A unified data governance solution that helps manage, protect, and discover data across your organization
The likely issue is the rule conditions. For upload blocking to a restricted cloud service domain, the documented pattern is to use a rule that detects sensitive content and then apply Audit or restrict activities on devices with Upload to a restricted cloud service domain or access from an unallowed browser. The documented steps use Content contains with a Sensitive info type, not File type or Document size as the trigger.
Check these areas:
- Service domains configuration
- In Microsoft Purview portal > Data loss prevention > Settings > Data Loss Prevention > Endpoint settings > Browser and domain restrictions to sensitive data > Service domains:
- Set Service domains to Block.
- Add the WhatsApp Web domain under Add cloud service domain.
- Save the configuration.
- Sensitive service domain group
- In the same area, create a Sensitive service domain group.
- Add the domain and select the correct Match type.
- URL matching supports multiple websites and wildcards for subdomains.
- Policy scope
- Create or edit the DLP policy so it is scoped only to Devices.
- Set Admin units to Full directory.
- Rule design
- On Define policy settings, use Create or customize advanced DLP rules.
- Under Conditions, add Content contains.
- Add a Sensitive info type.
- Under Actions, add Audit or restrict activities on devices.
- Under Service domain and browser activities, choose Upload to a restricted cloud service domain or access from an unallowed browser.
- Set it to Audit only, Block with override, or Block as needed.
- Use + Choose different restrictions for sensitive service domains and add the sensitive service domain group.
- Browser support
- Domain restriction enforcement applies to uploads through Microsoft Edge, or Google Chrome / Mozilla Firefox only when the Microsoft Purview browser extension is installed.
- Since testing was done in Edge, that part aligns with supported behavior.
- What to change in this case
- Replace the current rule logic based on File Type or Document Size with a rule based on Content contains and a Sensitive info type.
- Then retest the upload in Edge.
- Expected behavior
- When the file matches the DLP rule and the upload target is a restricted service domain, the configured action should apply.
- If a browser is configured as unallowed, users are prompted to open the file through Microsoft Edge.
A practical test is to use a file that contains a known sensitive info type covered by the rule, then upload it to WhatsApp Web in Edge after policy sync completes.
- Configure endpoint data loss prevention settings
- Help prevent sharing of sensitive items with unauthorized cloud apps and services
- Help prevent sharing of sensitive items with unauthorized cloud apps and services
- Help prevent risky user activity by monitoring or restricting access to sensitive service domains