Data Loss Prevention (DLP) in Microsoft 365 is a set of policies that detect and prevent sensitive information — credit card numbers, National Insurance numbers, passport details, medical records — from being shared outside your organisation inappropriately. It's a key component of GDPR compliance and often required for ISO 27001 certification.
DLP policies scan content in Exchange, SharePoint, OneDrive, Teams, and endpoints (if you have Defender for Endpoint). When it finds content that matches a sensitive information type — like a 16-digit number that looks like a credit card — it can:
Basic DLP (Exchange and SharePoint) is available from Business Premium and E3. More advanced DLP including endpoint DLP and Teams requires E5 Compliance or the Microsoft 365 E5 licence.
Start in test mode. Going straight to blocking can disrupt legitimate business workflows. Running in test mode first lets you see false positives and refine the policy before it affects users.
Microsoft 365 includes pre-built detectors for:
M365Clarity scans your DLP policy status as part of every tenant scan. If no DLP policies are configured it flags this as red — particularly important if your licence includes DLP and you haven't yet set it up.
Connect your tenant, run a scan, and see exactly what needs attention — in plain English. Free plan available.
Scan your tenant free →Related articles