10.1 Configure DLP Policies for Adaptive Protection
Key Takeaways
- Adaptive Protection feeds DLP through the condition Insider risk level for Adaptive Protection is, with values Elevated, Moderate, and Minor — not Insider Risk Management alert severity Low, Medium, or High
- Quick setup auto-creates Adaptive Protection policy for Teams and Exchange DLP and Adaptive Protection policy for Endpoint DLP, each with an elevated block rule and a moderate/minor audit rule, both starting in simulation mode
- Adaptive Protection currently supports DLP locations Exchange, Microsoft Teams, and Devices; you can add other locations on a policy, but those locations are not Adaptive Protection–supported enforcement surfaces
- For Devices, enable Advanced classification scanning and protection, or select the File Type is condition; overlapping Adaptive Protection and independent Device DLP policies apply the most restrictive actions
- Manual configuration is ordinary DLP plus that insider-risk condition; Insider Risk Management or Insider Risk Management Admins turn Adaptive Protection on, while Compliance Administrator, Compliance Data Administrator, DLP Compliance Management, or Global Administrator author the DLP policy
The July 28, 2026 SC-401 outline asks you to configure data loss prevention policies for Adaptive Protection. That is not a third DLP product. Adaptive Protection in Microsoft Purview uses Insider Risk Management machine learning to assign each in-scope user an insider risk level, then lets data loss prevention (DLP), data lifecycle management, and Microsoft Entra Conditional Access apply stronger or weaker controls as that level changes. DLP’s job is to consume the level as a condition so a high-risk leaver is blocked while a low-risk analyst still works.
Learn’s Adaptive Protection DLP article (Learn about Adaptive Protection in data loss prevention) and the Insider Risk Management Adaptive Protection article (Help dynamically mitigate risks with Adaptive Protection, updated 2026-06-26) are the sources for this section. Licensing is documented on Microsoft’s enterprise-plans page; Microsoft does not publish an SC-401-specific SKU matrix in the skills outline, so do not invent one.
Insider risk levels are not alert severity
Insider Risk Management already scores alerts as Low, Medium, or High so analysts can triage. Adaptive Protection uses a different scale:
| Adaptive Protection insider risk level | Built-in meaning (customizable) |
|---|---|
| Elevated risk level | High-severity alerts; at least three sequence insights that each carry a high-severity alert for specified risk activities; or one or more confirmed high-severity alerts |
| Moderate risk level | Medium-severity alerts, or at least two data-exfiltration activities with high severity scores |
| Minor risk level | Low-severity alerts, or at least one data-exfiltration activity with a high severity score |
A level is assigned only when the number of insights and their severity match the definition. Ten SharePoint downloads in one day that Insider Risk Management treats as a single high-severity insight count as one insight, not ten. Elevated typically needs two additional high-severity insights on top of that first one. If the user is in several Insider Risk Management policies and those policies raise different alert severities, Adaptive Protection uses the highest severity the user actually received — but only when that activity exists in a policy Adaptive Protection selected.
You can customize each level to fire on alerts generated or confirmed (conditions are not additive: any listed alert condition is enough) or on specific user activity (conditions are additive: activities, activity severity, and occurrences in the detection window must all match). Past activity detection looks back 7 days by default and can be set between 5 and 30 days; it applies to activity-based levels, not alert-based levels. The insider risk level timeframe keeps a level on the user for 7 days by default (also 5–30 days) and extends if the user meets the same level again. Levels also reset when the associated alert is dismissed, the associated case is resolved, or an investigator Expires the level on the user. Automatic expiration when an alert is dismissed or a case is closed is on by default; turn it off only if you want the DLP condition to keep matching after the investigation closed.
Quick setup hard-wires a narrower set: Elevated needs at least three high-severity exfiltration sequences; Moderate needs at least two high-severity activities (excluding some download types); Minor needs at least one high-severity activity (excluding some download types).
How the level shows up in DLP
After Adaptive Protection is configured in Insider Risk Management, DLP rules scoped to supported locations gain the condition Insider risk level for Adaptive Protection is (the Insider Risk Management article also says User's insider risk level for Adaptive Protection is — same condition). Values are Elevated risk level, Moderate risk level, and Minor risk level. You can pick one, two, or all three on a single rule. The DLP policy reference lists that condition for Exchange Online, Devices, Teams, and unmanaged cloud apps. The Adaptive Protection product page is stricter about enforcement: you may include other locations on the DLP policy, but Adaptive Protection currently supports only Exchange, Microsoft Teams, and devices. Do not tell the exam that SharePoint or OneDrive Adaptive Protection DLP is a supported location. Treat unmanaged cloud apps as a condition catalog entry, not as a promise that Adaptive Protection currently drives those policies the way it drives Exchange, Teams, and Devices.
You still combine the risk-level condition with ordinary DLP predicates. Quick setup’s Exchange/Teams rules add Content is shared from Microsoft 365 with people outside my organization. Quick setup’s Device rules add File Type is Word processing, Spreadsheet, Presentation, Archive, and Mail. Manual policies can add SITs, labels, or sharing conditions as needed — the Adaptive Protection condition is the switch that turns the rule on only for currently risky users.
Quick setup versus manual DLP
Quick setup is the fastest path when you do not already have Insider Risk Management, DLP, data lifecycle management, or Conditional Access policies. Start from the Adaptive Protection cards on the Purview home page, the DLP Overview page, or Insider Risk Management > Adaptive protection > Dashboard > Quick setup. Scoped (administrative unit) admins cannot turn on quick setup. Do not disable Adaptive Protection while setup is running; Microsoft warns that doing so can produce policy errors. Quick setup can take up to 72 hours. Administrators get email when it finishes. It creates, among other objects:
- An Insider Risk Management policy named Adaptive Protection policy for Insider Risk Management from the Data leaks template, scoped to all users and groups.
- Two DLP policies that start in simulation / test (audit only) — not Turn it on.
- A Conditional Access policy in report-only mode that blocks Office 365 apps for Elevated users (preview naming on that CA policy).
- A data lifecycle management auto-apply label policy that watches Elevated users and preserves deleted SharePoint, OneDrive, or Exchange Online content for 120 days (admins restore preserved content by contacting Microsoft support; that is DLM, not DLP).
The two DLP policies are the ones SC-401 wants you to recognize by name and rule shape.
Adaptive Protection policy for Teams and Exchange DLP
| Rule | Conditions | Actions | Notifications / override | Status |
|---|---|---|---|---|
| Adaptive Protection block rule for Teams and Exchange DLP | Insider risk level is Elevated AND content is shared with people outside the organization | Restrict access or encrypt content in Microsoft 365 locations: Block only people outside your organization | Policy tip on (notify the user who sent, shared, or last modified); user override off; incident reports on, severity Low, alert every match | Simulation; policy tips not selected |
| Adaptive Protection audit rule for Teams and Exchange DLP | Insider risk level is Moderate or Minor AND content is shared outside the organization | None (audit/educate path) | Policy tip on; override off; incident reports on, severity Low | Simulation; policy tips not selected |
Adaptive Protection policy for Endpoint DLP
| Rule | Conditions | Actions | Notifications / override | Status |
|---|---|---|---|---|
| Adaptive Protection block rule for Endpoint DLP | Elevated AND File Type is Word processing, Spreadsheet, Presentation, Archive, Mail | Block upload to a restricted cloud service domain or access from unallowed browsers; block copy to clipboard, removable USB, network share, and print; block access by restricted apps | User notification off; override off; incident reports on, severity Low | Simulation |
| Adaptive Protection rule for Endpoint DLP (moderate/minor) | Moderate or Minor AND the same file types | Audit the same device activities | Notification off; override off; incident reports on, severity Low | Simulation |
Two Device facts Microsoft prints as Important:
- For Adaptive Protection to work on Devices you must enable Advanced classification scanning and protection, or, if you create the policy yourself, select the File Type is condition.
- If a user is in the default Adaptive Protection Device DLP policy and an independent Device DLP policy, only the actions of the most restrictive policy are applied.
Manual configuration is the custom-setup path: create or edit any DLP policy the usual way, add Insider risk level for Adaptive Protection is, pick the levels, set the other conditions and actions, and deploy with your normal simulation-then-enforce process. Microsoft recommends testing DLP with policy tips and reviewing DLP alerts before you turn Adaptive Protection on. After custom objects exist, enable Adaptive Protection on Adaptive Protection settings. Expect up to 36 hours before levels and DLP/Conditional Access/DLM actions apply to user activity.
Who can configure what, and where you look
| Task | Documented assignment |
|---|---|
| Configure Adaptive Protection and update its settings | Insider Risk Management or Insider Risk Management Admins |
| Create and manage DLP policies that use the Adaptive Protection condition | Compliance Administrator, Compliance Data Administrator, DLP Compliance Management, or Global Administrator (use the least privilege that still works) |
| View which users or agents currently have a level | Insider Risk Management, Insider Risk Management Analysts, or Insider Risk Management Investigators |
The Adaptive Protection page hides tabs you cannot use. The Data Loss Prevention tab lists only DLP policies that include the Adaptive Protection condition, with policy state (Active/Inactive), location, insider risk levels, and status (On or Test with notifications). Insider Risk Management also says you can open that Adaptive Protection DLP list if you hold Compliance administrator, Compliance Data administrator, Organization management, Global administrator, DLP compliance management, or View-only DLP compliance management — still prefer least privilege; Global Administrator is the last resort.
Privacy trap: Insider Risk Management can show anonymized user names. That anonymization is not preserved in Adaptive Protection–related DLP alerts or activity explorer. Conditional Access never anonymizes names. Plan investigations accordingly.
Related, but not this bullet: DLP incident reports feed Insider Risk Management only when incident-report severity is High. Quick setup’s Adaptive Protection DLP rules set incident severity to Low. Do not confuse “make IRM see this DLP alert” with “make DLP see this IRM risk level.”
Disable and tune
Turning Adaptive Protection Off stops assigning levels and sharing them with DLP, data lifecycle management, and Conditional Access. Existing levels reset. Expect up to six hours for assignment to stop. The Insider Risk Management, DLP, DLM, and Conditional Access policies are not automatically deleted. You can opt out of DLM preservation without disabling Adaptive Protection by turning off Adaptive protection in Data Lifecycle Management (that deletes the DLM policy).
If too many or too few users receive a level, tune the level definitions (severity, occurrence count, alerts-versus-activity basis) or the Insider Risk Management policy thresholds that produce high/medium/low severity insights. That is how you change who matches the DLP condition — not by inventing a fourth risk level.
When you can name the DLP condition, contrast quick setup’s two simulation policies with a hand-built rule, list Exchange/Teams/Devices as the Adaptive Protection DLP surfaces, and recite the Device classification prerequisite, you have this blueprint skill.
A DLP rule should apply only to users Insider Risk Management Adaptive Protection currently treats as risky. Which condition does Microsoft document for that rule?
What DLP objects does Adaptive Protection quick setup create, and in which state do they start?
You are creating a manual Adaptive Protection DLP policy for Devices. What does Microsoft document as required for Adaptive Protection to work on that location?