Microsoft DLP: Emailing of Sensitive Data.

Summary

Microsoft Purview Data Loss Prevention (DLP) is configured in our Office 365 tenant to protect against the accidental or intentional sharing of sensitive information such as Credit Card Numbers (CCN) and U.S. Social Security Numbers (SSN).

Body

Overview

Microsoft Purview Data Loss Prevention (DLP) is configured in our Office 365 tenant to protect against the accidental or intentional sharing of sensitive information such as Credit Card Numbers (CCN) and U.S. Social Security Numbers (SSN). 

When users attempt to send emails or attachments that contain sensitive data, they are presented with policy tip notifications and may be required to take further action before sending. 

When sensitive information is detected, a Policy Tip appears above the email. Screenshot below.

Uploaded Image (Thumbnail)

The tip shows:

o    Which type of sensitive information was detected (e.g., Credit Card Number, SSN).
o    Why the email cannot be sent immediately.
o    An option to Report if the user believes it is not sensitive.

Override Prompt (Blocking Screen, Top right) 

Uploaded Image (Thumbnail)
•    The message is blocked until the user makes a decision.
•    Two options are presented:


1.    Report → Used if the user thinks the detection is a false positive.
2.    Acknowledgement → User confirms they are intentionally sending sensitive data and that it complies with policies. Screenshot below.

Uploaded Image (Thumbnail)


o    Learn more (policy details)
o    Send anyway (override)
o    Cancel

Example: “Your organization won’t allow this message to be sent until the sensitive information is removed.” 

Details

Details

Article ID: 28002
Created
Mon 3/2/26 3:38 PM
Modified
Tue 3/3/26 3:08 PM