DLP guides
Data loss prevention — Microsoft Purview policies that detect and act on sensitive data movement. See the glossary entry →
30 guides touch on dlp.
- Copilot agents and Agent Store governance
What a Copilot agent is, how the Agent Store distributes them, the tenant controls for who can build, share, and install, and where governance falls short.
- Exchange transport rule examples
Real-world transport rule patterns — external-sender warnings, encryption triggers, blocking, and compliance scenarios.
- How to create a DLP policy in Microsoft Purview
How to create a DLP policy in Microsoft Purview for card and personal data: locations, sensitive info types, rules and actions, simulation mode, enforcement.
- Microsoft 365 admin center
The Microsoft 365 admin center: what actually lives there, the specialist portals it hands off to, and the role design that should gate all of it.
- Microsoft 365 Copilot data access and permissions
How Copilot decides what content to surface — permissions, sensitivity labels, and the controls that gate access.
- Microsoft 365 Copilot data security and privacy
How Microsoft 365 Copilot handles your tenant's data — what's sent to the model, what's retained, and what compliance covers.
- Microsoft 365 dev/test tenant strategy
Why and how to maintain a separate dev/test Microsoft 365 tenant for safe testing of changes.
- Microsoft 365 documentation patterns
What to document for a Microsoft 365 tenant, how to structure it, and how to keep it from rotting.
- Microsoft 365 governance framework
A practical framework for governing Microsoft 365 — domains, policies, roles, and operating cadence.
- Microsoft Defender for Cloud Apps explained
Defender for Cloud Apps is Microsoft's CASB — discovering, monitoring, and controlling SaaS app usage.
- Microsoft Defender for Endpoint explained
Defender for Endpoint is Microsoft's EDR/XDR platform for laptops, servers, and mobile. Here's what it does.
- Microsoft Priva privacy management
Microsoft Priva is the data-privacy management product in Microsoft 365 — risk management and subject rights requests.
- Microsoft Purview Compliance Manager
Compliance Manager scores your tenant against compliance frameworks and tracks improvements over time.
- Microsoft Purview Data Loss Prevention — a deep dive
DLP policies detect and prevent sensitive data from leaving Microsoft 365. Here's the architecture and how to roll them out.
- Microsoft Purview Data Map
The Data Map is the data governance side of Purview — discovering, classifying, and cataloguing data across the enterprise.
- Microsoft Purview sensitivity labels — a deep dive
How Purview sensitivity labels classify and protect content, how to design a taxonomy that survives contact with users, and the rollout order that works.
- Office 365 Message Encryption
OME is Microsoft's email encryption service — what it does, how to enable it, and what it looks like for recipients.
- OneDrive for Business vs OneDrive (personal)
Two products, one name — the differences between work and consumer OneDrive, and why mixing them is a bad idea.
- Power Platform Center of Excellence (CoE) Toolkit
Microsoft's free toolkit of apps and flows for governing Power Platform at scale.
- Power Platform custom connectors
How to build custom connectors for Power Automate and Power Apps — wrapping any REST API as a Power Platform connector.
- Power Platform DLP policies
How Power Platform DLP policies govern which connectors apps and flows can combine — for data protection at the platform layer.
- Power Platform environments and governance
Environments are the unit of isolation in Power Platform. Designing them well prevents most governance problems.
- Purview auto-labelling policies
How auto-labelling applies sensitivity and retention labels automatically based on content match — and the operational realities.
- Purview Insider Risk Management
Insider Risk Management detects risky internal behaviour — data theft, IP leakage, policy violations — with built-in privacy controls.
- Purview vs Netskope
Microsoft Purview vs Netskope for data protection: native labelling and DLP inside Microsoft 365 against SSE-based DLP across every cloud app and the web.
- Teams app permission policies design
Designing Teams app permission and setup policies — controlling app installation and pinning at scale.
- What is Microsoft Purview?
What Microsoft Purview is: labels, DLP, retention, eDiscovery, insider risk, and the data-governance catalogue — how the two halves differ and where to start.
- What is Power Apps?
What Power Apps is: each app type and what it's for, where Dataverse fits, what's really included with Microsoft 365, and when not to use it.
- What is Power Automate?
What Power Automate is: cloud flows, desktop flows and RPA, what Microsoft 365 includes for free, and the governance that keeps it from becoming shadow IT.
- Zero trust in Microsoft 365
What zero trust actually means in a Microsoft 365 context — and the concrete controls that get you there.