A unified data governance solution that helps manage, protect, and discover data across your organization
Microsoft Purview DLP: Unable to Block File Uploads to Specific Websites
I'm currently working with Microsoft Purview's Data Loss Prevention (DLP) and facing an issue where a policy designed to block file uploads to specific websites is not working as expected.
🔍 Here's the situation:
- I've configured a DLP policy to prevent file uploads to certain websites (e.g., Dropbox, Google Drive, etc.).
The policy is intended to block the action entirely, not just audit it.
Despite this, I'm still able to upload files to the targeted sites from user devices.
The devices are onboarded to Microsoft Defender for Endpoint (MDE) and report as healthy.
The DLP policy is applied to "Devices", and the conditions should match.
I've also configured the "Unallowed URLs" under endpoint DLP settings, but uploads are still going through.
- We're primarily using Microsoft Edge and Google Chrome.
- Windows 10/11 is used to all over the organization.
âś… What I've checked so far:
Policy is not in audit mode
Devices are reporting and synced
The sensitive info types and conditions are set appropriately
URLs are entered correctly with wildcards where needed (e.g., https://*.dropbox.com/*)
- DLP policies are synced via the Microsoft 365 compliance portal (Microsoft Purview)
âť“ My Question:
What might I be missing here? Are there additional configurations required to fully block file uploads via browser? Is this behavior expected under any conditions—like a specific app, browser type, or URL pattern?
Also, the same policy try to block file uploads on Generative AI Websites (https://learn.microsoft.com/en-us/purview/ai-microsoft-purview-supported-sites), but it is not working as expected as well.
I'd really appreciate any guidance, tips, or documentation references that could help me troubleshoot and get this DLP policy working as intended.
Thanks in advance!