0:00–0:10
Recap
0:10–0:35
Lecture
0:35–1:45
Lab 7-D
1:45–1:55
Bonus
1:55–2:00
Debrief
0:00 – 0:10Recap · 10 min

Day 3 review & the data exfiltration gap

0:10 – 0:35Lecture · 25 min

DLP architecture — conditions, actions, policy tips, and endpoint DLP

How a DLP policy evaluates content

Content created
Email, file, chat, etc.
DLP scans
Checks conditions: SIT matches, volume, recipient, location
Match found?
Conditions met — rule fires
Action taken
Block, restrict, notify, audit
+
Policy tip
User notified inline
WorkloadWhat DLP scansActions availableWeeks 3–6 connection
Exchange OnlineEmail body, attachments, subjectBlock, block with override, notify, encryptWeek 3 — Exchange admin, mail flow rules
SharePoint OnlineDocument library files, list itemsBlock external sharing, restrict access, notifyWeek 4 — SharePoint sites, external sharing
OneDriveFiles in OneDrive (including KFM-redirected Desktop/Docs)Block external sharing, restrict access, notifyWeek 4 — OneDrive, Lab 6-C KFM
TeamsChat messages, channel posts, file attachmentsBlock message, notifyWeek 5 — Teams policies, channels
Endpoint devicesFile operations on enrolled devices (copy, print, upload, USB)Block, audit, warn with overrideWeek 6 — Intune, Lab 7-B — MDE onboarding
Instructor note: The policy tip demonstration is the most impactful moment of Day 4. Paste a fake credit card number into an Outlook email draft on WIN-CLIENT-01 — after a few seconds, a yellow policy tip banner appears at the top of the compose window, before the email is sent. This makes DLP feel real and immediate. Fake card numbers: Visa test — 4111 1111 1111 1111, Mastercard test — 5500 0000 0000 0004. Both are valid SIT matches but not real cards.
0:35 – 1:45Guided lab · 70 min

Lab 7-D: Financial data DLP policy and endpoint DLP

Students enable the audit log (required for DLP alerts), create a cross-workload DLP policy protecting credit card and NZ bank account data, test it with a synthetic document, configure endpoint DLP to block USB transfers, and review DLP alerts in the Purview compliance portal.

DLP policy propagation time: After saving a DLP policy, it can take up to 1 hour to fully propagate across all workloads. Policy tips in Outlook typically appear within 5–15 minutes. SharePoint and Teams enforcement may take longer. If a policy tip doesn't appear immediately, wait 10 minutes and retry.
The Week 3–6 payoff: One DLP policy now governs all five workloads simultaneously. The Exchange mailboxes configured in Week 3, the SharePoint libraries from Week 4, the OneDrive KFM-redirected folders from Lab 6-C, the Teams channels from Week 5, and the Intune-managed endpoint from Week 6 are all under a single data governance rule. This is the unified M365 governance stack in action.
1:45 – 1:55Bonus · 10 min

⭐ Bonus: Custom SIT and DLP activity explorer

⭐ Bonus A — Create a custom Sensitive Information Type
  • Navigate to purview.microsoft.comData classification → Sensitive info types → + Create sensitive info type
  • Name: LL — Lakeview Employee ID. Create a pattern that matches a fictional Lakeview Logistics employee ID format: LL-\d{5} (LL- followed by exactly 5 digits, e.g. LL-10023)
  • Add a supporting keyword element: require the word "Employee" or "ID" within 300 characters of the pattern match to reduce false positives
  • Test the SIT using the test panel — paste Employee LL-10023 and confirm it detects. Then add the SIT to the LL — Financial Data Protection policy as an additional condition
  • Lab Journal: what are the risks of a regex that is too broad? What are the risks of one that is too narrow? How would you tune a custom SIT in production?
⭐ Bonus B — DLP Activity Explorer
  • Navigate to purview.microsoft.comData classification → Activity explorer
  • Filter by: Activity type = DLP rule matched. Review the events generated by today's lab tests
  • Filter by: Workload = Exchange. Then filter by Workload = SharePoint. Compare the event formats
  • Lab Journal: explain the difference between DLP Alerts (in Data loss prevention → Alerts) and Activity Explorer events. When would you use each? What does Activity Explorer show that Alerts doesn't?
1:55 – 2:00Debrief · 5 min

Reflection & preview

Learning outcomes — by end of Day 4, students can…

Explain DLP architectureDescribe SITs, rules, conditions, actions, and policy tips in a DLP policy
Create a DLP policyBuild a cross-workload financial data policy covering Exchange, SharePoint, OneDrive, Teams, and Devices
Test a DLP policyGenerate synthetic sensitive data and verify policy tip and block behaviour across workloads
Configure endpoint DLPAdd USB transfer blocking to an existing DLP policy for Intune-managed devices
Review DLP alertsNavigate Purview DLP alerts and read alert metadata including matched content and workload
Explain the workload connectionDescribe how DLP unifies governance across all workloads configured in Weeks 3–6

What you need ready

purview.microsoft.com accessible WIN-CLIENT-01 enrolled in Intune and onboarded to MDE (Lab 7-B) All 10 user accounts with E5 licences assigned Finance SharePoint site active (from Week 4) Outlook accessible on WIN-CLIENT-01 Unified audit log enabled (Lab 7-C Step 3 or enable now)
Day 5 →Week 7 Overview