TrustRadius: an HG Insights company

Microsoft Purview Data Loss Prevention

Score8 out of 10

40 Reviews and Ratings

What is Microsoft Purview Data Loss Prevention?

Microsoft Purview Data Loss Prevention is used to provide intelligent detection and control of sensitive information across Office 365, OneDrive, SharePoint, Microsoft Teams, and on the endpoint. It also helps prevent data loss through identifying and preventing risky or inappropriate sharing, transfer, or use of sensitive data on endpoints, apps, and services.

Read more details.

Categories & Use Cases

Media

Screenshot of pre-built policy templates to easily get started
Screenshot of DLP analytics to help recommend new policies and fine tune existing ones
Screenshot of the step that enables one policy to be applied to several locations
Screenshot of then next step, that enables policies to be scoped to specific users and user groups
Screenshot of composite conditions using groups of AND /OR and exceptions with NOT
Screenshot of granular restrictions for different actions
Screenshot of configuring different restrictions for different groups of devices
Screenshot of custom user notifications and policy tips
Screenshot of policy creation in Simulation mode to gain confidence before deploying in production
Screenshot of a migration of existing DLP policies to Microsoft Purview DLP, which occurs automatically
Screenshot of a display DLP incidents within the context of Security incidents in Microsoft Defender XDR
Screenshot of viewable sensitive information and surrounding context relevant to an incident
Screenshot of manual remediation actions that can be run from the event page

1 / 13

Screenshot of pre-built policy templates to easily get started

Top Performing Features

  • Data Encryption

    Data encryption to ensure data privacy

    Category average: 8.3

Areas for Improvement

Who Buys & Uses Microsoft Purview Data Loss Prevention

Pros

  • Centralized policy creation and management for sensitive data.
  • Strong integration with the Microsoft 365 ecosystem.
  • Extends data protection visibility and control to third-party cloud applications, endpoints, and macOS.

Cons

  • Significant latency in real-time alerting, potentially delaying incident response.
  • Requires careful configuration of custom sensitive information types to mitigate false positives.
  • Potential for perceived double payment if data resides outside Microsoft's infrastructure.

Microsoft Purview Data Loss Prevention Review

Use Cases and Deployment Scope

Our use cases are primarily helping customers around their regulatory requirements. Their requirements are to understand, discover sensitive information going outside their network, whether it be device or to another partner, another vendor that they're working with. They just need discovery around it. Now, recently we have also been engaged with customers around use cases where they want to understand what sensitive information is flowing into the AI space. So if users are accessing unapproved AI applications within the environment, they want to understand if any corporate sensitive information or corporate confidential files are going into those apps or not. So those are some use cases that we are currently working on.

Pros

  • I think from a coverage standpoint, it's pretty comprehensive. The areas it covers, of course, include the Microsoft stack, but also focus on using the definitive cloud apps integration to extend visibility and control to third-party cloud apps, endpoints, and even Macs. So those are capabilities.
  • Its comprehensiveness, its simplicity of creating the policies in one place, are definitely one of the plus points the solution has.

Cons

  • I mean, for the edge for business, there is one use case around using Microsoft Edge for business, understanding sensitive information flowing into AI sites. It currently depends on an Azure subscription. I would love to see if it could all be included as part of E5. The reason being, I don't know why it is that case, but it would be really beneficial if organizations that do not have to worry about ACR cost, they would be able to use this for all the users. Right now, we have to struggle with only limiting it to a few users, limiting the scope to only users because of the fear that we may not know what cost we would end up in when this is turned on. So that's kind of a challenge.

Return on Investment

  • Microsoft Purview Data Loss Prevention is definitely something... It's hard to give an ROI, unless you're talking to the right people. We try to speak to the legal compliance team, so that if the project is led by the legal team, they understand the risk around it. So the ROI is basically you not getting into, in legalities or in legal cases where somebody could, a customer or a partner that you're working with can sue you because you don't have these controls in place. That also helps you comply with certain regulatory requirements like ISO 27,001, at least have these enabled in monitoring mode, and have the discovery being done.
  • But overall, from starting with discovery and then having enforced protection, it really helps you understand the ROI from that pact. It may not have a real monetary value attached to it, but the monetary value may be attached. If you're talking to the legal guys, they understand how many from a data exfiltration standpoint, what incidents they have come across, and how much fines they have paid. So, having Microsoft Purview Data Loss Prevention is a low-hanging fruit. At least start enabling them to start seeing what's coming back in your tenant, and understand what data is being used and shared externally. So that's the ROI I see: protecting your compliance teams from any unintended fees or subpoenas, and getting around this.

Other Software Used

Microsoft Azure, Microsoft Dynamics 365

Usability

Microsoft Purview Data Loss Prevention Review

Use Cases and Deployment Scope

The reason it's important is that, as our company, we use it internally and as part of our platform. Our solution allows us to manage how users collaborate internally and externally within the organization, and we also use Microsoft Purview Data Loss Prevention and labels to drive our policy. So this way, we can automate how our solution will serve our customers, both internally and externally.

Pros

  • What it does do well, if you have it configured right, is when you start creating specific custom sensitive information types, especially when you drill down to things like exact data match and fingerprinting, it does a pretty good job of that. The challenge, as with most DLP solutions, is that out-of-the-box solutions tend to produce many false positives. And unfortunately, because of the way the solution has been positioned in the marketplace, a lot of people have a bad impression of it because it does not provide the level of out-of-the-box capability that some other solutions are offering.

Cons

  • I'd say over the last couple of years, there have been some great advancements in Microsoft Purview Data Loss Prevention, so I really do like that. I think some of the challenges I see with Microsoft Purview Data Loss Prevention today are in the first-party world; it does provide some real-time capabilities, but the alerting on DLP has a big lag. And some of our customers, actually, one of my customers in particular, whom I advise heavily, ran into a situation where they were getting hours of delays when they were getting critical, sensitive alerts. So being able to provide that in a more real-time way for both internal use within Microsoft and for third-party products, I think, would be significantly impactful. E-share, as a platform, also uses DLP in order to automate our policy, as I mentioned before. And some of that is a challenge because some of the capabilities we do need real-time information for aren't exposed to us based on the current capabilities that Firmy provides.

Return on Investment

  • From an ROI perspective, being able to have a robust DLP capability within 365 and with eShare, again, providing the defensive depth and keeping data 365 gives both us as well as our customers an ROI by being able to not use third party repositories to share data externally and by keeping data inside of 365. It gives me much more visibility into my data landscape. One of the things we advise our customers to do when they're starting to explore the advanced capabilities of Microsoft Purview Data Loss Prevention, for example, is to use that DLP product to monitor and understand the flows of sensitive data within the organization. By being able to look at that DLP, identify those sensitive niche types, and see which transactions occur internally within the organization, I get a clearer picture of what I'm doing.

Microsoft Purview Data Loss Prevention Review

Use Cases and Deployment Scope

It's for data protection, data loss protection. We use it for MIP labeling. It's to label the files with confidential sensitivity so they're not allowed to be sent outside the organization.

Pros

  • If the calls are set up right, if it sees files marked with certain labels like confidential, it will stop them from being sent out of the organization. So the data leakage is to a minimum.

Cons

  • I would say they improved a lot of their reporting. Where I would like to see them improve is probably by adding more features sooner.

Return on Investment

  • As a public company, I don't focus on ROI too much. Okay. But it has a positive impact because we're stopping data leakage.

Other Software Used

CrowdStrike Falcon

Usability

Microsoft Purview Data Loss Prevention

Use Cases and Deployment Scope

The biggest one for us is insider risk management: being able to track employee behavior, not only against their own baseline, but against organizational baselines to understand when certain patterns of actions stand out from that. That's given us much better insight into some of the non-direct-threat actions, but there are still concerning things we need to follow up on, especially for data loss prevention.

Pros

  • It does very well at pulling data from across the Microsoft platform. We have implemented several of the tools, so being able to have Defender for Cloud information, we have the Microsoft Purview Data Loss Prevention browser extension deployed. So we get browser level information there. It's probably the best kind of single-frame visibility I have from endpoint to cloud systems for user interactions, with very detailed logs.

Cons

  • The ability to tune it is difficult. In a lot of cases, you're reliant on Microsoft's pre-built attack chains, and their ability to tune those to either organizational levels or overall customer pool levels is pretty opaque to the user. So to some degree it's set and forget. In other degrees, I'd really like to have a little more control over what kinds of chains and actions that we're monitoring within it.

Return on Investment

  • Yeah, it's really sped up our SOX ability to respond to insider threat events and get a much better idea without having to do that level analysis for themselves. Copilot security agents, too. Those are starting to be used within Microsoft Purview Data Loss Prevention to try and triage alerts. And that's been a really nice feature to have.

Other Software Used

Appgate SDP

Usability

Microsoft Purview Data Loss Prevention

Use Cases and Deployment Scope

We use a product to select the data sensitivity labels that are rolled out across the Office 365 suite of products. Users are able to, when they're creating documents or working with documentation in Office 365, select a sensitivity label that applies certain policies, such as restrictions on emailing, access, or encryption. And that is to protect the data.

Pros

  • The sensitivity labels are pretty good. The enforcement in the Office 365 suite is amazing because you can actually force users to tag documentation on the spot at the time of creation. The enforcement on the Office Suite works pretty well. Either it's on-prem or in the cloud, it also works very well.

Cons

  • Hard to use. Let's say, on the client side, the product relies on Microsoft Defender for Cloud, specifically for improvement. I would say more third-party integrations. So for non-Microsoft products, so you can actually enforce DLP on the actual endpoint.

Return on Investment

  • One of the problems we had at our business was data sprawl. Basically, documentation is created, stored in legacy file systems, and then it gets stale and forgotten. The life cycle of the documents becomes a problem. By using Microsoft Purview Data Loss Prevention, we can establish lifecycle policies for documentation so that we don't have data sprawl and avoid having documentation that's not relevant to the business anymore. So it helps with the lifecycle, plus it also helps with making sure that we don't leak out any type of sensitive information into the public.

Other Software Used

Microsoft 365 Business Premium, Dropbox, CrowdStrike Falcon, Proofpoint Email Protection

Usability