11.3 Configure Endpoint DLP Settings

Key Takeaways

  • Endpoint DLP settings are tenant-wide controls under Data loss prevention > Overview > Data loss prevention settings > Endpoint settings; they apply to every Devices-scoped DLP policy
  • Advanced classification scanning and protection sends content to the cloud so EDM, trainable classifiers, named entities, credential classifiers, and document fingerprinting work on devices; Paste to browser does not use it
  • A rolling 24-hour per-device bandwidth cap pauses cloud classification when exceeded; even unlimited bandwidth still has a 64 MB text limit and a 50 MB OCR image limit
  • Network share coverage extends Devices policies to new and edited files on shares and mapped drives after the published Windows KBs, Defender 4.18.2304.8, and macOS Defender 101.24122.0005
  • Unallowed browsers, service domains, sensitive service domain groups, printer/USB/network-share groups, file-path exclusions, Always audit, and Enable Endpoint DLP for Windows Servers are settings, not per-rule checkboxes
Last updated: August 2026

The July 28, 2026 bullet is Configure Endpoint DLP settings. These are not the actions inside one rule. They are central switches that apply to all DLP policies for devices. Path: Microsoft Purview portal > Data loss prevention > Overview > settings gear > Data loss prevention settings > Endpoint settings (Microsoft also labels the blade Endpoint DLP settings). If a rule says Block upload to restricted cloud domains but the Service domains list is empty in Allow mode, the rule has nothing to match. If advanced classification is off, an EDM SIT on that same rule never fires on the laptop.

Advanced classification scanning and protection

Turn this on when device policies must use exact data match (EDM), trainable classifiers, named entities, credential classifiers, or document fingerprinting. The device sends content to the Microsoft Purview cloud classification service and gets labels/SITs back. DLP policy evaluation still happens in the cloud even when you are not shipping user content for those extra classifiers. Support matrix: Windows 10 1809+ / Windows 11 / Windows Server 2019+ (x64) and macOS three latest majors. Microsoft documents advanced classification for Office (Word, Excel, PowerPoint) and PDF. Paste to browser does not support advanced classification — pasted text is evaluated differently; do not promise EDM on a paste-to-ChatGPT stem.

Bandwidth is a rolling 24-hour, per-device cap you set here, or Do not limit bandwidth. Unlimited. If the cap is exceeded, Endpoint DLP stops sending content to the cloud. Local classification continues, but EDM, named entities, trainable classifiers, and credential classifiers are unavailable until usage drops below the cap. Evidence collection for matched files (if you enable it) does not count against this cap. Microsoft does not publish a mandatory default gigabyte number on that page — you configure the limit or choose unlimited. Unlimited still cannot scan text files larger than 64 MB. With OCR on, image files have a 50 MB advanced-classification limit. Windows 10 needs KB5016688 and Windows 11 KB5016691 for advanced classification / contextual summary in Activity explorer. Advanced classification Windows 10 floors also include 20H1/21H1+ with KB 5006738 and RS5 with KB 5006744; all Windows 11 versions are listed as supported.

Advanced label-based protection for all files on devices is a related tenant switch: labeled files that use access control can stay unencrypted on the PC while Endpoint DLP still enforces, then encrypt on egress. Microsoft documents it only on onboarded Windows devices, with Information Protection client 3.1.309+ and anti-malware 4.18.25050+ plus the listed Windows updates. Do not enable it as a macOS answer.

Network share coverage, path exclusions, and servers

Network share coverage and exclusions extends Devices DLP actions to new and edited files on network shares and mapped drives. Exclude paths in Exclude these network share paths. If just-in-time protection is on, JIT coverage follows the same share setting — you still configure JIT in the next chapter; here you only know the setting exists and that coverage and JIT together apply to shares, while JIT alone without this setting stays on local storage. Published prerequisites: Windows 10 KB5023773 / KB5023774, Windows 11 KB5023778, Microsoft Defender platform 4.18.2304.8 (engine 1.1.20300.3), macOS three latest with Defender app 101.24122.0005. This is complementary to DLP on-premises repository actions (scanner on the file server), not a replacement.

File path exclusions turn off auditing and enforcement under those paths. Windows patterns: C:\Temp\ (files directly in the folder), C:\Temp\* (subfolders only), C:\Temp (folder and subfolders), wildcards such as C:\Users\*\Desktop\, *(1) for a single user folder, and %SystemDrive%. Defaults already exclude each user's AppData\Roaming and AppData\Local. macOS paths are case-insensitive; /System is excluded by default. Keep Include recommended file path exclusions for Mac On unless you have a reason to scan /Applications, /usr, /Library, Teams support folders, and the other listed paths — Microsoft recommends leaving it on for performance.

Enable Endpoint DLP for Windows Servers is the toggle from section 11.1. Onboard first, then set it On under Endpoint DLP support for onboarded servers.

Always audit file activity for devices is on by default after onboarding: Office, PDF, and CSV activity is audited even with no policy match (create, modify, rename, created on removable media, created on a network share). Turn it off only if you want audit when the device is in an active policy. Word, PowerPoint, Excel, PDF, and CSV can be audited even when the device is not targeted by any policy while this setting is on.

Browsers, service domains, and authorization groups

Unallowed browsers (Windows: executable name; macOS: full path) cannot open files that match a cloud-upload rule set to block or block with override; users get a toast to use Edge. Service domains work with the rule's Audit/Block/Block with override on Upload to a restricted cloud service domain. They apply only to uploads in Edge or Chrome/Firefox with the Purview extension. Paste-to-browser does not follow the Service domains list; it can follow Sensitive service domain groups on the rule.

Service domains modeListed siteSite not listed
AllowUpload allowed; no DLP restriction from this list (still audited)DLP policy restriction is applied (audit/block/override as the rule says)
BlockDLP policy restriction is appliedUpload allowed; no restriction from this list

Allow mode requires at least one domain or nothing is enforced. Add FQDNs without a trailing dot and without https://. contoso.com matches that host and subsites, not www.contoso.com; *.contoso.com matches subdomains. Microsoft documents up to 50 domains under the Sensitive service domains list used with this setting. Sensitive service domain groups are the larger grouping object: 100 websites per group, 150 groups (15,000 sites). Edge can print/copy/save-as/paste/upload; Chrome with the extension: paste and upload; Firefox with the extension: upload and paste. IP address / range match is preview and does not include paste-to-browser; upload-by-IP is Windows-only. The Generative AI Websites group is built in for DSPM for AI and cannot be edited or deleted.

Authorization groups let a rule Allow Legal printers and Block everything else:

Group typePublished ceilingTypical use
Printer groups20 groups, 50 printers eachAllow contract printing only on Legal printers. Friendly name and USB IDs work on Windows and macOS; Print to file, Universal Print, Corporate printer, and Print to local are Windows-only.
Removable USB device groups20 groups, 50 devices eachAllow copy only to named backup drives (vendor/product/serial/device IDs).
Network share groupsPrefix/wildcard pathsAllow save only to \\Finance\Close.
Restricted apps / app groups50 apps per group, 10 groupsAllow CAD.exe; auto-quarantine OneDrive sync loops.
VPN settingsServer address or network address from Get-VpnConnectionDifferent clipboard/USB/print actions on VPN vs corporate network. Not supported on macOS.

Do not stack USB printer, IP range, Print to file, Universal Print, Corporate printer, and Print to local on the same printer definition. Corporate network under network restrictions is Get-NetConnectionProfile with NetworkCategoryId = DomainAuthenticated. If VPN and corporate network are both selected, order decides which action wins — put VPN above corporate network if VPN should win.

Business justification in policy tips is global for Block with override: default options plus custom text, defaults only, or custom text only. You can customize up to five dropdown strings (established workflow, manager approved, urgent, false positive, other).

Unsupported file extension exclusions and Disable classification refine Document could not be scanned / Apply restrictions to only unsupported file extensions. Do not put a leading dot on the extension. Blocking .dll or .json can break apps that open those files as part of normal work. Auto-quarantine on a restricted cloud-sync app moves the file to an admin folder and can drop a placeholder .txt so OneDrive.exe does not toast forever.

Evidence collection to Azure Storage, always-on diagnostics, and the full Activity explorer attribute list are operational follow-ons. Just-in-time protection has its own Learn articles. Configure those in the next chapter. This chapter's settings job is: classification bandwidth, share coverage, path exclusions, browser/domain lists, authorization groups, Always audit, and the Windows Server enable switch.

Loading diagram...
Endpoint DLP settings feed every Devices policy
Test Your Knowledge

A Devices DLP rule uses an exact data match sensitive information type. Laptops classify built-in credit card numbers but never match the EDM SIT. Advanced classification scanning and protection is off. What should you do first?

A
B
C
D
Test Your Knowledge

Endpoint DLP Service domains is set to Allow and only sharepoint.com is listed. A Devices rule sets Upload to a restricted cloud service domain to Block. A user uploads a matching file to github.com in Microsoft Edge. What happens?

A
B
C
D
Test Your Knowledge

You want Devices DLP to evaluate new files users save on mapped network drives. Which Microsoft-documented configuration is required?

A
B
C
D