Microsoft 365 DLP configuration — set policies, labels and actions
Microsoft 365 DLP configuration means using Microsoft Purview to define detection rules, sensitivity labels and actions so sensitive data is monitored or blocked; align policies with the Data Protection Act 2018 and keep audit logs for ICO breach reporting within 72 hours.
What to define first: scope, discovery and classification
Start by deciding what you need to protect. For most UK small and medium firms that will be customer personal data, financial records and any HR files. Use Microsoft Purview’s built‑in sensitive-information types and map them to your organisation’s labels. Define a clear scope by grouping users and services (e.g. Exchange Online, SharePoint, OneDrive) so policies don’t run everywhere at once.
Practical steps to scope and discover:
- Inventory locations: list mailboxes, SharePoint sites and Teams channels that hold regulated data.
- Run discovery scans in a test tenant or limited production segment to see false positives.
- Apply sensitivity labels to known repositories so DLP rules can reference them.
Why this matters: broad, untargeted policies commonly generate too many alerts and user friction. Start narrow, prove detection on a handful of sites, then expand. For many organisations that means protecting 3–5 high‑risk repositories first, then iterating based on real alerts.
Policy design: conditions, actions and exceptions
Your policy design is the engine of DLP. Each policy should state a readable business rule (for example, “don’t allow staff to email client payment details externally”) and then map that to technical conditions in Purview: sensitive info types, keywords, file extensions and labelled content. Pick actions that match risk — alert only, restrict sharing, or block and notify.
Key design choices to get right:
- Conditions: combine sensitive information type detection with location, user group and device signals.
- Actions: use a graduated approach — start with monitoring and user notifications, then move to blocking for repeat or high‑risk breaches.
- Exceptions: whitelist business processes (for example approved payroll systems) rather than disabling protection globally.
Don’t forget user experience: add clear notification text so staff understand why an action happened and who to contact. If you need technical help mapping business rules to Purview logic, the Microsoft 365 support for business team can help translate specific workflows into policy conditions and actions.
Operation and assurance: monitoring, tuning and regulatory evidence
A DLP configuration is only useful if you run it and learn from it. Set up a regular review cadence: check alerts, triage incidents, tune rules and archive resolved cases. Use dashboards and exportable reports to provide evidence for auditors and for incident response. Keep retention long enough to prove compliance if needed.
Operational checklist:
- Alert triage process: assign ownership for daily or weekly review of high‑priority alerts.
- False positive tuning: record patterns and update conditions or add exclusions weekly until noise drops.
- Reporting and retention: keep DLP logs and exported evidence for at least the period your legal team requests.
Remember regulatory responsibilities: if a DLP event reveals a likely personal data breach you may need to inform the ICO within 72 hours. For reference, see the ICO’s breach reporting guidance. Where you can, keep an audit trail of decisions so incident logs double as compliance evidence.
Related reading
- our microsoft 365 support for business guide
- Microsoft 365 security audit service: what UK SMEs need to know
- Microsoft 365 eDiscovery Support — built-in tools, Microsoft support and third‑party services
- Cost of Microsoft 365 managed services — a practical guide for UK businesses
- Microsoft 365 backup service: a straightforward guide for UK businesses
FAQ
How long does a typical Microsoft 365 DLP configuration take for a small office in the UK?
A basic pilot protecting email and one SharePoint site can be configured and tested in 2–5 working days; a full rollout across mailboxes, Teams and SharePoint typically takes several weeks depending on scope and tuning needs.
Will Microsoft 365 DLP stop staff from emailing client lists outside the company?
Yes, you can create a policy that detects lists or patterns and either warn the user or block the send — ensure you test on a small group first to tune false positives before wider enforcement.
Can DLP cover personal devices used by staff working from home in the UK?
DLP on cloud services (Exchange, SharePoint, OneDrive) works regardless of device; to control local files or mobile apps you’ll need endpoint DLP or Intune app protection policies combined with conditional access.
Will DLP logs help if there’s an ICO investigation?
Yes — exportable DLP alerts and audit logs provide time‑stamped evidence of access, actions and policy matches that you can include in an ICO report, which must be made within 72 hours of becoming aware of a qualifying breach.
When should I ask for external help configuring Microsoft 365 DLP?
If you lack in‑house policy mapping to business processes, are handling large volumes of regulated data, or need defensible evidence for auditors quickly, bring in specialist support to speed setup and reduce business disruption.







