What's changed: Created MS-102 Chapter 5 (domain: Manage compliance by using Microsoft Purview). Information protection (sensitive information types keyword/regex, sensitivity labels classify/encrypt/marking and label policies, Content/Activity explorer), data lifecycle management (retention labels item-level, retention label policies publish/auto-apply, retention policies location-level bulk retain/delete), and DLP (Exchange/SharePoint/OneDrive/Teams workload DLP, policy tips, Endpoint DLP device control, DLP alerts/events/reports). This completes the MS-102 textbook: all 5 chapters / 13 sections.
5.3Data loss prevention (DLP)
Understand applying DLP policies to Exchange Online/SharePoint Online/OneDrive/Teams to block sharing/sending of sensitive info, Endpoint DLP for device control, and reviewing/responding to DLP alerts/events/reports.
Data loss prevention (DLP) prevents sensitive information from leaking outside the org. Using classification (sensitivity labels) or detection (SITs) as conditions, it controls sharing/sending actions.
5.3.1Workload DLP
DLP policies apply to workloads such as Exchange Online (mail), SharePoint Online/OneDrive (file sharing), and Teams (chat/channels). On matches (matching a SIT, carrying a sensitive label), they block external sharing/sending, warn users with policy tips, notify managers, or encrypt. You can allow override with justification for false positives.
5.3.2Endpoint DLP and alerts
Endpoint DLP controls actions on Windows/macOS devices with sensitive data—copy (USB/removable media), print, upload to cloud, clipboard—i.e., leakage prevention at the endpoint, not in cloud workloads. Review detections in DLP alerts/events/reports, investigate scope, and respond (tune policy, educate, handle exceptions).
Cues: "block sensitive sharing/sending in Exchange/SharePoint/OneDrive/Teams" = workload DLP policy. "warn the user" = policy tip. "control copy/print/USB/clipboard on a device" = Endpoint DLP. "review/respond to detections" = DLP alerts/events/reports. DLP = prevent leakage; label = classify; retention = preserve.
Watch the mix-ups: (1) DLP (prevent leakage) vs sensitivity label (classify) vs retention (preserve)—DLP uses labels/SITs as conditions. (2) Endpoint DLP (device actions) vs workload DLP (cloud sharing/sending). (3) Policy tips (warn) vs block (stop) are different actions.
5.3.3Section summary
- DLP policies block/warn on sensitive sharing/sending in Exchange/SharePoint/OneDrive/Teams
- Endpoint DLP controls copy/print/USB/clipboard on devices
- Review detections in DLP alerts/events/reports; DLP uses labels/SITs as conditions
Sign in to track progress — Log in.
Quick check
(just a quick review)Q1. You want to block external sending of emails containing credit card numbers in Exchange Online and warn the sender. Best?
Q2. You want to control employees copying sensitive files to USB or printing them, on the device. Best?
Q3. You want to prevent sensitive documents in SharePoint Online and OneDrive from being shared with external users. Best?
Q4. You want to understand how much your DLP policies detect/block sensitive leakage and tune false positives. Best?
Q5. "Classify and protect," "prevent leakage," and "retain long-term" are different. Which prevents sensitive info from leaking externally?
Keep track of your progress
The full study guide is free to read. Sign up free to practice with the question bank, track what you have read, review your mistakes, and highlight passages.

