★ First page of Microsoft's 100,000-partner directory, sorted by responsiveness✓ Microsoft Solutions Partner — Security, Modern Work, Infrastructure, App Innovation, Data & AI● Microsoft partner since 2006◆ 1,100+ organizations under management

Microsoft Purview DLP for a 50-User Firm: The First Five Policies, What They Catch, and What Licenses They Need

2026-09-27·IT Partner·Licensing and cost guidesNewComplianceMicrosoft PurviewData ProtectionMicrosoft 365

A 50-user firm does not need forty data loss prevention policies. It needs five that are switched on, tuned and producing a log an auditor will accept. This article gives the five we start with, what each one catches in a real tenant, the order to turn them on (simulation, then notifications, then blocks), and the licensing line between what Microsoft 365 Business Premium already includes and what needs an E5 add-on. The groundwork in [Purview before Copilot](/blog/microsoft-purview-controls-before-microsoft-365-copilot) and [controlling shadow AI with Purview](/blog/control-shadow-ai-microsoft-365-purview) is assumed.

What DLP does, and what it does not

Purview DLP inspects content where it lives and where it moves: Exchange Online mail, SharePoint and OneDrive files, Teams chat and channel messages, and, with the right license, Windows and macOS devices. A policy has three parts. Conditions describe what to look for: built-in sensitive information types such as credit card numbers and U.S. Social Security numbers, a sensitivity label or keywords. Scope says where and for whom. Actions decide what happens on a match: record it only, show the user a policy tip, notify an administrator, block with an override the user must justify, or block outright.

DLP is not classification and not encryption; sensitivity labels do those jobs and DLP can key off them. What it does well is catch the ordinary mistakes: the tax return sent to the wrong domain, the spreadsheet of card numbers shared with an "Anyone" link, the payroll export copied to a USB stick.

The first five policies

  1. Card and Social Security numbers in email and files. Locations: Exchange, SharePoint, OneDrive. Condition: content shared outside the organization contains a credit card number or a U.S. Social Security number. Two rules in one policy: one to nine instances shows a policy tip and lets the user send with a justification; ten or more blocks the send or the external share and emails an incident report to the administrator. What it catches: a client's SSN pasted into a message to a personal address; a customer list with card numbers uploaded to a shared folder. It is the policy our HIPAA implementation model and SOC 2 mapping both point at.
  2. Financial and HR data leaving to personal email. Location: Exchange. Conditions: content contains bank account or routing numbers, employer identification numbers or the firm's own "Payroll" or "Confidential" label, and the recipient domain is a consumer mail service. Action: block with override and a written justification, incident report to the administrator. What it catches: the payroll export forwarded to a home mailbox before a vacation; the term sheet sent to a personal address to print at home.
  3. Sensitive files shared with anyone. Locations: SharePoint and OneDrive. Condition: a file carrying a sensitive information type or a Confidential label is shared with people outside the organization, including through "Anyone" links. Action: block the external access and notify the owner. Reset the tenant's sharing settings first (External Sharing and Guest Access Cleanup, $2,950 per project) so the policy is not fighting the defaults.
  4. Endpoint DLP for USB, print and uploads. Location: devices. Prerequisites: Windows or macOS devices onboarded to Defender for Endpoint, which the Defender for Endpoint deployment handles. Conditions: a file with a sensitive information type or a Confidential label. Actions, in audit first: copy to removable media, print, copy to a network share, upload to a browser domain outside an allow list, and paste into an unallowed application. What it catches: the departing employee's USB export, the client file printed at a hotel business center, the upload to a consumer AI site.
  5. Teams chat and channel messages. Location: Teams. Condition: a message or attachment contains a card number or SSN, or is sent to an external or guest participant while carrying a Confidential label. Action: block the message with a policy tip that tells the sender why. What it catches: the SSN typed into a chat with the bookkeeper; the labeled file dropped into a channel shared with a vendor.

Simulation mode first, then notifications, then blocks

Every policy above starts in simulation mode. Microsoft's simulation feature runs the policy against real traffic and files, records what would have matched, and takes no action. Run it for two weeks, open the simulation results, and read the matches: a card-number rule that fires on invoice numbers, an SSN rule that fires on nine-digit part codes. Tighten the conditions (require a supporting keyword, raise the instance count, exclude the finance site) until the matches are real.

Then turn the policy on with notifications only: policy tips in Outlook, Word and the browser, and a mail to the user. Users learn what the firm considers sensitive without a single blocked message. Read the reports again. Only then enable blocks, starting with the high-count rules (ten or more numbers) and the endpoint actions with the clearest intent (USB copy). Keep override with justification on the low-count rules for at least the first quarter; a firm that blocks everything on day one gets workarounds through personal email, which DLP does not see. Confirm the current steps on Microsoft Learn.

Licenses: what Business Premium includes, and what needs an E5 add-on

Microsoft's Purview licensing guidance (opened 27 September 2026) draws the line clearly. Data loss prevention for Exchange Online, SharePoint Online and OneDrive is included in Microsoft 365 Business Premium, E3 and E5, and both also carry manual sensitivity labeling, retention policies, eDiscovery (Standard) and Audit (Standard). Policies 1, 2 and 3 above therefore run on a Business Premium or E3 tenant with no extra purchase.

Endpoint DLP and DLP for Teams chats are not in that base. The guidance lists both under Microsoft 365 E5 and under the add-on suites: Microsoft 365 E5 Information Protection and Governance; the Microsoft Purview Suite (called Microsoft 365 E5 Compliance until late 2025); and a Microsoft Purview Suite for Business Premium. Policies 4 and 5 need one of them.

Prices, annual commitment, Microsoft list price, September 2026 price list: Microsoft 365 E5 Information Protection and Governance is $84.00 per user per year, or $7.00 a month. For a 50-user firm that is $4,200 per year on top of Business Premium ($264.00 per user per year, $13,200) or E3 ($468.00, $23,400). The Purview Suite and its Business Premium edition are not on our September 2026 sheet, so we quote them on request; Microsoft 365 E5 ($720.00 per user per year) includes the whole Purview Suite. Microsoft licenses these features per user; license the people whose devices and chats the policies cover, and confirm the current scoping rule on Microsoft Learn. Our E5 add-ons versus full E5 article runs the wider math.

The override log auditors ask for

Every match, notification, override and block writes a record. The DLP alerts view shows incidents; Activity explorer shows the individual events, including the user's justification text on an override; and the unified audit log keeps the same events for the retention period your license allows. This log is the evidence. A SOC 2 auditor asks for it to prove the confidentiality control operates; a cyber insurer's questionnaire asks whether DLP is "enabled and monitored," and monitored means someone reads it.

Set a monthly routine: export the overrides, read the justifications, and act on the pattern. Keep the exports with the other evidence; the Compliance Evidence and Audit Readiness Retainer ($950 per month) does the collection if nobody owns it. Audit (Standard) retention is shorter than most audit periods, which is why the SOC 2 article treats retention as the first setting to fix.

Frequently asked questions

Does Microsoft 365 Business Premium include DLP?

Yes, for Exchange Online, SharePoint Online and OneDrive, per Microsoft's Purview licensing guidance. Endpoint DLP and DLP for Teams chat are not included; they need Microsoft 365 E5, the E5 Information Protection and Governance add-on, or a Purview Suite.

Do I need E5 to use Purview DLP?

No. Three of the five policies here run on Business Premium or E3. You need an E5-tier license only for devices (USB, print, uploads) and Teams chat; buy the Information Protection and Governance add-on for the users who need those two.

What is DLP simulation mode?

A way to run a policy against real mail, files and messages without taking any action, then review what would have matched. It replaces guessing. Run each new policy in simulation for about two weeks, tune, then enable notifications, then blocks.

Can users override a DLP policy?

If the rule allows it. An override requires the user to enter a business justification, and the justification is recorded in Activity explorer and the audit log. Allow overrides on low-count rules while the firm learns, and remove them where the risk is unambiguous.

Sources

  • Microsoft, "Microsoft Purview licensing guidance" (microsoft.com/licensing, opened 27 September 2026): DLP for Exchange, SharePoint and OneDrive in Business Premium and E3; Endpoint DLP and DLP for Teams chats under E5, the E5 Information Protection and Governance add-on, the Purview Suite and the Purview Suite for Business Premium
  • Microsoft, Enterprise security suites pricing page (opened 27 September 2026): the Purview Suite "previously Microsoft 365 E5 Compliance" and its contents
  • Microsoft Learn, "Add Microsoft Defender Suite for Business Premium to your subscription" (ms.date 24 September 2025; opened via the MicrosoftDocs GitHub source): Business Premium including Purview Information Protection and DLP for email and files
  • Microsoft Learn, "Get started with data loss prevention simulation mode" and "Learn about Endpoint data loss prevention" (not opened; as summarized in search results on 27 September 2026; verify on Microsoft Learn)
  • Microsoft, Commercial price list, September 2026 (our CSP price sheet)
  • IT Partner blog: microsoft-purview-controls-before-microsoft-365-copilot; control-shadow-ai-microsoft-365-purview; hipaa-on-microsoft-365-implementation-model; soc-2-on-microsoft-365-mapping-the-trust-services-criteria-to-entra-intune-purview-and-defender
  • IT Partner engineering notes from DLP deployments for 20 to 200-user firms, September 2026 (the policy thresholds and rollout timings are ours)
Policy Locations Condition Starting action License
1. Card and SSN numbers Exchange, SharePoint, OneDrive Card or SSN shared outside the firm Tip and override under ten instances; block at ten or more Business Premium or E3
2. Financial and HR data to personal email Exchange Bank, EIN or Payroll label to a consumer mail domain Block with justified override; incident report Business Premium or E3
3. Sensitive files shared with anyone SharePoint, OneDrive Sensitive type or Confidential label shared externally Block external access; notify owner Business Premium or E3
4. Endpoint DLP Windows and macOS devices Sensitive file to USB, print, share or unallowed upload Audit, then block with override E5, E5 Information Protection and Governance, or a Purview Suite
5. Teams chat Teams Card or SSN in chat, or labeled content to guests Block with policy tip E5, E5 Information Protection and Governance, or a Purview Suite

Key takeaways

  • Five policies cover the ordinary leaks: card and SSN numbers in mail and files, financial data to personal email, sensitive files shared with anyone, USB and print on devices, and Teams chat.
  • Simulation mode first, notifications second, blocks last; a firm that blocks on day one teaches its users to route around DLP through personal email.
  • Business Premium and E3 already license DLP for Exchange, SharePoint and OneDrive; endpoint and Teams chat DLP need E5, the E5 Information Protection and Governance add-on ($84.00 per user per year, Microsoft list price, September 2026 price list) or a Purview Suite.
  • Endpoint DLP only works on devices onboarded to Defender for Endpoint, so device management comes before policy four.
  • The override log in Activity explorer and the audit log is the evidence auditors and insurers want; read it monthly and keep the exports.

Configure and Enable DLP Policies ($8,000 per project, four weeks) builds these five policies in your tenant, runs the simulation and tuning cycle, sets the notifications and blocks in the order above, and hands you the monthly override review. Where the firm also needs retention and records rules behind the labels, the Microsoft Purview Data Lifecycle Management Implementation ($4,500 per project, 30 days) follows. Licenses are at Microsoft's list price on our Microsoft 365 E5 Information Protection and Governance, Microsoft Purview Suite and Microsoft 365 Business Premium pages. Contact us with your user count and the data you handle and we will tell you which two of the five need the add-on.

Questions this article didn’t answer?

Thirty minutes with Mike — our CEO, not a sales rep. Bring the hard version of the question.