Purview DLP policy doesn't preventing download in SharePoint sites

Shao Liu 0 Reputation points
2025-02-12T16:39:03.76+00:00

I create one Data loss policy to block downloading for everyone. I select 'Block Everyone' in the rule. I used the custom property for searching the documents. The simulation found the right docs in SharePoint, and I turned on the policy. But I can still download and share the document. I don't know what happened here. Thanks

SharePoint
SharePoint
A group of Microsoft Products and technologies used for sharing and managing content, knowledge, and applications.
11,231 questions
Microsoft Purview
Microsoft Purview
A Microsoft data governance service that helps manage and govern on-premises, multicloud, and software-as-a-service data. Previously known as Azure Purview.
1,406 questions
{count} votes

2 answers

Sort by: Most helpful
  1. Chandra Boorla 8,870 Reputation points Microsoft Vendor
    2025-02-13T09:11:06.8033333+00:00

    Hi @Shao Liu

    Greetings & Welcome to Microsoft Q&A forum! Thanks for posting your query!

    As I understand that you are attempting to create a Microsoft Purview Data Loss Prevention (DLP) policy to prevent downloads in SharePoint Online. However, despite the policy simulation correctly identifying the files, users are still able to download and share the documents.

    Here are a few steps you can take to investigate and potentially resolve the issue:

    Policy Configuration - Double-check that the DLP policy is correctly set up to block downloads for everyone. Ensure that the custom property you are using is accurately defined and applied to the documents you want to protect.

    Policy Status - Make sure the policy is not in "Test" or "Simulation" mode, as these modes do not enforce restrictions. The policy should be set to "On" or "Enforce" mode for it to block actions.

    Testing and Simulation: While the simulation may have identified the correct documents, it’s important to test the policy in a real-world scenario. Sometimes, simulations do not fully replicate the enforcement of the policy.

    User Permissions - Verify that there are no exceptions in the policy that might allow certain users to bypass the download block. Also, review any conflicting permissions that might override the DLP policy.

    Policy Activation - Ensure that the DLP policy is fully activated. Sometimes, there can be a delay in policy enforcement after activation. Check the policy status to confirm it is active.

    Policy Scope - Verify that the policy is correctly scoped to the SharePoint sites you intend to protect. If the policy is not applied to the specific sites or libraries, it won't enforce the restrictions.

    Policy Conditions - Review the conditions set in the DLP policy. Ensure that the custom property you are using for document identification is correctly configured and that the documents meet the criteria specified in the policy.

    Policy Conflicts - If there are multiple DLP policies in place, they may conflict with each other. Ensure that there are no other policies that might allow downloads or sharing of documents.

    Please refer to the below mentioned MS Q&A threads addressing similar issue, as they might offer some insights.

    I hope this information helps. Please do let us know if you have any further queries.


    If this answers your query, do click Accept Answer and Yes for was this answer helpful. And, if you have any further query do let us know.

    1 person found this answer helpful.

  2. Pauline Mbabu 595 Reputation points Microsoft Employee
    2025-02-13T10:06:08.3633333+00:00

    Hello @Shao Liu ,

    If you were able to run the Policy in Simulation and turned the Policy on, then ensure that the Policy is not being blocked by other policies due to the priority ordering. Priority 0 is the highest Priority, and the rule will run first.

    You can also check if the policy us running after some time since it might just be a
    an issue with the rule taking some time to propagate.
    I hope this helps to answer your question.

    If you find the answer above helpful, please Accept the answer to help anyone in the community who might have a similar question to quickly find the solution.
    If you have further questions, kindly leave a comment and I will get back to you.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.