Microsoft Purview Data Loss Prevention (DLP) is a powerful solution to monitor and protect sensitive information across devices, services, and applications. However, like any security tool, Endpoint DLP (EDLP) has limitations that organizations should be aware of when designing their data protection strategies. This article outlines key limitations in Endpoint DLP and suggests possible workarounds or complementary solutions.

1. Policy Scoping for Specific Destinations

Limitation

Currently, Microsoft Purview DLP does not support destination-specific policy configurations (e.g., blocking data uploads to a specific website or cloud service).

Workaround

Another solution is to leverage Microsoft Defender for Cloud Apps (MDA). For more granular control, use Microsoft Defender for Cloud Apps to detect and block unsanctioned apps and URLs. This includes real-time session control and app governance.

2. Screenshot Prevention

Limitation

Endpoint DLP cannot block screenshots or screen clipping tools on endpoints natively.

Workaround

Important. This protection does not work in web-based apps, including Outlook on the web (OWA). Users can still take screenshots of sensitive data when viewed in a browser.

3. Manual Entry of Sensitive Data

Limitation

Endpoint DLP does not monitor or block sensitive data that users manually type into web forms or applications.

Clarification

Preview Feature (as of June 20, 2025)

Microsoft has introduced "Collection policies", a preview capability designed to detect manually entered sensitive data. Key points.

4. Raw Packet Inspection and Encrypted Traffic Analysis

Limitation

Endpoint DLP does not support deep packet inspection or encrypted traffic analysis.

Clarification

By design, Microsoft Purview Endpoint DLP does not work at the network layer. It does not perform raw packet inspection or analyze encrypted traffic. Instead, it operates at the application and file level, focusing on user interactions with sensitive data on supported endpoints. This means it relies on file classification and user activity monitoring, based on conditions defined in the Purview portal. Actions like allow or block are triggered when the data matches the configured DLP policies

5. Handling Password-Protected Files

Limitation

DLP cannot scan the contents of encrypted or password-protected files.

Workaround

6. Blocking File Transfers to Mobile Devices (MTP/PTP)

Support

Limitation: Microsoft Endpoint DLP supports blocking file transfers to mobile phones and cameras that connect via MTP/PTP protocols.

Recommendations

To strengthen your Endpoint DLP deployment.