Hi @Shao Liu
Greetings & Welcome to Microsoft Q&A forum! Thanks for posting your query!
As I understand that you are attempting to create a Microsoft Purview Data Loss Prevention (DLP) policy to prevent downloads in SharePoint Online. However, despite the policy simulation correctly identifying the files, users are still able to download and share the documents.
Here are a few steps you can take to investigate and potentially resolve the issue:
Policy Configuration - Double-check that the DLP policy is correctly set up to block downloads for everyone. Ensure that the custom property you are using is accurately defined and applied to the documents you want to protect.
Policy Status - Make sure the policy is not in "Test" or "Simulation" mode, as these modes do not enforce restrictions. The policy should be set to "On" or "Enforce" mode for it to block actions.
Testing and Simulation: While the simulation may have identified the correct documents, it’s important to test the policy in a real-world scenario. Sometimes, simulations do not fully replicate the enforcement of the policy.
User Permissions - Verify that there are no exceptions in the policy that might allow certain users to bypass the download block. Also, review any conflicting permissions that might override the DLP policy.
Policy Activation - Ensure that the DLP policy is fully activated. Sometimes, there can be a delay in policy enforcement after activation. Check the policy status to confirm it is active.
Policy Scope - Verify that the policy is correctly scoped to the SharePoint sites you intend to protect. If the policy is not applied to the specific sites or libraries, it won't enforce the restrictions.
Policy Conditions - Review the conditions set in the DLP policy. Ensure that the custom property you are using for document identification is correctly configured and that the documents meet the criteria specified in the policy.
Policy Conflicts - If there are multiple DLP policies in place, they may conflict with each other. Ensure that there are no other policies that might allow downloads or sharing of documents.
Please refer to the below mentioned MS Q&A threads addressing similar issue, as they might offer some insights.
- DLP actions for Sharepoint files
- Purview unable to find certain SharePoint Online sites when querying to add them to a DLP policy scope
I hope this information helps. Please do let us know if you have any further queries.
If this answers your query, do click Accept Answer
and Yes
for was this answer helpful. And, if you have any further query do let us know.