Government: DLP and compliance at scale with Microsoft Purview
A government organization phases in Data Loss Prevention across mail, endpoints and network, with retention, Communication Compliance and a demonstrable audit trail for the regulator.

Business challenge
A government organization was at risk of leaking citizen data, while strict GDPR and records legislation demands a demonstrable audit trail. DLP policy existed on email only; endpoints, collaboration channels and the network stayed unwatched, and retention was handled manually per department.
Architecture
Sensitivity labels on citizen data carry the protection policy. DLP policy extends across Exchange, SharePoint, Teams and Endpoint DLP on devices, and, more recently, across the network layer via Entra Global Secure Access, which inspects text and AI interactions at the network level. Retention policy and records management fix retention periods per the archiving law. Communication Compliance watches risky communication patterns, and Audit (Premium) records every relevant action for the regulator.
Why this choice
The organization wanted one policy model across all channels, not a patchwork of separately configured point solutions per channel. Because DLP, labels and audit share the same classification, a single policy is consistently enforceable from mailbox to network edge.
Alternatives
A network firewall with deep packet inspection could intercept traffic at the network level, but had no awareness of data classification and so could not distinguish sensitive from non-sensitive content. For an organization that must be able to justify per data source why something was blocked, that was insufficiently explainable to the regulator.
Trade-offs
- Network-level DLP via Global Secure Access was still in preview during this programme (July 2026); a production dependency called for a fallback scenario. Since September 2026 the integration is generally available, which removes that fallback but keeps the licensing requirement: M365 E7, or Purview E5 alongside Entra Internet Access.
- Endpoint DLP requires managed devices; unmanaged devices from external parties fell outside its reach.
- Communication Compliance generates a lot of signals to review; without enough triage capacity, alerts pile up.
Microsoft products
Microsoft Purview (Information Protection, Data Loss Prevention, Communication Compliance, Audit, retention/records), Microsoft Entra ID (Global Secure Access).
Best practices
- Roll out DLP per channel in phases: simulate first, then enforce, then move to the next channel.
- Treat network DLP via Global Secure Access as complementary to, not a replacement for, channel-specific DLP.
- Document retention policy per data source explicitly, including the legal basis, so an audit does not have to re-derive why a retention period applies.
Lessons learned
The network layer turned out to be the channel with the most unprotected traffic, larger than expected from the mail and Teams figures alone. Without that layer, a significant share of the risk would have stayed invisible.
Architecture at a glance
Click a component for details
Sensitivity labels
Labels on citizen data carry the protection policy.
Network DLP via Global Secure Access complements channel-specific DLP, it does not replace it.
Related content
Related how-tos
Related best practices
