Insights & News
Microsoft Purview DLP for Australian SMEs
- September 30, 2026
Microsoft Purview data loss prevention lets you write policies that detect sensitive information in Exchange Online, SharePoint, OneDrive and Teams, then warn or block when someone tries to send or share it. If you hold Microsoft 365 Business Premium or E3, you already have it for those locations. What you do not have at that licence level is Endpoint DLP, the part that controls copying to USB, printing and uploads from the device, which needs Microsoft 365 E5 or the Purview Suite add-on.
Key facts
- Purview DLP for Exchange Online, SharePoint Online, OneDrive and Teams is included with Microsoft 365 Business Premium and E3.
- Endpoint DLP requires Microsoft 365 E5, E5 Compliance, or the Purview Suite add-on, per Microsoft's Purview service description.
- From 2 May 2025, Business Premium is no longer eligible for the legacy Microsoft 365 E5 Compliance add-on, and the Purview Suite for Business Premium replaced it, capped at the same 300 user limit as Business Premium.
- Endpoint DLP only applies to devices onboarded to Microsoft Defender for Endpoint, so device onboarding is a prerequisite rather than an afterthought.
- Policies can run in simulation mode, which reports what would have happened without affecting users, and this is where every rollout should start.
- Policy tips shown in Outlook and Office apps are the part users actually notice, and they are the main reason DLP changes behaviour rather than just producing reports.
What does Purview DLP cover at each licence level?
The licensing question is the first thing to settle, because it decides what the project can and cannot do. With Business Premium or E3 you can build policies across email, SharePoint, OneDrive and Teams, using Microsoft's library of sensitive information types plus any custom ones you create. That covers the largest single source of accidental disclosure in Australia, which is email to the wrong recipient.
What you cannot do at that level is control the device. Copying a file to a USB stick, printing it, or uploading it to a personal Dropbox are Endpoint DLP actions and they sit behind E5 or the Purview Suite add-on. For a Business Premium tenant under 300 users, the Purview Suite for Business Premium add-on is the intended path, and Microsoft's own guidance is that you can licence only the users who need it rather than the whole business.
Worth saying plainly: if endpoint control is the requirement and the budget is not there, Sophos Endpoint includes DLP at no extra licence cost and covers the device regardless of your Microsoft plan. We run that combination for a number of clients.
How do you build a Purview DLP policy?
A Purview DLP policy is four decisions: where it applies, what it looks for, what it does, and who it notifies.
Where it applies is the location, for example Exchange email plus SharePoint sites. What it looks for is one or more sensitive information types, with a confidence level and an instance count. What it does is the action, from auditing only, through showing a policy tip, up to blocking with or without an override. Who it notifies covers both the user and the alert that lands with your IT team.
The instance count is the setting that saves most projects. A rule that fires on a single credit card number will bury you. A rule that fires on ten or more, at high confidence, almost always means an actual data extract.
Which sensitive information types matter in Australia?
Microsoft ships Australian specific sensitive information types, and these are the ones we turn on first: tax file number, Medicare number, bank account number, passport number, driver licence number, and company number. For a medical practice, add the health-related types. For a law firm or accounting practice, the higher value work is usually a custom type matched to your own matter or client reference format, because that is what identifies your files as yours.
The one to treat carefully is the driver licence type. Australian licence numbers vary by state and the pattern is loose, so it generates more noise than the others. Raise the instance count or pair it with a second condition.
What goes wrong with Purview DLP rollouts?
Three things, in our experience across Sydney SMEs.
The first is going straight to block. Purview has a simulation mode that shows you exactly what a policy would have caught, and skipping it is how a business ends up blocking its own finance team on day one. Run in simulation for at least a month.
The second is forgetting that Endpoint DLP needs devices onboarded to Defender for Endpoint. We have walked into tenants where the policy was configured, the licence was paid for, and the laptops were never onboarded, so nothing was ever enforced. The console showed a healthy policy and the control did not exist.
The third is nobody owning the alerts. A DLP policy generates a queue, and if that queue has no owner it becomes noise within a fortnight. Either someone internally owns it as a weekly job, or it goes to your MSP as part of a managed service. Both work. Neither happening does not.
Purview DLP or a third party tool?
For most Australian SMEs already standardised on Microsoft 365, start with Purview because the data you care about is already sitting in Microsoft's estate and the policy engine understands it natively. It is the cheapest sensible starting point and, at Business Premium, effectively free.
The honest limitation is that Purview protects Microsoft data on Microsoft devices. If a large part of your workflow lives outside that, or you need device level control without E5, the picture changes and a second tool earns its place. That is a licensing and risk conversation rather than a product preference, and it is worth having before anyone buys anything.
Frequently asked questions
Is Microsoft Purview DLP included in Business Premium?
Yes for Exchange Online, SharePoint Online, OneDrive and Teams. No for Endpoint DLP, which requires Microsoft 365 E5, E5 Compliance, or the Purview Suite for Business Premium add-on. Business Premium has not been eligible for the legacy E5 Compliance add-on since 2 May 2025.
What is the difference between Purview DLP and sensitivity labels?
Sensitivity labels classify a document and can apply protection such as encryption that travels with the file. DLP enforces rules about where content can go, and it can use a label as one of its conditions. The strongest setup uses both: label the data, then write DLP rules that act on the label as well as on content patterns.
Does Purview DLP work on Macs?
Endpoint DLP supports macOS as well as Windows, but the supported channels differ between platforms and macOS coverage has historically lagged. Test against your actual device fleet before assuming a rule behaves the same on both.
How long should a policy run in simulation mode?
At least four weeks, and six is better if the business has monthly cycles such as payroll or end of month reporting. You are trying to see every normal process at least once before you start blocking anything.
Can Purview DLP stop someone emailing data to their personal address?
Yes. An Exchange policy scoped to external recipients will catch sensitive content heading to any address outside your tenant, including a personal webmail account, and can block it or warn the sender with an override. Combine it with Endpoint DLP if you also want to stop the file being copied off the laptop entirely.
If you hold Microsoft 365 Business Premium and have never opened the Purview portal, there is a control in your licence you are not using. We will review your tenant, tell you what is already covered, and build the policies properly.
About the author
Brett Muscio is the Director of 4iT Support Pty Ltd, a managed services provider based in Castle Hill, NSW. He works with SME clients across Sydney, Melbourne, and Brisbane on Microsoft 365 environments, including Purview governance, data loss prevention, conditional access, and Copilot rollouts, with on-site support across the Sydney metro area and remote delivery nationally. Connect on LinkedIn.
Recent Posts
-
How to Write a Data Loss Prevention Policy -
Microsoft Purview DLP for Australian SMEs -
What Is Data Loss Prevention (DLP)? -
Has the Privacy Act small business exemption been removed? -
Microsoft Authenticator Setup for Business -
Windows Hello for Business: Passwordless Sign-In for SMEs -
Microsoft 365 MFA Setup: Security Defaults or Conditional Access -
Microsoft Is Retiring SMS and Voice MFA: What to Do Before February 2027 -
Choosing a Password Manager for Small Business -
Passkeys vs Passwords: What Businesses Need to Know







