No more typing reviews! Try our Samantha, our new voice AI agent.
Suraj Varma - PeerSpot reviewer
Network Security Engineer at Digitaltrack
Real User
Top 5Leaderboard
May 31, 2026
Stronger data protection has reduced accidental leaks and supports ongoing compliance monitoring
Pros and Cons
  • "Microsoft Purview Data Loss Prevention has impacted the organization very positively by strengthening data security through automatically detecting and protecting sensitive information across emails, endpoints, SharePoint, and OneDrive."

    What is our primary use case?

    Microsoft Purview Data Loss Prevention is used to monitor, detect, and prevent sensitive information from being shared or copied, or to prevent transferring files outside the organization. This is the main use case.

    Microsoft Purview Data Loss Prevention is used to identify sensitive information such as financial records, customer data, and confidential business documents. Policies can automatically block users when they attempt to send any sensitive data through email or any kind of application.

    What is most valuable?

    The best features of Microsoft Purview Data Loss Prevention are multiple, including sensitive data discovery, endpoint DLP, policy-based enforcement, and compliance reporting.

    Endpoint DLP is the most valuable feature because it extends data protection control directly to the user device.

    Microsoft Purview Data Loss Prevention has impacted the organization very positively by strengthening data security through automatically detecting and protecting sensitive information across emails, endpoints, SharePoint, and OneDrive. It has helped reduce the risk of data leaks and improve compliance with regulatory requirements.

    After implementing Microsoft Purview Data Loss Prevention, approximately a 40% reduction in accidental sensitive data sharing has been observed, and compliance monitoring has been improved.

    The AI-driven classification and detection capabilities of Microsoft Purview Data Loss Prevention help strengthen governance by identifying sensitive information, enforcing protection policies, and supporting regulatory compliance requirements.

    The content inspection and classification capabilities of Microsoft Purview Data Loss Prevention are reliable and very effective in identifying sensitive information, providing accurate data.

    What needs improvement?

    Microsoft Purview Data Loss Prevention is a powerful solution. The only thing that needs to be improved is an easier policy troubleshooting process. Apart from this, everything is excellent.

    For how long have I used the solution?

    Microsoft Purview Data Loss Prevention has been used for almost three years.

    Buyer's Guide
    Microsoft Purview Data Loss Prevention
    June 2026
    Learn what your peers think about Microsoft Purview Data Loss Prevention. Get advice and tips from experienced pros sharing their opinions. Updated: June 2026.
    900,644 professionals have used our research since 2012.

    What do I think about the stability of the solution?

    Microsoft Purview Data Loss Prevention is a very stable solution.

    What do I think about the scalability of the solution?

    The scalability of Microsoft Purview Data Loss Prevention is excellent and handles the organization's requirements effectively.

    How are customer service and support?

    Customer support for Microsoft Purview Data Loss Prevention is excellent because support is available at any time. Whenever there is a technical issue, a ticket can be raised with the support team, and they provide support on a call to troubleshoot the issue.

    Which solution did I use previously and why did I switch?

    Microsoft Purview Data Loss Prevention has been used since the beginning, with no switching from another solution.

    How was the initial setup?

    The experience with pricing, setup cost, and licensing for Microsoft Purview Data Loss Prevention was straightforward because there is a strong partnership with the vendor sales team, who are helpful in addressing setup costs and licensing matters.

    What about the implementation team?

    The implementation team consists of a partnership with the vendor of Microsoft Purview Data Loss Prevention.

    What was our ROI?

    A good return on investment has been seen with Microsoft Purview Data Loss Prevention. Time and money have been saved because the solution has reduced data leakage incidents, improved compliance, and provided very good visibility.

    What's my experience with pricing, setup cost, and licensing?

    The experience with pricing, setup cost, and licensing for Microsoft Purview Data Loss Prevention was straightforward because there is a strong partnership with the vendor sales team, who are helpful in addressing setup costs and licensing matters.

    Which other solutions did I evaluate?

    No other options have been evaluated.

    What other advice do I have?

    Microsoft Purview Data Loss Prevention should be considered as one of the best solutions present in the market. It is recommended to start with the monitoring mode before enforcing policies and to understand the sensitive data landscape while fine-tuning policies very carefully. This review has been given a rating of 9.

    Which deployment model are you using for this solution?

    Public Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
    Last updated: May 31, 2026
    Flag as inappropriate
    PeerSpot user
    Managing Director, Chief Information Security Officer at a financial services firm with 201-500 employees
    Real User
    Top 10
    Mar 24, 2026
    Data protection has stopped sensitive emails and improves discovery with simple file labeling
    Pros and Cons
    • "We have not seen any sensitive files leave via email, which represents a significant improvement."
    • "To improve Microsoft Purview Data Loss Prevention, I think it would be helpful if we could make bulk labeling easier, as it is a little cumbersome at the moment."

    What is our primary use case?

    My main use cases involve trying to prevent sensitive files from leaving the company. Any sensitive data that the business has marked as should not be able to leave the company is stopped at the email level, providing significant benefits to our organization.

    What is most valuable?

    The feature I appreciate most about Microsoft Purview Data Loss Prevention is the simplicity of labeling files. The classification of policy controls by Microsoft Purview impacts my user productivity in a positive way, but more from a security perspective, helping me more than the user. It finds social security numbers in the files when we scan for it, so that we can prevent those from leaving the company.

    What needs improvement?

    To improve Microsoft Purview Data Loss Prevention, I think it would be helpful if we could make bulk labeling easier, as it is a little cumbersome at the moment. The bulk labeling process is a challenge that could use improvement to make it easier, but the user experience is relatively simple, which is good.

    For how long have I used the solution?

    I have been using Microsoft Purview Data Loss Prevention for about a year.

    What do I think about the stability of the solution?

    I have not experienced any downtime, crashes, or performance issues.

    What do I think about the scalability of the solution?

    Microsoft Purview Data Loss Prevention scales well with the growing needs of my organization. I have expanded usage, and it is an ongoing project. The process of expansion takes a lot of effort from the end-users, but the results are good.

    Which solution did I use previously and why did I switch?

    Prior to adopting Microsoft Purview Data Loss Prevention, I was not using another solution to address similar needs.

    How was the initial setup?

    I would describe my experience with deploying Microsoft Purview Data Loss Prevention as positive.

    What about the implementation team?

    I was not really involved in the deployment; one of my team members did that.

    What was our ROI?

    I have seen a return on investment with Microsoft Purview Data Loss Prevention.

    What's my experience with pricing, setup cost, and licensing?

    My experience with the pricing, setup costs, and licensing is that everything is included in our enterprise licensing, so there are no particular pluses or minuses.

    Which other solutions did I evaluate?

    Before selecting Microsoft Purview Data Loss Prevention, I considered solutions like Saiara and Concentrix. What stood out in my evaluation process, either positively or negatively, when comparing the options is that the integration with Microsoft Office and the file system makes it a plus for us.

    What other advice do I have?

    I assess Microsoft Purview Data Loss Prevention's ability to prevent unauthorized sharing of sensitive information within my organization as working well. Microsoft Purview Data Loss Prevention has helped improve my organization's ability to discover sensitive data. We have not seen any sensitive files leave via email, which represents a significant improvement. My advice to another organization considering Microsoft Purview Data Loss Prevention is to give it a try, as it works well with the integration, is relatively simple for the end-users, and the users appreciate it. I would rate Microsoft Purview Data Loss Prevention overall as an eight out of ten.

    Which deployment model are you using for this solution?

    On-premises

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    Last updated: Mar 24, 2026
    Flag as inappropriate
    PeerSpot user
    Buyer's Guide
    Microsoft Purview Data Loss Prevention
    June 2026
    Learn what your peers think about Microsoft Purview Data Loss Prevention. Get advice and tips from experienced pros sharing their opinions. Updated: June 2026.
    900,644 professionals have used our research since 2012.
    Senior Consultant at SYNERGY ADVISORS, LLC
    Real User
    Top 20
    Apr 6, 2026
    Data protection has integrated with existing workflows and now needs fairer licensing
    Pros and Cons
    • "The feature I appreciate most about Microsoft Purview Data Loss Prevention is the native synchronization between the tool and all the Office applications that the customer already has."
    • "The only concern is that it forces clients to use an expensive license."

    What is our primary use case?

    Deploy the whole solution for customers that are starting from zero to hero. The implementation framework for data protection goes as follows:

    -Identification of information assets

    -Protection, which means placing technological controls to protect the flow of data

    -Monitoring through the different dashboards that the portal offers.

    The other side of the coin is the internal user monitoring; at the end they are the ones handling the data, this can be archived with IRM, DSPM, CC.

    What is most valuable?

    The feature I value most about Microsoft Purview Data Loss Prevention (DLP) is its native synchronization with all the Office applications that customers already use. Unlike other solutions in the market, such as CrowdStrike, Proofpoint, and Cato, which also provide DLP capabilities, these tools are not able to fully interpret encrypted documents generated by Purview. While they offer strong controls, they cannot manage information with the same level of depth as Microsoft Purview DLP due to its native integration within the Microsoft ecosystem.

    The main benefit for organizations is the ability to leverage a technological control that operates natively within their existing Microsoft environment. This enables them to effectively define and govern the flow of data.

    What needs improvement?

    When assessing Microsoft Purview Data Loss Prevention (DLP) and its ability to prevent unauthorized sharing of sensitive information within my organization, I would consider it a strong solution. However, there is a key limitation: the licensing model can be expensive for many customers.

    With a base license, organizations can apply controls within the Microsoft environment. However, extending these capabilities to non-Microsoft domains requires an E5 license, which represents a significant investment. Not all organizations have the budget to afford this level of licensing. While the controls themselves are effective, I believe the pricing model should be adjusted based on region, as what is affordable in the United States may not be in other regions. Therefore, pricing should be reviewed or adapted accordingly.

    For how long have I used the solution?

    I have been using Microsoft Purview Data Loss Prevention for two and a half years.

    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    Last updated: Apr 6, 2026
    Flag as inappropriate
    PeerSpot user
    Director of Cyber Security
    Real User
    Top 10
    May 5, 2025
    Continuous alerts significantly boost data guideline monitoring but lots of false positives
    Pros and Cons
    • "We can triage based on quick and sometimes constant alerts."
    • "The impact of Microsoft Purview Data Loss Prevention's classification and policy controls on our productivity within our organization is significant, as it's helped our security team."
    • "Improving Microsoft Purview Data Loss Prevention would involve recognizing that the whole AI path we are all on is going to help, given the massive amount of data we handle; even if there are true positives, implementing a degree of severity ranking is essential."
    • "The amount of false positives and the hash issue we had have brought down the score for me."

    What is our primary use case?

    Our use cases for Microsoft Purview Data Loss Prevention include particularly email egress where we're looking for certain types of data to block, primarily for data exfiltration prevention and to combat malicious traffic.

    Based on what I've seen, I've anticipated that the use case where we use the most true positives helps us categorize certain emails, allowing us to decide which ones need more attention based on sensitivity, unlike someone's email about marketing.

    How has it helped my organization?

    The features have helped our organization as we can take action as necessary if something appears to be a serious violation. We can take fast corrective action as necessary.

    What is most valuable?

    The feature I find most valuable that I'm currently using is the quickness of the emails that the Microsoft Purview Data Loss Prevention solution sends to us, where we get notifications that say a user has potentially breached our data guideline rules, and we get those alerts continuously, allowing us to enforce them manually. We can triage based on quick and sometimes constant alerts.

    The impact of Microsoft Purview Data Loss Prevention's classification and policy controls on our productivity within our organization is significant, as it's helped our security team. We can quickly categorize and try to weed out false positives in an ongoing process, especially in a large firm with many different emails going on every day.

    My experience with centralizing our DLP program on Microsoft Purview Data Loss Prevention has helped us weed out false positives and leverage that information to go back to the business, informing them on security awareness and how our security posture is being affected by team members misusing privileged information.

    It's helping to improve our organization's security posture as we are on that journey, with ongoing in-flight projects here. 

    Regarding saving time or money, we haven't really quantified in terms of money yet; we are still a little younger than full data categorization for security, however, I expect about 40% to 50% of our time was spent chasing false positives, especially among a certain class of users in the US versus some offshore counterparts.

    I find the comprehensive coverage of our DLP, firewall, and endpoint solutions essential, which encompasses the whole SOC2 compliance process.

    What needs improvement?

    Improving Microsoft Purview Data Loss Prevention would involve recognizing that the whole AI path we are all on is going to help, given the massive amount of data we handle; even if there are true positives, implementing a degree of severity ranking is essential.

    We do have to deal with a lot of false positives, particularly at the outset. 

    For how long have I used the solution?

    I've been using the solution for as long as it's been around. 

    What do I think about the stability of the solution?

    I haven't had issues with stability.

    What do I think about the scalability of the solution?

    I've seen no issues with scalability. 

    How are customer service and support?

    On a scale of one to ten, I would rate my experience with support in the high seven to eight range, although there was a specific problem with Microsoft Purview Data Loss Prevention regarding hashing that dropped this score due to communication issues with engineers. We went through a reseller and had issues. Once we got to the Microsoft engineers, the experience was great. The reseller being between us was nightmarish. Typically, support is very good. 

    How would you rate customer service and support?

    Positive

    Which solution did I use previously and why did I switch?

    In my current organization, prior to adopting Microsoft Purview Data Loss Prevention, we were using Microsoft DLP, which was one of the earlier solutions.

    How was the initial setup?

    The learning curve is hard at first in terms of weeding out false positives and refining that process. AI will help with that. Rather than fine-tuning taking months, we're hoping it will get faster. 

    What was our ROI?

    I cannot quantify a return on investment specifically; however, for our security posture, I have seen some slight improvement in my teams' reports. From a pure financial perspective, I do not have that information.

    What's my experience with pricing, setup cost, and licensing?

    My experience with the pricing, setup costs, and licensing is not something I manage directly since I'm the owner operator; my colleagues might be more involved with that aspect as we have other teams to handle those details.

    Which other solutions did I evaluate?

    I'm committed to our current path.

    What other advice do I have?

    I would assess the usability of authorized shares of sensitive information as a process still in the works. My hope is that we're doing great, and the expectation is high for future outcomes.

    Currently, I do not utilize the machine learning for anomalies that is offered by Purview.

    On a scale of one to ten, I rate Microsoft Purview Data Loss Prevention a six out of ten. The amount of false positives and the hash issue we had have brought down the score for me.

    Which deployment model are you using for this solution?

    Hybrid Cloud
    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    Prajwal Chougale - PeerSpot reviewer
    System Analyst at a tech services company with 51-200 employees
    MSP
    Top 10
    Nov 5, 2025
    Has helped strengthen data protection policies and improve sensitive data discovery
    Pros and Cons
    • "Microsoft Purview Data Loss Prevention's ability to prevent unauthorized sharing of sensitive information is valuable."
    • "The main disadvantages of Microsoft Purview Data Loss Prevention in comparison to the Netscope product are notable considerations."

    What is our primary use case?

    I have good hands-on experience with Microsoft Defender, Azure Sentinel, Microsoft Admin portal, Azure portal, and the tools that XDR includes such as Microsoft Defender for EDR and O365. I use all of these tools daily.

    I have good hands-on experience working with the Face API, which I used in the past six months. I do not use it every day because I work as a cybersecurity analyst.

    Overall, I have been working with the Face API for some project work spanning eight to ten months.

    What is most valuable?

    I utilize the machine learning driven analysis offered by Microsoft Purview Data Loss Prevention.

    Microsoft Purview Data Loss Prevention has helped to improve my organization's ability to discover sensitive data.

    Classification and policy controls enhance productivity and user experience.

    What needs improvement?

    There are specific missing features that I would like to see included in Microsoft Purview Data Loss Prevention in the future.

    For how long have I used the solution?

    I have been working with the Face API for more than two years.

    What do I think about the stability of the solution?

    I assess the stability and reliability of Microsoft Purview Data Loss Prevention as good.

    What do I think about the scalability of the solution?

    Microsoft Purview Data Loss Prevention scales well with the growing needs of my organization.

    How are customer service and support?

    I have escalated questions to technical support and would rate the technical support as a five on a scale of one to ten, where ten is the best.

    How would you rate customer service and support?

    Positive

    How was the initial setup?

    The initial setup and deployment of Microsoft Purview Data Loss Prevention was straightforward, but I faced some challenges and complexities during the process.

    What other advice do I have?

    I use Microsoft Purview Data Loss Prevention for various main use cases and for data governance purposes.

    The main disadvantages of Microsoft Purview Data Loss Prevention in comparison to the Netscope product are notable considerations.

    Classification and policy controls impact user productivity within the organization.

    Microsoft Purview Data Loss Prevention's ability to prevent unauthorized sharing of sensitive information is valuable.

    The deployment experience with Microsoft Purview Data Loss Prevention involved both positive aspects and challenges. The solution operates on a cloud-based, Azure-based DLP model.

    I purchased Microsoft Purview Data Loss Prevention through Microsoft directly.

    My experience with centralizing my DLP program in Microsoft Purview Data Loss Prevention has been informative, and I can share advice and recommendations with other organizations considering this solution.

    I recommend Microsoft Purview Data Loss Prevention to other organizations considering a data loss prevention solution.

    I am an end user of Microsoft products and work as a system analyst at Stratogent company.

    Overall, I would rate Microsoft Purview Data Loss Prevention as a product and solution with a rating of ten on a scale of one to ten.

    Which deployment model are you using for this solution?

    Public Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Disclosure: My company has a business relationship with this vendor other than being a customer. MSP
    Last updated: Nov 5, 2025
    Flag as inappropriate
    PeerSpot user
    Roby Skariah - PeerSpot reviewer
    Solution Architect : Corporate wide systems at a healthcare company with 10,001+ employees
    Real User
    Jul 13, 2023
    Automation has given us consistent analytics and improved quality of insights into user activity
    Pros and Cons
    • "One of the valuable features of Purview is the ability to create a legal hold on a user's account within the compliance portal. That's pretty useful when it comes to any litigation or if you want to redeem the content within a mailbox, OneDrive, or a generic public SharePoint site."
    • "A site can have different containers where you store data. We have always wanted to apply compliance, labels, and policies at the container level, rather than to an outer shell or at the site level. That is something we have been looking forward to and I believe Microsoft is already planning something like that."

    What is our primary use case?

    We use it for scheduled audit log retrieval on a monthly basis. We have strictly confidential SharePoint sites and requests come in where we have to find out the activity by users, such as who has viewed specific files or pages on a particular site. The logs contain activity by users and are part of Microsoft Purview. We can run search queries against the logs to get user activity across the tenant for a particular, confidential site.

    How has it helped my organization?

    The solution has tools for creating robotic process automation and workflows and we use them to reduce manual intervention and to handle some of the manual jobs. They make things much faster and more accurate. Of course, it involves much more testing and back and forth, but once you streamline an automated process, it's easy and accurate. It saves a lot of time because you don't need to have a manual monitoring system. Rather, the system identifies things and notifies you. It can save costs on the order of 60 or 70 percent.

    With automation, the quality of insights has improved a lot. Manual processes have been replaced with something like a bot. It creates a more consistent pattern that gives you proper analytics and insights into how activities are being carried out.

    Also, compliance can be viewed in real time to a certain extent. A small portion is not available in real time, but 70 to 80 percent of it is accessible in real time. Overall, Purview helps us to stay on top of compliance because it handles just about all the compliance factors.

    What is most valuable?

    One of the valuable features of Purview is the ability to create a legal hold on a user's account within the compliance portal. That's pretty useful when it comes to any litigation or if you want to redeem the content within a mailbox, OneDrive, or a generic public SharePoint site. If you want to retain the user's data until the case is resolved, you can use the legal hold feature.

    Also, it's important that Purview can connect to iOS, Mac, and Android devices. With smartphone involvement, so many applications can now be accessed through them and it is important to apply Purview across operating systems and platforms.

    Purview's natively integrated compliance across Azure Dynamics and Office 365 is also significant because within Microsoft 365 there are multiple applications. Irrespective of whether it's Dynamics or Azure, it's very important that it has native support. The data connectivity should be efficient enough to support and secure their own platform's data.

    In addition, with varying regulations in different industries and matters, Purview lets you create rules and conditions based on industry standards around the world. That is important. Our company is in pharmaceuticals and the rules and conditions are different from other industries. It is important to be able to keep track of all these regulations and have a tool that is flexible enough to create the regulatory rules and conditions we need.

    And when it comes to data loss protection, Purview has features that can recognize patterns and detect any sort of data loss, where the data is being transferred from its platform to a different one. The default settings that come with it are pretty nice for identifying data transfer or data loss across the platform.

    It also comes with a lot of training materials, with use cases and examples, to help educate users and make them familiar with the tool.

    What needs improvement?

    A site can have different containers where you store data. We have always wanted to apply compliance, labels, and policies at the container level, rather than to an outer shell or at the site level. That is something we have been looking forward to and I believe Microsoft is already planning something like that.

    For how long have I used the solution?

    I have been using Microsoft Purview Data Loss Prevention for less than a year.

    What's my experience with pricing, setup cost, and licensing?

    It's a little bit pricey compared to competitors, but it's not too high. On a scale from one to 10, where 10 is expensive, it's a seven.

    What other advice do I have?

    Overall, it's a very nice product and can handle a lot of applications.

    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    HosmanRodriguez - PeerSpot reviewer
    Senior Compliance Manager at a hospitality company with 10,001+ employees
    Real User
    Top 5
    Jul 1, 2024
    Nice dashboard, good data loss prevention, and helps with compliance
    Pros and Cons
    • "If we can prevent information from going out, eventually, when a regulator is asking about our security measures, we can show what we've been doing."
    • "It could cover more solutions and technologies."

    What is our primary use case?

    The solution is primarily used for preventing leaks - to protect us from getting information out of the company.

    What is most valuable?

    The data loss prevention is great. It can prevent things like credit card information from being taken. The data protection is excellent. 

    We can use the solution on Windows and iOS. We mostly use it with Office 365 and ingest data sources from Microsoft.

    The solution is natively integrated and compliant across Azure. It takes into account critical regulations from around the world. We need to comply with various regulations. For our business case, it's very important. 

    If we can prevent information from going out, eventually, when a regulator is asking about our security measures, we can show what we've been doing. It helps us to reduce the likelihood of potential fines.

    We can educate users on how to handle sensitive data. By showing the records we keep and explaining the technologies implemented, we can provide awareness to our users. 

    The solution offers good visibility into our environment. Our security team can use the product to monitor and track.

    Its dashboard allows us to show compliance in real-time.

    We've been able to reduce the time to action on insider threats. Security permissions are always being monitored. In general, it has saved us time and money when dealing with security. It's made us become more efficient. We've increased our compliance capabilities by 25%.

    What needs improvement?

    It could cover more solutions and technologies.

    One of the challenges that we're facing now is how we can identify our critical information storage level, for example, via scanning or some other method. 

    For how long have I used the solution?

    While I'm no longer using the tool, I used the solution for two years. 

    How are customer service and support?

    Support is good.

    How would you rate customer service and support?

    Positive

    Which solution did I use previously and why did I switch?

    In the past, I've used Forcepoint. I used it at a different company. Purview is easier to use.

    How was the initial setup?

    The deployment is pretty easy. As with any implementation, there may be some challenges. However, it wasn't overly complicated. It depends on the complexity of the business. 

    We had a small team that handled the setup. It was specifically the networking team.

    What about the implementation team?

    We rely on business partners to help with the technical part to reduce the impact on the business.

    What was our ROI?

    We have reduced ROI in terms of time and money saved. 

    What's my experience with pricing, setup cost, and licensing?

    The pricing is a little bit better when compared to others on the market.

    Which other solutions did I evaluate?

    I'm unsure if my current company evaluated other options. 

    What other advice do I have?

    We are Microsoft customers. 

    I'd rate the solution nine out of ten.

    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    Anna Virtsan - PeerSpot reviewer
    IT Project Manager at UkrSibbank
    Real User
    Top 10
    Aug 18, 2023
    Integrates well, connects with iOS and Android devices, and takes into account critical regulations from around the world
    Pros and Cons
    • "I rate Microsoft Purview Data Loss Prevention's stability a ten out of ten."
    • "They do not provide language options beyond the ones already available, so our language option is missing."

    What is our primary use case?

    We prioritize the control of sensitive data according to our classification, which closely aligns with Microsoft's classification system. Our main goal is to prevent the loss of personal secret data. To achieve this, we focus on specific data types. Our use case involves managing managers who interact with customers. The objective is to limit access to this sensitive data within different departments, allowing some groups to have access while denying it to others. We also control outgoing information through the extension line.

    The basic use case scenario is as follows: when we receive sensitive personal data from a customer, we classify this information with Microsoft Purview Data Loss Prevention for information protection. The next step involves narrowing down the range of people who can access this data through recording management. The third step is to use DLP to prevent the loss of this personal information through the extension line.

    The second part of the process deals with the use and storage of this information in OneDrive, SharePoint, and Teams. We label and save it within the perimeter system. Lastly, we implement retention policies and tuition policies to ensure that the controlled path of this information is secure and that it is deleted when necessary.

    How has it helped my organization?

    It's important to us that Purview can connect to iOS, Mac, and Android devices, as well as data in other SaaS apps. We also have numerous organizations with corporate devices, all of which are connected by the MDM and MAM systems within Azure and our on-premises network. Therefore, it's essentially within our perimeter. It's crucial to control the overall flow of data and information on all endpoints, including mobile devices such as tablets and phones. Almost everything is on iOS because we are currently transitioning from older Android devices and corporate devices to Apple devices. Essentially, iOS provides better control.

    Purview's native integration for compliance across Azure Dynamics 365 and Office 365 is of utmost importance to us. We have high demands for compliance, and the current design of Purview greatly enhances the user experience for both administrators and regular users. The all-in-one user admin dashboard holds significant value, as it allows administrators to easily visualize connections between modules. Moreover, as administrators, we can effectively track the flow of data between these modules and understand the interconnections of the rules across different modules. This feature is truly impressive and well-implemented. In contrast, most specific cybersecurity programs tend to have more complicated dashboard interfaces, making it challenging to identify the next step in the data flow.

    It is important that Purview was built taking into account critical regulations from around the world. We are part of an international group, and we collaborate with other offices and colleagues from different countries. They are currently conducting their own research and starting to implement it. We understand that we can essentially use the same rules, making it clear to everyone how it works, how it is made, and how it is built. We have already modified some default rules and sensitive information types, making it unnecessary to create them from scratch and consider all the small details. Microsoft has provided this functionality for us, and it's incredibly useful, making the entire process much quicker.

    We have a plan to set up Purview for the DLP model and incorporate it as a part of our Global DLP system in the company. Currently, we are in the planning and researching phase, and there is a lot of interest in the tool. We anticipate huge potential in Microsoft tools and how they evolve, such as Azure and Entra. Having a wider range of tools gathered in one place is very convenient.

    We observe the clients' weaknesses because it essentially operates through pooled solutions within the organization. Whether we use it or not, the tenant's full settings are functional. As we work, and delve deeper into research, we notice some weaker spots. At present, we are in a phase similar to the planning step, but we already perceive the potential directions that Microsoft Purview Data Loss Prevention offers for us to work on. Consequently, we have discovered a few types of information that we had not taken into consideration before, and we see that our users encounter these information types in their everyday operational activities.

    Purview has the potential to reduce the number of solutions, and as a result, it has logically impacted the company's budget. On the other hand, Microsoft has been very active in updating systems over the past three years. This development potential stands out compared to other cybersecurity tools that remain relatively static. Consequently, we don't foresee much progress or development in the functional side of those tools in the near future. In contrast, Microsoft offers its customers a clear and open roadmap for the development of their tools.

    The AI algorithms could significantly assist cybersecurity specialists in mitigating risks, addressing potential threats, and preventing such threats from compromising the system.

    What is most valuable?

    The most crucial aspect is controlling how Microsoft Purview Data Loss Prevention functions within the SharePoint environment and cloud storage. Additionally, we exchange ideas because, as a centralized organization, we also make use of a variety of tools, including Symantec DLP. Consequently, we have different levels of systems that monitor the external and internal parameters of the company. These lines of defense are integral to our cybersecurity solutions, and at the heart of this framework lies Microsoft Purview Data Loss Prevention.

    What needs improvement?

    I currently work in the financial domain, and we have very strict regulations from national banks and the group side. Domain-related improvements could be really useful for organizations and banks. For example, sensitive information types are the basic level of information protection, similar to the Purview model. We start with creating or duplicating sensitive insights and editing them. I am talking about more sensitive information types that align with European regulations, especially in the financial sector. Having more variety would be beneficial. All of the EU considers sensitive information types in finance, but we need more variety, especially as a Ukrainian company. We face a lack of attention to our region, despite having the same strict regulations as EU companies. 

    One point of improvement is related to organization and language issues. For instance, we use different sensitive information types for France, the UK, and other countries where we have offices. Unfortunately, Microsoft doesn't support the Ukrainian language, unlike Chinese and Japanese languages, which have deeper layers of understanding of information. It would be helpful to add support for Ukrainian. However, I understand that we are essentially bilingual, using both English and Ukrainian in our companies, and we are a minority in terms of languages.

    Other solutions, like ERP systems, offer localization for Ukraine and have partnerships with companies. Microsoft 365 also supports the Ukrainian language from a user perspective. However, unfortunately, Defender and Azure lack deeper settings. They do not provide language options beyond the ones already available, so our language option is missing. Purview includes sensitive info types covering a wide range of languages and country specifications. For instance, it includes passport numbers for Ukraine, but we also need a sensitive input type for our tax numbers. Currently, there is no option for our tax numbers, which forces us to duplicate the data. In contrast, they include all sorts of options such as driver's license numbers and insurance policy numbers for EU companies. It would be beneficial to have those presets available for us as well.

    For how long have I used the solution?

    I have been using Microsoft Purview Data Loss Prevention for a couple of months.

    What do I think about the stability of the solution?

    I rate Microsoft Purview Data Loss Prevention's stability a ten out of ten.

    What do I think about the scalability of the solution?

    I rate Microsoft Purview's Data Loss Prevention scalability a ten out of ten. The tool is highly flexible, offering a wide range of capabilities that largely depend on the defense strategies and the proficiency of the managers who work with it. It provides ample opportunities to address various traditional data management problems. Furthermore, as the vendor develops additional solutions, such as AI, its potential for high scalability remains significant. 

    Which solution did I use previously and why did I switch?

    We are currently considering the possibility of discontinuing our DLP program called Varonis. This is because it essentially duplicates the data classification capabilities of Purview for cloud storage. By doing this, we can potentially reduce costs, and one of the major advantages of Microsoft is its licensing structure. All our users are already covered by various types of licenses, and we can easily add another type, such as for level admins or security admins, to provide them with additional licenses that offer more possibilities and options to work with the system.

    On the other hand, we have another system that also incurs implementation costs and requires significant human and primary resources. Additionally, we must consider various types of licensing, both long-term and short-term. However, one more significant advantage of Microsoft is its clear and transparent licensing policies. We can easily access information and conduct preliminary research without the need for additional communication with partners or vendors. This allows us to make well-informed decisions on what suits us best before involving a reseller, which is also an important aspect to consider.

    How was the initial setup?

    As the Product Owner of Microsoft 365 and also the Project Manager involved in every step, I find it challenging to describe the process due to being the sole expert in this area. The difficulties arose due to wartime circumstances and the complexity of migrating to the cloud. The team had to handle the heavy lifting of the project, and the lack of available personnel added to the challenges we faced.

    We have layers of regulations to consider, especially since we operate in the finance domain. It's a rather complicated situation overall, but the solution is actually quite easy to deploy.

    What about the implementation team?

    We are implementing the solution in-house but are seeking a partner for consulting.

    What's my experience with pricing, setup cost, and licensing?

    We are using the E3 license for Microsoft 365 with the E5 compliance license add-on. 

    The prices are quite reasonable, but unfortunately, I don't know the hourly rates since they are globally negotiated for the entire group, and we probably have some nice discounts. In Ukraine alone, we have five thousand users.

    Which other solutions did I evaluate?

    We have a range of tools, and prior to considering Microsoft Purview Data Loss Prevention, we also evaluated other solutions.

    What other advice do I have?

    I would rate Microsoft Purview Data Loss Prevention an eight out of ten. It is not specifically created for security purposes but rather functions as a branch for Microsoft, from what I can observe. However, they are actively working on improvements. I hope that eventually, it will be rated a ten out of ten. Currently, when comparing it to other systems we are using, such as Symantec DLP, it falls on the lower end.

    We have only considered using Purview to help reduce actions on insider threats, but it could potentially be helpful for our ESS experts.

    Our goal is to use Purview to serve multiple departments instead of 5,000 users within a single tenant.

    Purview requires some maintenance because our managers have to do so after the deployment stage. The maintenance stage comes in, as the task for our information security managers is to analyze alerts and likely repeat certain steps such as creating an incentive prototype, establishing rules, and creating new DLP rules. This involves constant management processes, which are more like operational processes.

    I would highly recommend Microsoft Purview Data Loss Prevention for researching and implementing data loss prevention measures, especially for mid-size businesses. As an enterprise-level organization, we have higher standards and demands. However, I believe small and mid-size businesses would find it particularly beneficial. Purview addresses all the traditional data management problems and offers specifications that are not commonly found in the enterprise sector. By using Purview, businesses can save on costs and efforts, particularly smaller ones that may lack a sufficient number of staff members with expertise in information security, DLP, and data management. Unlike enterprises, these businesses might not have the luxury of hiring specialized roles such as solution architects, data architects, and a full range of information security experts, which makes Purview an attractive solution for them.

    Which deployment model are you using for this solution?

    Hybrid Cloud
    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    Abdulkadir AKGUN - PeerSpot reviewer
    Senior Cloud Solutions Consultant. MW and Security at Data Market
    Consultant
    Top 20
    Sep 17, 2024
    Useful for the protection of sensitive information and is not very expensive
    Pros and Cons
    • "The tool's most valuable feature is in the area of OCR."
    • "The tool's user interface and document fingerprinting have been very poor for my customers because uploading files manually can be problematic."

    What is our primary use case?

    I prefer to use products under Microsoft Office 365. I tell my customers to use Microsoft products.

    My customers do not use Microsoft Purview Data Loss Prevention as they prefer to use Forcepoint Data Loss Prevention. My customers have used Microsoft Office 365, but they have not used its features. From next year, they might start using Microsoft Purview Data Loss Prevention.

    I use Microsoft Purview Data Loss Prevention to protect information and endpoint or USB device controls. The tool is used for sensitive information protection on mobile devices and other settings.

    What is most valuable?

    The tool's most valuable feature is in the area of OCR. For my organization, Microsoft Purview compliance portal, Azure subscriptions and integrations were helpful. The document fingerprinting feature, information protection during integrations, and full cloud integrations are areas in which I am very experienced.

    What needs improvement?

    My customer wants the tool's OCR feature improved. The tool's user interface and document fingerprinting have been very poor for my customers because uploading files manually can be problematic.

    The product's scalability is an area with certain shortcomings, making it an aspect where improvements are required.

    For how long have I used the solution?

    I have been using Microsoft Purview Data Loss Prevention for five years. I work as Microsoft's strategic partners in Istanbul, especially for Microsoft Office 365 products.

    What do I think about the stability of the solution?

    Stability-wise, I rate the solution a nine out of ten.

    What do I think about the scalability of the solution?

    The tool offers medium scalability and not an advanced one. Scalability-wise, I rate the solution a two out of ten.

    Around 300 people are using the tool.

    I have used the tool in large infrastructures over a period of three to four years.

    How are customer service and support?

    My company's teams have communicated with the solution's technical support via emails. Based on my customer's experiences, I rate the technical support a five or six out of ten. The tool's support helped my company in areas like information protection, integration support, sensitive info types, custom keywords, and keyword dictionaries. The technical support experts that I communicated with were effective in resolving my issues.

    How would you rate customer service and support?

    Neutral

    Which solution did I use previously and why did I switch?

    I have used Forcepoint Data Loss Prevention, NetSense, McAfee, and Symantec. I started to use Microsoft Purview Data Loss Prevention since I had to work with Microsoft in a collaborative manner.

    How was the initial setup?

    When it comes to the product's initial setup phase, it is difficult, especially when it comes to the DLP endpoint onboarding of agents. There are some policies that are complex for some of my customers. With all the service integrations, you can work with Microsoft Purview Data Loss Prevention in very complex architectures.

    With the tool, creating policies is easy, but its settings may be difficult. If one is difficult, and ten is easy, I rate the tool's installation phase as a three out of ten. When it comes to e-commerce or credit card numbers, there can be some installation issues, which is a problem for my customers.

    The solution is deployed using the cloud services offered by Microsoft Azure.

    Our company deployed the solution for seven or nine projects, including PoCs and demos. A couple of hours were needed to deploy the tool.

    The product's deployment phase involved the creation of policies and the onboarding of users.

    The tool's deployment requires around four people, and its maintenance requires a minimum of ten people.

    What's my experience with pricing, setup cost, and licensing?

    The tool was not very expensive. If one is very cheap and ten is very expensive, I rate the price as one out of ten.

    What other advice do I have?

    Microsoft Purview Data Loss Prevention has been effective in identifying and mitigating potential data leaks. Microsoft handles the XDR for the endpoints and helps prevent data leaks.

    I rate the tool a ten out of ten.

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Microsoft Azure
    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    Bryan Sprowls - PeerSpot reviewer
    Senior technical consultant at a computer software company with 501-1,000 employees
    Consultant
    Dec 14, 2023
    An affordable and easily scalable tool that decreases the risk of data leakage in an organization
    Pros and Cons
    • "The product can block the uploads to cloud services."
    • "The support is poor."

    What is our primary use case?

    We do implementations for Endpoint DLP and the cloud-based DLP. It can prevent the exfiltration of documentation, automate the classification of documents, and look for PII. We work on any sensitive information that customers don't want to leave the environment.

    How has it helped my organization?

    The tool decreases the risk of data leakage for the organizations that we've been implementing it for, both accidental and intentional.

    What is most valuable?

    The product can block the uploads to cloud services. The users can justify why they want to do it if they want us to allow it.

    What needs improvement?

    The Endpoint DLP engine has a lot of delays. The just-in-time protection feature does not always work as expected, mainly when working with network files in a more classic environment.

    For how long have I used the solution?

    I've been implementing the solution for about a year and a half.

    What do I think about the stability of the solution?

    It's a fairly stable product. It requires a few more improvements.

    What do I think about the scalability of the solution?

    The tool is easily scalable.

    How are customer service and support?

    The support is poor. When it comes to DLP, the cases get tossed around a lot between Endpoint DLP and the cloud-based DLP. Sometimes, some information goes to the Microsoft Defender team. The cases get tossed around a lot.

    How would you rate customer service and support?

    Negative

    Which solution did I use previously and why did I switch?

    We mostly used the built-in Exchange DLP in the past.

    How was the initial setup?

    The initial setup is fairly straightforward. Our implementation strategy varies from customer to customer.

    What was our ROI?

    We have seen an ROI on the product because customers do not have to go to a third-party vendor to get the DLP functionality. A lot of customers already own the licensing port anyway.

    What's my experience with pricing, setup cost, and licensing?

    The pricing is good. It is a good value because it is bundled with a lot of things that people buy already.

    Which other solutions did I evaluate?

    Proofpoint DLP has been assessed for a lot of customers. Microsoft Purview Data Loss Prevention allows for a lot more integration into other areas within the Microsoft realm. Proofpoint doesn't really have that and the visibility and tie-ins into all the different areas.

    What other advice do I have?

    It is important to me that Purview delivers data protection across multi-cloud and multi-platform environments. Otherwise, we would have to have multiple DLP solutions. It is very important to me that the solution was built taking into account critical regulations from around the world. It makes it easier to templatize deployments for data loss prevention.

    I use the tool for data loss protection. The tool works fairly well in remediating policy violations. There could be a little bit of improvement in policy tips. Policy tips aren't consistent across different experiences.

    The tool has greatly impacted the visibility of most of our customers. Some of our customers didn't realize they had a lot of PII data being sent externally until after the tool was implemented. Later, they become more aware.

    The solution enables us to show our compliance as close to real-time as possible. It has affected our meetings with compliance regulators. We don't save time and money directly. The tool saves us time and money by saving on fines for regulatory compliance violations. Without the solution, one of our customers would have been fined about $2,500,000.

    It is important to me that the product can connect to iOS, Mac, and Android devices, as well as data in other SaaS apps. It's not a complete solution unless it can be used everywhere. We are implementers. People evaluating the product must understand the types of data and the compliance models they must adhere to.

    Overall, I rate the product an eight out of ten.

    Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
    PeerSpot user
    Buyer's Guide
    Download our free Microsoft Purview Data Loss Prevention Report and get advice and tips from experienced pros sharing their opinions.
    Updated: June 2026
    Buyer's Guide
    Download our free Microsoft Purview Data Loss Prevention Report and get advice and tips from experienced pros sharing their opinions.