The Feature Already in Your Microsoft 365 Plan That Stops Data Leaving by Accident

· by IDE Solutions
Ask a business owner what a data breach looks like and most describe a hacker: a stolen password, a hole in the firewall, someone on the outside getting in. Verizon's 2025 Data Breach Investigations Report tells a different story: the "human element" was involved in roughly 60% of breaches, and a large share of that is not malice at all. It is an invoice sent to the wrong contact, a customer list attached to a personal email by mistake, a spreadsheet of salaries shared with the whole company instead of one manager. No hacker required.
Microsoft's answer to that problem already sits inside most Microsoft 365 subscriptions, under a name few owners have heard: Purview Data Loss Prevention, DLP for short. In plain terms, it is a set of rules that watch email, SharePoint and OneDrive for content that looks sensitive, an IBAN, a national ID number, a file marked "confidential", and step in before it leaves the company, rather than after. Business Premium already includes the basic version. Almost nobody has switched it on.
What DLP actually catches
A DLP policy is a rule with three parts: what to look for, where to look, and what to do when it finds a match. Out of the box, Microsoft ships templates for the categories that come up most in day-to-day business: credit card numbers, IBANs and bank account details, national ID and passport numbers, and health information. You turn on the templates relevant to your business and Purview scans outgoing email and shared files for a match.
The action on a match is configurable. A first offense might just warn the sender with a pop-up ("this email looks like it contains a customer's bank details, are you sure?"), giving them a chance to stop before sending. A repeated pattern, or a more sensitive category, can block the send outright and notify an admin. Nothing gets silently deleted; the point is to interrupt the moment before the mistake leaves the building, which is also the moment almost every real-world leak actually happens.
Where DLP sits in the Microsoft 365 lineup
This is the part most quotes and brochures skip, and it is why the same question keeps coming up in our Microsoft 365 security assessments: which plan actually includes it, and what does the add-on buy on top.
| Plan | DLP coverage | Typical gap |
|---|---|---|
| Business Basic / Standard | None | No policy engine at all; leaks are invisible until a customer complains |
| Business Premium | Basic DLP for Exchange, SharePoint, OneDrive | Included but off by default; most tenants never enable a single policy |
| Purview Suite add-on | Adds Teams chat, endpoint DLP, eDiscovery, adaptive protection | Worth it once you have outgrown the basic templates, not before |
For the large majority of companies under 50 people, the Business Premium tier is enough to close the gap that actually matters: email and file-sharing. The add-on suite earns its cost later, once a company has regulatory reporting obligations or handles data across Teams chat routinely.
Which three categories to turn on first
Microsoft ships dozens of ready-made "sensitive information type" templates, and switching all of them on at once is how most companies end up with the notification fatigue that gets the whole feature disabled within a month. Three cover most of the exposure a small business actually has:
Financial account data. IBANs, bank account numbers, and card numbers. This is the category that appears in almost every invoice fraud case we get called about after the fact: an attacker intercepts an email thread and asks for payment to a "new" account, and DLP flags the outgoing IBAN before a reply confirms it.
National ID and passport numbers. Relevant the moment you handle HR paperwork, onboarding documents, or any government contract that asks for staff identity verification. A single HR spreadsheet emailed to the wrong distribution list is the most common way this leaks.
A custom keyword policy for "Confidential" and "NDA". Not a Microsoft template, this one you build yourself in ten minutes: flag any document or email whose text contains "Confidential", "Vertraulich", or the name of an active NDA. It catches the contracts and term sheets that generic templates were never built to recognize.
What this costs in practice
There is no license fee here if you already run Business Premium: the DLP engine is included, not billed separately. The real cost is setup time and the ongoing few minutes a week to read the report. In the tenants we manage, the initial rollout, choosing templates, running the audit window, and tuning the false positives, runs three to six hours of admin work depending on how messy the existing file structure is. After that, reviewing the weekly summary takes ten to fifteen minutes for a company under 30 people. Weighed against even one incident, a wrong-recipient email containing customer bank details, that is a small amount of time for the kind of mistake that otherwise triggers a breach notification obligation and an uncomfortable client phone call.
Quick answers
Does Purview DLP replace antivirus or a firewall?
No. DLP only looks at content leaving through email, SharePoint, and OneDrive. It does nothing against malware, phishing links, or network intrusion; those are covered separately by Defender and your cloud security setup. Think of DLP as a rule for outgoing content, not a perimeter defense.
Will employees notice it running?
Only when a policy actually matches something. In audit mode, nothing is visible to the sender at all. In warn mode, a pop-up appears only on a match, asking the sender to confirm or cancel. It is not a background monitoring tool employees interact with day to day; for the large majority of emails sent, it does nothing at all.
Setting up Purview DLP for a small business, realistically
The Microsoft admin center presents dozens of options, which is where most owners give up and leave it switched off. In practice, a working setup for a small business takes a few hours, not weeks, and follows a short sequence:
Start with one or two templates that match your actual risk, usually financial data and any category tied to a regulator you answer to (health data, for a clinic; card data, for a retailer). Run it in "audit only" mode for two to three weeks first: no blocking, just logging what would have triggered. This step matters more than it looks; without it, the first thing most companies discover is dozens of daily false positives on their own invoice template, which gets everyone switching the feature straight back off. Adjust the policy against the log, then move it to warn or block. Finally, name one person, not necessarily IT, who reviews the weekly DLP report; a policy nobody reads is a policy that quietly rots.
Companies working through wider compliance and governance requirements, an ISO 27001 questionnaire, a NIS2 supply-chain letter, will recognize this step; it is usually one of the concrete controls being asked for, phrased differently.
What it will not do
DLP is not a firewall and it is not antivirus, and treating it as a complete data protection plan is the most common mistake we see. It does not stop someone taking a photo of a screen with their phone, does not cover data once it is legitimately downloaded onto a laptop (that is a device policy, closer to what we cover in our piece on managing company devices with Intune), and does nothing for data an employee had every right to access in the first place. It also will not catch anything outside the templates you turned on: an untemplated data category, a language it was not tuned for, a format it does not parse, all pass straight through.
Pair it with the basics already covered in our guide to Microsoft 365 security hardening and, for anyone with staff working outside the office, the checklist in our remote workforce security guide. DLP closes one specific, common gap. It is not the whole picture.
Is it worth switching on
For a company already paying for Business Premium, yes, close to unconditionally: the feature is licensed and unused, and the setup cost is a few hours once, not an ongoing subscription. The honest caveat is time, not money. Someone has to pick the right templates, sit through the audit period, and read the weekly report, or the policy drifts into either noise (too many false alarms, gets disabled) or blindness (nothing tuned, nothing caught). That ongoing attention is the part a one-off setup guide cannot replace, and it is the part most in-house IT teams do not have spare hours for once the initial configuration is done.
We set up and tune Purview DLP as part of a full tenant review
Our Microsoft 365 security assessment includes turning on the right DLP templates for your business, running the audit period, and handing you a plain-language report of what it caught, not a wall of admin center screenshots.
We also take on the part that gets skipped after launch: reviewing alerts, adjusting policies as your business changes, and keeping the whole thing tuned instead of quietly disabled six months from now.