> For the complete documentation index, see [llms.txt](https://helpdesk.augmentt.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://helpdesk.augmentt.com/stonly-import-secure-purview/purview-data-loss-prevention.md).

# Purview Data Loss Prevention

Augmentt integrates with Microsoft Purview and allows you to build, template and deploy Data Loss Prevention (DLP) policies across your tenants without working in each customer's Purview portal.

From the **Secure > Purview > Data Loss Prevention** section you can:

* Import an existing Purview DLP policy from a connected tenant and save it as a reusable template
* Group templates into baselines so a standard DLP posture can be applied to every new customer
* Deploy a policy or a whole baseline to a selected tenant
* Deploy in simulation mode first, so you can measure impact before anything is enforced
* Track policy sync status and simulation progress from the policies list

The page has two tabs:

* **Policies** — DLP policies currently deployed in the selected tenant
* **Templates** — your library of reusable DLP templates and baselines

**Access.** You need the Manage permission on Purview to create templates or deploy policies. With read-only access you can view policies but the Deploy button is hidden.

**Licensing.** Microsoft Purview DLP requires appropriate Microsoft 365 licensing in the customer tenant. Several locations carry additional Microsoft-side prerequisites, which Augmentt warns you about at deployment time (see Choosing locations).

## Creating a DLP template

Templates are exported Purview DLP policies that can be reused and deployed across tenants through Augmentt.

Start by creating or configuring the DLP policy you want to standardise in a connected Microsoft tenant, then import it:

1. Navigate to **Secure > Purview > Data Loss Prevention**.
2. Open the **Templates** tab.
3. Click **Create New > Template**.
4. Select the tenant to import from.
5. Select the existing DLP policy you want to import.
6. Name your template and add a description if needed.
7. Click **Create**.

The template is now stored in Augmentt and can be deployed to any other connected tenant.

**What a template does and doesn't carry.** A template stores which locations it covers, along with rule logic, conditions and actions. It does not store tenant-specific location assignments — the individual users, groups, sites, instances or repositories inside those locations. Augmentt states this on the template itself: "Tenant-specific location assignments are not saved in templates." So you pick the locations once on the template, and resolve who or what inside them each time you deploy.

## Editing a DLP template

Open a template from the Templates tab to change:

* Name and description
* Locations — which locations the template covers

At least one location is required. A template with no locations selected cannot be saved.

Editing locations on the template itself means you no longer have to correct the location set on every single deployment. Get the template right once, and each deployment starts from the correct footprint.

Changing locations on an imported template carries a warning. Augmentt flags that changing locations may produce rules incompatible with the new policy scope — a rule written for Exchange email may not make sense once the location set changes. Re-read the rules after widening or narrowing a template's locations rather than assuming they carry over cleanly.

## Creating a DLP baseline

Baselines are a collection of DLP templates that deploy together. Use them to define a standard data-protection posture and apply it consistently at customer onboarding.

1. Navigate to **Secure > Purview > Data Loss Prevention > Templates**.
2. Click **Create New > Baseline**.
3. Select the DLP templates you want to include.
4. Name the baseline and add a description.
5. Click **Create**.

You can create multiple baselines to support different customer tiers or compliance frameworks.

## Deploying a DLP policy

1. Navigate to **Secure > Purview > Data Loss Prevention**.
2. Select the tenant you want to deploy to.
3. Click **Deploy** in the upper-right corner and choose **Policy**.
4. Select the DLP template to deploy.
5. Give the policy a name and description as it should appear in Purview.
6. Choose the locations the policy applies to, and scope each one.
7. Choose the deployment mode (see the next section).
8. Review the configuration and the rule names that will be created.
9. Click **Deploy DLP policy**.

To deploy a whole baseline, choose **Deploy > Baseline** instead and select the baseline. You are asked to configure locations for each policy in the baseline before the review screen.

## Choosing a deployment mode

Augmentt exposes the same three modes Purview offers. Pick the one that matches your change-control process.

**Run the policy in simulation mode** — Purview shows you items that match the policy's conditions so you can evaluate its impact. Your data is not affected and the policy stays off while in simulation.

Two extra options become available in this mode:

* Show policy tips while in simulation mode — users see the policy tip without the action being enforced
* Turn the policy on if it's not edited within fifteen days of simulation — Purview automatically promotes the policy to enforcing after 15 days

**Turn the policy on immediately** — after creation the policy is turned on and begins enforcing changes once applied to the location.

**Leave the policy turned off** — the policy is created but inactive. Decide to test or activate it later.

**Recommended practice.** For a tenant whose data you do not know well yet, deploy in simulation mode with policy tips turned off, review simulation results after a few days, then edit the policy to On.

## Choosing locations

DLP policies apply to one or more locations. Augmentt supports the full Purview location set:

* Exchange email
* SharePoint sites
* OneDrive accounts
* Teams chat and channel messages
* Devices
* Microsoft Defender for Cloud Apps (Instances)
* On-premises repositories
* Applications
* Microsoft 365 Copilot and Copilot Chat
* Fabric and Power BI workspaces
* Microsoft Foundry
* Managed cloud apps
* Inline web traffic

Each location can be left at its "everything" scope (All users & groups, All sites, All groups, All devices, All instances, All repositories, All workspaces, All connected apps, All accounts) or narrowed to specific users, groups, sites or instances, with optional exclusions.

Some locations carry extra prerequisites. Augmentt surfaces these as warnings in the deployment wizard:

* **Fabric and Power BI workspaces** — pay-as-you-go billing must be set up in the tenant before this location can be configured
* **Managed cloud apps** — requires a Conditional Access policy with application control, and Edge for Business in-browser protection
* **Inline web traffic** — if the policy includes unmanaged apps in Edge for Business, additional policies outside Purview will be created to apply it. If you integrate with non-Microsoft partners, they may access and store some policy configuration, including user identifiers.
* **Changing locations on an imported policy** — Augmentt warns that changing locations may produce rules incompatible with the new policy scope

Application names vary between tenants. For managed-app policies, Augmentt shows you which apps the original policy included, but you must reselect them for the target tenant because application names and IDs differ from tenant to tenant.

## Avoiding name conflicts

Purview requires unique names, and this is the most common cause of a failed deployment. Augmentt validates before you deploy:

* **Policy name** — if a DLP policy with that name already exists in the target tenant, you are asked to choose a different name before deploying.
* **Rule names** — the review screen lists every rule name that will be created. Rule names must be unique across all DLP policies in the tenant. If any already exist, Augmentt names them and blocks the deployment until you remove the existing policies that own those rules, or deploy to a different tenant.

If rule names could not be validated, Augmentt warns you that any naming conflict will be rejected by Microsoft.

## Monitoring policies after deployment

The Policies tab shows each deployed policy with:

* **Priority** — Purview evaluation order
* **Mode** — On, In simulation with notifications, In simulation without notifications, or Off
* **Policy sync status** — Sync in progress or Sync completed
* Locations, Rules and Admin units
* Email notifications

For policies in simulation, a **Simulation progress** column reports Searching for matches, {matched} of {total} items matched, or No match found, alongside a simulation status of Simulation in progress, Simulation completed or Simulation expired.

Use **View rule** on a policy row to inspect the conditions and actions of an individual rule.

## Changing policy priority

Priority decides the order Purview evaluates DLP policies in, and it can now be changed straight from the policies table without opening the full edit flow.

Click the Priority value on a policy row to open a quick-actions menu:

| Action                           | Effect                                                                 |
| -------------------------------- | ---------------------------------------------------------------------- |
| Move to top (highest priority)   | Evaluated first                                                        |
| Move up                          | One position higher                                                    |
| Move down                        | One position lower                                                     |
| Move to bottom (lowest priority) | Evaluated last                                                         |
| Assign priority                  | Opens the Edit Policy modal so you can type a specific priority number |

The menu only offers moves that would actually do something — Move to top and Move up are hidden on a policy already at the highest priority, and Move down and Move to bottom are hidden on one already at the lowest.

Move actions apply immediately. A loading indicator appears next to the priority value while Microsoft applies the change, the table refreshes when it completes, and a confirmation or error message tells you the outcome.

Priority is also now visible and editable inside the Edit DLP Policy modal, and shown read-only in the View Policy modal and the deployment review step.

Priority matters most where policies overlap. If two policies cover the same location and content, the higher-priority one determines the action taken. Reordering is the fix when a permissive policy is shadowing a restrictive one — and it's a far less risky change than rewriting rules.

A failed move is not a partial move. If Microsoft rejects the reorder you'll see an error and the original order stands. Re-check the table before retrying rather than assuming the change half-applied.

## Troubleshooting a failed deployment

* **"A DLP policy with this name already exists in this tenant"** — rename the policy on the deployment screen.
* **"The following DLP rule names already exist in this tenant"** — remove the existing policy that owns those rule names, or deploy to a different tenant.
* **"Microsoft rejected this policy but didn't return a specific reason"** — review the policy configuration directly in Purview, then contact Augmentt Support with the policy name.
* **A location warning blocks deployment** — complete the Microsoft-side prerequisite (pay-as-you-go billing, Conditional Access application control, or Edge for Business protection) and retry.
* **"{customer} is not authorized for this feature"** — the customer is not entitled to the Purview module in Augmentt. Contact your Augmentt account team.

If a policy deploys but does not appear to take effect, allow time for Policy sync status to reach Sync completed. Purview propagation is not instant.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://helpdesk.augmentt.com/stonly-import-secure-purview/purview-data-loss-prevention.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
