Infrastructure / Security and Identity / Data Loss Prevention
Preventing data loss doesn't start with a ban.
It starts with knowing what sensitive information you have and where it is located.Microsoft Purview Data Loss Prevention It identifies sensitive information and prevents it from being shared: a credit card number in an email, a payroll file uploaded to a shared folder accessible to everyone, a contract copied to a USB drive, or a customer database extract pasted into an AI assistant open in a tab. We carry out this work in the order that keeps it under control: classification, then observation without blocking, then rules.
The Paths Taken by Sensitive Information
Almost none of these logouts are malicious. They are normal work-related actions performed by people in a hurry, using tools that allow them to do so. That is precisely why a memo won’t stop them.
An attachment is sent to the wrong recipient
The automatic recipient suggestion feature suggests a person with the same name or a client's address instead of a colleague's. The message was sent before I had a chance to proofread it.
An email rule checks the attachment before sending, notifies the sender, and blocks the message if you request it.
A document can be shared with the entire company via a link
The “Entire Organization” link is the fastest default option. A personnel file, a fee schedule, or an application form becomes visible to 500 people without anyone intending it to be.
A rule regarding SharePoint and OneDrive detects sensitive content and restricts access to external users or everyone.
When an employee leaves the company, they take their files with them
Copies to a USB drive, an external hard drive, or a personal email address multiply in the days leading up to a departure, and no one checks them at that time.
A policy on the computers monitors copying to a USB drive, network sharing, printing, and the clipboard.
A file excerpt is pasted into an AI assistant
An employee wants a summary, a rewritten version, or a translation. He opens a new tab, pastes two pages of a contract, and the department that receives this text is not covered by any of your company’s contracts.
This is the most recent path, and the one on which Microsoft is making the most progress right now.
A file server stores things that no one looks at anymore
Historical shared folders contain accounting export files, copies of identification documents, and database backups—all stored in folders whose owners left the company long ago.
The Purview scanner reads these shares and the SharePoint installed on your premises, and applies the same rule as it does online.
A third-party app is receiving more than expected
A signature tool, a billing connector, a meeting note-taking assistant: each user is granted access once, and can then view everything their permissions allow.
Purview treats non-Microsoft applications as a separate policy location—first read, then block.
Depending on the location, a protection rule does not take effect at the same time
Microsoft distinguishes three stages in the life of a file, and this distinction determines what a rule can do. It also explains the one thing no tool can do: retrieve a message that has already been sent.
The file is sitting somewhere, and no one touches it
SharePoint, OneDrive, file servers, and SharePoint on-premises, workspaces Microsoft Fabric, and connected non-Microsoft applications.
The content is analyzed where it is stored. Even a belated discovery is still useful: the shared folder closes, and the file is moved to a quarantine folder.
Can be made up later.
The file or text is being sent
Email, chats, and channels Teams; forwarding to an unmanaged app from the browser or from the network.
This is the only time when the decision must be made before the action takes place. A rule that wasn't in effect at that exact moment won't get a second chance.
Only one chance to act.
Someone has the file open in front of them
Computers Windows and registered Macs, Word, Excel, and PowerPoint, Microsoft 365 Copilot.
Copying to a USB drive, printing, the clipboard, Bluetooth, and remote desktop sessions are each a separate action that can be audited, flagged, or blocked individually.
The thinnest—and the one that takes the longest to adjust.
All three are governed by a single rule, and that’s the beauty of the system: the same definition of “payroll file” is used for email, sharing, SharePoint and USB drives, without having to be written three times. The actions, however, differ from one location to another—not all of them are available everywhere, and we’ll let you know which ones are missing where you might need them.
How We Do It, in Five Steps
Order is non-negotiable, and that’s the whole point. A company that writes its blocking rules first ends up disabling them within a month, because they stop legitimate work before they stop anything else.
Inventory of Sensitive Information
Which categories warrant a rule: social security numbers, payment card data, personnel files, health data, contracts, intellectual property, and customer lists. Microsoft provides more than 300 ready-to-use types of sensitive information, including Swiss social security numbers and Swiss mailing addresses; you can also create your own definitions.
A good list is a short one. A company that lists twenty categories provides less protection than one that lists four and sticks to them.
Confidentiality labels: When They're Useful
A tag follows the document—even when it leaves your environment—and enables it to be encrypted. This is the right solution for a small number of documents that are shared—such as proposals, merger filings, and construction plans.
This is not a mandatory requirement. We protect thousands of files based solely on their content, without requiring the user to make any decisions at all. We only apply labels when someone is actually able to choose the right one.
Simulation mode: everything is measured, nothing is restricted
A rule in simulation mode reads everything, counts everything, reports everything, and does not apply any of its actions. This is where we discover what no workshop can predict: the department that sends a file of AVS numbers to the pension fund every week—and has good reasons for doing so.
This is the step that projects tend to skip—and it’s the one that saves them. We hold off for several weeks, until at least one billing cycle, one month-end closing, and one payroll have been completed.
Switching to blocking mode without activating everything on the same day
First, the warning is activated, with the option to override it by providing a reason: the justification is recorded, and it’s better than a block, because it teaches you something. A block with no exception follows, applied only to the rules that the simulation has shown do not bother anyone.
Each rule has its own effective date. A project that switches over all at once that same morning will no longer know, the next day, which of the eight rules stopped billing.
Day-to-Day Operations
A rule applies: alerts are addressed, false positives are corrected, new sharing services emerge, and definitions are refined. Without this work, a dashboard fills up with alerts that no one reads anymore—which is the same as not having installed anything at all.
This work can be handled in-house or outsourced. We’re capable of doing both, and that’s what allows us to advise you based on your specific needs rather than on what we know how to sell.
The opposite is also true. If you only have one type of information to protect and it’s only shared via email, an email policy is all you need—it can be set up in a few days, and it’s already included in the Microsoft 365 subscription you’re paying for. We’d rather tell you that than try to sell you the five-step process.
Places Where a Protective Rule Applies
A single protection rule applies to one or more of these locations. The first two cover most cases and are included in standard Microsoft 365 subscriptions; the others require a more comprehensive subscription, and we make that clear before offering them.
Email, both incoming and outgoing
The message body, subject line, headers, and attachments. Beyond blocking: encrypt, quarantine, add your supervisor as a recipient, or ask for their approval before sending.
SharePoint and OneDrive
Files that have already been uploaded are scanned, not just new ones. A rule can restrict access to external users, a specific domain, or everyone except authorized users.
Computers connected to the service
Under Windows such as macOS. USB drives, network sharing, printing, clipboard, Bluetooth, remote desktop sessions, prohibited applications, and prohibited browsers. Each action can be audited, flagged, or blocked individually.
Microsoft Teams : Conversations and Channels
The message containing sensitive information is not displayed to the recipient. Note: In this case, a rule is based on the types of sensitive information, not on confidentiality labels.
File servers and SharePoint installed on your premises
Microsoft Purview 's scanner (Information Protection ) scans shares and libraries hosted on your own servers and applies the same definitions as it does online. It is deployed separately.
The workspaces where your dashboards live
Microsoft Fabric and Power BI are standard locations. A dashboard often brings together information that ten separate files did not provide: it is the most commonly overlooked part of an inventory, and one of the most sensitive.
Connected non-Microsoft services
By Microsoft Defender for Cloud Apps, a third-party service becomes a rule-based setting: read-only first, then blocking, with a distinction between managed and unmanaged computers.
Microsoft 365 Copilot
A separate section: We restrict what the assistant is allowed to read when generating its response, based on confidentiality labels and types of sensitive information.
Web traffic to unmanaged services
Two options: Microsoft Edge for Business on a managed computer, or a network-level scan that covers more than 34,000 services in the Defender for Cloud Apps catalog.
How Artificial Intelligence Is Changing Things
The issue is no longer the USB drive. It’s the tab open next to the document, and the fact that a company employee—who is fully within the scope of their employment—can read everything that their user access rights allow them to access. The two issues are distinct, and they cannot be addressed in the same place.
Limit the content that Copilot is allowed to use
A rule can exclude documents with a specific label or containing a specific type of sensitive information from the assistant's responses. This setting answers the question, "So, is it going to read everything?"
Preview location. Restricting the processing of files and emails requires a Microsoft 365 E5 subscription or equivalent.
See what your employees are typing in the assistant
Text entered into Copilot and Copilot Chat can be reviewed just like an email. This is the only way to know for sure whether a portion of a contract has been copied into it, rather than just assuming it has.
Available to all Copilot and Copilot Chat users, with no additional subscription required.
Pasting into an assistant that isn't yours
ChatGPT, Gemini, DeepSeek, and Copilot are specifically targeted—either by Microsoft Edge ( for Business ) on a managed computer or by monitoring network traffic. You can audit, issue warnings, or block them.
This is a preview version, and billing is based on usage. Therefore, this is not a setting you need to enable—it’s a budget line item you need to decide on.
Screenshots, and What They Should Not Contain
A rule condition detects whether a sensitive document or message Teams is present in a snapshot and excludes it. This is useful when the feature is enabled on newer computers.
Pre-release version, available Windows only.
Data loss prevention prevents data from leaving the company. Access rights determine what a person can access.
A contract-based business assistant, set up with permissions that have never been reviewed, provides access to more content than a consumer-grade tool that no one has ever updated. No data loss prevention policy can fix this, because nothing actually leaves the system: the information is simply viewed by someone who shouldn’t have had access to it. That’s a different task, and it takes priority.
Reinstating Access Rights Before Copilot What’s Covered by Your Contract—and What Isn’t Regulating AI tools that no one has validated Agent governance
A rule that blocks too much is disabled within a month—and the company is then less protected than before, because it believes it is protected.
We don't start with computers
This is the most visible and most expensive part: machine registration, fine-tuning, and processing exemptions. Email and document sharing cover a wider range of situations, cost less, and are often already included in what you pay.
We refuse to activate a block without a simulation
Not out of caution: because no one knows the list of legitimate ways to send a sensitive file within their own company. It has to be learned; it can’t be guessed.
An alert dashboard that no one reads doesn't protect anything
This is the most common outcome of a technically successful implementation. The question that needs to be decided before getting started is who will handle the alerts on Tuesday morning.
We'll let you know when your current subscription is sufficient
Much of this work is already included in standard Microsoft 365 subscriptions. Understanding how to make the most of both tiers is what allows us to advise you on your requirements rather than on upgrading to a higher tier.
What You Need to Know Before You Begin
Six points that determine the budget and schedule. None of them is an obstacle: these are the areas where a project goes off the rails when they haven’t been addressed at the first meeting.
What's Already Included in Your Subscription
Email rules, SharePoint and OneDrive are included in Microsoft 365 E3, Business Premium, and even in Exchange Online Plan 2 or SharePoint Plan 2 on its own. That’s the first benefit, and it doesn’t cost anything extra.
Features that require Microsoft 365 E5 or an add-on: computers, conversations Teams, web traffic, restricting what Copilot reads, enriched alerts in Outlook, and adaptive protection that tightens rules for a person whose behavior changes. Transparency: We assess what you already have before making any recommendations, and sometimes the answer is “nothing to buy.”
What Content Analysis Misses
On a computer, anything that is never saved to the hard drive is not scanned: a document that is opened and then sent directly to a USB drive is not subject to content scanning. The list of scanned file formats is long but finite—industrial design files or proprietary databases are not included. And a label added by another company is not recognized.
The solution: each of these three scenarios has its own solution, and we include them in the scope of work. Formats that haven’t been analyzed are handled by a rule that prohibits taking any action without first reading the content—a less nuanced approach, but an effective one, and often exactly what’s needed for a project plan.
False reports, and the work they entail
A 16-digit number isn't always a payment card. An order reference, a machine ID, or a serial number can trigger rules that are too broadly defined, and every unnecessary trigger wears down your teams' patience a little more.
The threshold: that is exactly what simulation mode measures, and what the thresholds control. A rule that is triggered only after ten occurrences in the same file behaves very differently from a rule that is triggered after the first occurrence.
An alert has a limited duration
An alert remains visible for thirty days in the Purview dashboard and for six months on the Microsoft Defender portal. The activity explorer shows the last thirty days. For a case that goes to trial two years later, that’s not enough.
Transparency: Events are also logged in the audit log, and data that needs to be retained for a longer period is exported. This is decided at the outset—data that hasn’t been exported cannot be retrieved.
Where Is Purview's Data Stored, and the Swiss Question
Switzerland is one of the countries covered by the Microsoft 365 Advanced Data Residency option, which specifically addresses data loss prevention. There are two requirements to keep in mind before discussing this with management: the commitment requires that 100% of the tenant’s paid licenses be covered by the option, and the migration migration of existing data can take up to twelve months.
The first step: We start by identifying where your data is currently located in the administration center. Many companies discover at this point that they’re already where they wanted to be, and that the question doesn’t even arise.
What's in the preview version, and what that means
Copilot as a rule location, monitoring web traffic to unmanaged services, and the condition on Windows are announced by Microsoft as preview features. Preview features are subject to change, and web traffic monitoring is billed on a pay-as-you-go basis.
The rollout: A pre-release version works very well when tested on a small group, and that’s how we proceed—never company-wide, and never as the basis for a written commitment to a client or auditor.
Questions We Are Asked
Seven questions that have come up often enough to warrant a written response. The first two concern products that Microsoft has discontinued or renamed: if you came here looking for information about them, you'll find the answer here.
"We had Windows Information Protection on our computers. What happened to it?”
Microsoft announced that it had reached end-of-life in July 2022, and it is being removed from Windows 11 starting with version 24H2. Microsoft explicitly refers to Microsoft Purview Information Protection and Microsoft Purview Data Loss Prevention. If your computers still have it installed, it’s because they’re running a version of Windows that hasn’t removed it yet: the replacement is being prepared without urgency, but before the next system upgrade.
"And Microsoft Information Protection —is that something else?"
That’s the old name. The product is now called Microsoft Purview Information Protection : same privacy labels, same encryption, same file server scanner. The acronym MIP is still used in older documentation and in certain interfaces.
"Does this work on a Mac?"
Yes, across the last three major versions of macOS, with some real differences: protecting files on an offline computer and blocking applications not on the allowed list are features available only on Windows, and remote desktop sessions are not monitored. We compile the list of discrepancies beforehand, not afterward.
"Our file servers aren't online. Are they covered?"
Yes, using the scanner from Microsoft Purview Information Protection , which is installed on your premises, scans your file shares and the SharePoint hosted on your servers, and applies the same definitions. It’s deployed separately, and that’s a project in its own right: you need to provide it with a service account, read permissions, and processing time.
"Should our computers be managed by Intune ?"
No. Registration is performed via a local script, through Group Policy, or Configuration Manager, Intune or a script designed for virtual machines. And if your machines are already connected to Microsoft Defender for Endpoint, they’ll appear automatically—all you need to do is enable monitoring.
"Is anything off-limits from day one?"
No, and that's not desirable. A rule created in simulation mode does not execute any of its actions; it simply counts and reports. The decision to block is a separate one, made rule by rule, once you've reviewed the simulation's findings.
"How long does it take for the adjustment to take effect?"
Allow about an hour for an activated or modified rule to take effect throughout the service; the affected files will then be reevaluated the next time they are accessed. A change to the group of authorized users takes twenty-four hours. This is not instantaneous: a test performed within five minutes does not prove anything.
In addition to preventing data loss
What we protect lives elsewhere and can be reached in a different way. Here’s where to find the rest.
Where the decision is made to share too broadly
Access permissions, sharing links, and what you need to set up before opening a wizard on your documents.
View the page SharePoint Microsoft CopilotWhat the assistant can access—and what it cannot
Where do the questions asked of the assistant go, what you need to have done before opening it, and the gap between the demonstration and Monday morning.
See the Copilot page IntuneComputer Registration, and What It Enables
The technical requirements for computer rules, and everything else that centralized machine management makes it possible to maintain.
View the page Intune Conditional AccessWho is logging in, from where, and on which device
The other half of the issue: preventing access rather than departure. The two are addressed separately and complement each other.
See Conditional Access Managed ServicesWhen sorting through alerts becomes too costly
Contract-based operation, with written time slots and a designated contact person—including for alerts regarding these rules.
See IT Outsourcing GlossaryThe terms used in this field, explained in plain language
168 definitions, including the 12 Microsoft products whose names have changed since 2020.
See the glossaryLet's talk about your sensitive information
Tell us about the three pieces of information you don't want to lose
What would cause the most damage if it were to leak from your company, the tools through which it currently circulates, and the name of the person who would receive the alerts. With these three elements, the first meeting is already productive.
What we offer is the opportunity to meet with the engineers who will do the work. The scope of work includes inventory, simulation, and threshold adjustment. The preliminary discussion, however, is free and is often enough to determine whether the project fits within your current subscription.
Renens, Sion, Châtel-Saint-Denis
Microsoft Solutions Partner, operating in French-speaking Switzerland since 1995. A single point of contact from inventory to alert triage.
Renens VD +41 21 806 37 15
Sion VS +41 27 552 00 22
Châtel-Saint-Denis FR +41 26 322 59 05

