Customer data in an email to a personal address. A spreadsheet of salaries shared with "anyone with the link." A contract uploaded to an unapproved file-sharing site. Most data leaks are not attacks. They are everyday work without guardrails.
Microsoft Purview DLP and sensitivity labels give you those guardrails inside the tools your people already use.
Most data leaks are not attacks.
What is Microsoft Purview?
Microsoft Purview is Microsoft's family of data security, governance and compliance solutions. For data protection, the key components are:
Microsoft Purview DLP policy tip warning user
Illustration in progress
- Information Protection: sensitivity labels that classify and optionally encrypt content
- Data Loss Prevention (DLP): policies that detect sensitive information and restrict how it is shared
- Insider Risk Management: detects risky user behaviour, such as mass downloads before resignation
- Data Lifecycle Management: retention and deletion policies
- Data Security Posture Management (DSPM): visibility into where sensitive data sits and how it is used, including with Copilot and other AI apps
What are sensitivity labels?
Sensitivity labels are tags such as Public, Internal, Confidential and Highly Confidential applied to documents, emails, Teams and SharePoint sites. A label can:
- Add headers, footers or watermarks
- Encrypt content so only authorised users can open it
- Restrict external sharing for labelled sites and Teams
- Travel with the file, even outside Microsoft 365
Labels can be applied manually, recommended, or applied automatically based on content.
What is Data Loss Prevention?
DLP policies identify sensitive information, such as credit card numbers, national ID numbers, bank account details or custom patterns, and take action when it is shared in risky ways. DLP covers Exchange, SharePoint, OneDrive, Teams, endpoints (Windows and macOS) and some third-party apps.
Typical actions include showing a policy tip to the user, requiring a business justification, blocking external sharing or alerting the security team.
A phased Purview rollout plan
Microsoft Purview DLP rollout plan
Illustration in progress
| Phase | Activities | Outcome |
|---|---|---|
| 1. Discover | Content explorer, activity explorer, identify sensitive info types | Know where sensitive data lives |
| 2. Define | Agree label taxonomy (4–5 labels) and DLP scope with business owners | Simple, understood classification |
| 3. Simulate | DLP in simulation mode, labels published to pilot users | Measure impact without disruption |
| 4. Educate | Policy tips, short training, champions | Users understand why |
| 5. Enforce | Turn on blocking for highest-risk scenarios | Real protection |
| 6. Tune | Review false positives and overrides monthly | Sustainable programme |
Which DLP policies should you start with?
- Block external sharing of documents containing payment card data
- Warn users when emailing national ID or bank details externally
- Block uploads of Highly Confidential files to unapproved cloud services from endpoints
- Restrict sharing of Highly Confidential labelled files with guests
- Alert on bulk sharing of sensitive files
Why does Purview matter for Copilot?
AI assistants like Microsoft 365 Copilot can surface any content a user has permission to access. If permissions are too broad, Copilot can expose sensitive data that was previously "hidden by obscurity." Labels, DLP and access reviews reduce this risk. See our Copilot readiness guide.
How Crozaint approaches data protection
Data controls with Microsoft Purview are part of the Deploy phase of Crozaint's Microsoft 365 security programme, following our 2–4 week assessment of data governance gaps. We design a label taxonomy with your business owners, roll out DLP in simulation mode, tune it and then enforce.
Our measure of success is enforced controls, not documented policy. For MUJI Europe, conditional access, device compliance and data-loss controls became enforced controls rather than a policy document. After deployment, you choose managed operations or a full handover.
Common mistakes to avoid
- Creating 15 labels nobody understands
- Enforcing DLP blocks on day one
- Rolling out labels without user communication
- Ignoring endpoint DLP while protecting only email
- Never reviewing false positives and overrides
Conclusion
Most data leaks are accidents. Purview labels and DLP prevent them inside everyday tools, as long as you discover first, simulate, educate and then enforce.
Worried about where your sensitive data is going? Book a 30-minute discovery call with Crozaint.

