DLP Policy Not Scanning Inside Compressed Files (Purview)

Mahmoud Hesham 5 Reputation points
2024-12-29T08:53:32.0033333+00:00

I'm trying to configure Microsoft Purview to scan inside compressed files (e.g., .zip, .rar) and apply Data Loss Prevention (DLP) policies to prevent sensitive data from being shared via email. However, I'm encountering the following issues:

I need to ensure that sensitive data labels are detected inside archives and trigger DLP policies when emailed.

Despite configuring the DLP policy, password-protected archives bypass detection.

Important: I do not want to block all encrypted/password-protected files – only the ones that contain sensitive data. Blocking every compressed file creates unnecessary disruption, but I need to ensure sensitive data isn't accidentally shared.

Could someone guide me on:

How to enable scanning for compressed files in Purview?

Whether Purview can extract and inspect contents of .zip files?

How to configure DLP to block only password-protected archives that contain sensitive data?

I would appreciate any detailed steps or links to relevant documentation.

Thank you!

Microsoft Purview
Microsoft Purview
A Microsoft data governance service that helps manage and govern on-premises, multicloud, and software-as-a-service data. Previously known as Azure Purview.
1,312 questions
Microsoft Defender for Cloud Apps
Microsoft Defender for Cloud Apps
A Microsoft cloud access security broker that enables customers to control the access and use of software as a service apps in their organization.
160 questions
Microsoft Defender for Endpoint Training
Microsoft Defender for Endpoint Training
Microsoft Defender for Endpoint: A Microsoft unified security platform for preventative protection, postbreach detection, and automated investigation and response. Previously known as Microsoft Defender Advanced Threat Protection.Training: Instruction to develop new skills.
19 questions
{count} votes

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.