Protecting information where it is actually used: what exists, where it lives, who can reach it and what should happen when someone tries to take it out.
A DLP strategy doesn't start in the admin console. It starts by answering a handful of uncomfortable questions about what information you hold and how it moves, and in many organisations that part hasn't been done.
Once those decisions are made, the technology executes a strategy defined beforehand. The other way round you end up with a pile of rules nobody dares switch to block mode, because nobody knows who they will land on.
There is no way to know what has been shared outside, with whom or through which channel. The first anyone hears of it is after the fact.
A contract, a security questionnaire or an external assessment asks about data loss controls and there is nothing in place.
Someone configured DLP policies at some point, they have been in alert mode ever since, and nobody dares turn them on properly.
This is the work that separates a rollout which lasts from one that gets switched off within three months.
The inventory that almost never exists and without which nothing can be protected.
The map of access and movement, which is where the surprises turn up.
Taking it to the platform, normally Microsoft Purview.
The risk of a badly planned DLP isn't that it fails to protect: it is that it stops people working and ends up switched off.
What information exists, where it lives and how it circulates today. What actually happens gets looked at, not what the procedure says.
What gets protected, at what level and what happens when someone tries to take it out. These decisions are made with the business, not only with IT.
Policies deployed without blocking anything, to measure the real noise and tune before anyone is left unable to work.
Moving to block mode whatever warrants it, in phases, with a clear procedure for legitimate exceptions.
A DLP stays alive: the exceptions and the reasoning matter as much as the rules.
Scope of the serviceThe project ends with the policies tuned, the exception procedure defined and your team operating them with the documentation to do so; day-to-day watching of the alerts stays on your side. It builds on data protection compliance and helps sustain it, but it is an information security project rather than a GDPR programme.
Purview is the usual platform because it tends to be in the licence already, but configuration is the last phase and not the first. What takes the work is deciding which information matters, who should reach it and what happens when someone tries to take it out. A tool doesn't make those decisions.
Not if it is rolled out in phases. Everything goes in first in alert mode, blocking nothing, long enough to see the real noise and tune. Only what warrants it moves to block, and with a procedure for legitimate exceptions, which do exist.
No, and waiting until everything is classified is the surest way never to start. You begin with whatever would hurt most to lose —what a client would ask for, what would sink a contract— and widen from there. Full classification is a consequence of the project, not a prerequisite.
It depends on your plan. You can check it in the Purview licensing simulator before we even speak. There is a fair amount of DLP available in mid-tier plans; the finer capabilities do require higher ones, and it is worth knowing which before deciding.
It depends on the channel and on what your licence and your device estate cover. Some of it is controlled technically and some isn't, and that boundary is worth knowing from the start rather than discovering later. Whatever the tool doesn't cover gets worked on through training and culture.
To connect these controls with identities, applications, data and exceptions, read the Microsoft 365 security assessment guide. It explains which evidence to review and how to prioritise improvements.
If the answer is "more or less", that is exactly the starting point. Tell me what you are worried about going out and which channels you work through, and we will see whether what you need is a DLP project or something simpler.
I reply personally within 24 working hours · No commitment