Enterprise-tier upgrade is worth pricing out, not a blanket move to E5 for everyone.

Ask your IT provider, not a vendor, to confirm the answer. A licensing upsell and an honest gap analysis look similar from the outside. The difference is whether the recommendation changes based on what your business actually needs.

Know what your current license actually protects

We audit which Microsoft 365 and Purview features your business is licensed for versus what is actually configured and working, then tell you plainly whether the gap is worth closing with a licensing change or a policy change. No pressure to buy the top tier if the plan you already pay for hasn't been switched on properly.

More Articles