Quick-reference tables for SharePoint Online Data Loss Prevention policy defaults, modes, and site-level behaviors as configured through the Microsoft Purview compliance portal.
| Area | Default value or behavior |
|---|---|
| New policy mode | Test mode with policy tips enabled |
| Sensitive info type instance count (minimum) | 1 (at least one instance triggers the rule) |
| Sensitive info type instance count (maximum) | Any (no upper cap unless specified) |
| Confidence threshold | High confidence (75% or above for most built-in types) |
| Policy tip display | Enabled by default when Test mode is selected |
| Auto-labeling throughput per tenant per day | 500,000 files (increased from 100,000 in July 2026) |
| DLP alert email | Disabled by default; configured manually per rule |
| Incident report severity | High severity incidents reported by default |
| Existing file scan on policy creation | Files crawled on initial policy application; new uploads scanned on save |
| Quarantine action availability | Generally available from mid-2026; off by default in new rules |
What are the DLP policy modes in SharePoint Online?
Every Microsoft Purview DLP policy runs in one of three modes that determine whether it blocks actions, shows policy tips, or just observes and logs.
| Mode | Protective actions taken? | Policy tips shown? | Matches logged? | Typical use |
|---|---|---|---|---|
| Test (policy tips off) | No | No | Yes | Silent baselining: understand match volume before users see anything |
| Test (policy tips on) [default for new policies] | No | Yes | Yes | User awareness: surface policy tips without blocking any action |
| Enforce | Yes | Yes | Yes | Full enforcement: blocks or restricts actions on matching content |
SharePoint-specific DLP actions and their defaults
SharePoint Online's DLP actions differ from those in Exchange Online or Teams - and most are off by default even when a policy is in Enforce mode.
| Action | Default state in new rules | What it does | User override available? |
|---|---|---|---|
| Block external sharing | Off | Removes external sharing links on the matching file; external users lose access immediately | Yes, if business justification override is configured in the rule |
| Block all sharing | Off | Prevents any sharing (internal or external) of the file until the policy is removed or the file is remediated | No; admin must change the file or the policy |
| Quarantine file | Off (GA from mid-2026) | Moves the matching file to a quarantine location; replaces it with a notice document at the original position; admin reviews and releases from Purview portal | No; only compliance admins can release |
| Policy tip | On in Test mode; configurable in Enforce | Shows an in-context notification to users when they upload or share content matching the policy | User can dismiss; business justification can be captured if rule is configured for it |
| Incident report | High severity events reported; email recipient must be set manually | Sends an email or Microsoft Teams notification to configured recipients when a rule triggers | N/A (notification only) |
| Notify user (email) | Off | Sends an email to the content owner or last modifier explaining the policy match | N/A (notification only) |
For step-by-step guidance on recovering a file that a DLP quarantine action has moved out of its original library location, see the guide: how to restore a file from SharePoint DLP quarantine.
Sensitive information type defaults for SharePoint
Built-in sensitive information types in Microsoft Purview carry confidence and instance count defaults that control how many matches are required before a DLP rule triggers. The values below apply when adding a sensitive information type to a new rule without customisation.
| Default setting | Value out of the box | Adjustable? |
|---|---|---|
| Minimum instance count | 1 | Yes (1 to any) |
| Maximum instance count | Any (no upper cap) | Yes |
| Confidence level | High (75% and above for most built-in types) | Yes (Low, Medium, or High) |
| Supporting keyword evidence required | Not required; keyword groups are optional corroboration | Yes (add keyword groups to reduce false positives) |
| File extension exclusions | All file extensions scanned | Yes (exclude specific file types from the rule) |
| Sensitivity label exclusion | No label exclusions by default | Yes (exclude files already carrying a specific sensitivity or retention label) |
| SharePoint site scope | All SharePoint sites and OneDrive accounts in the tenant | Yes (include or exclude specific sites or OneDrive accounts) |
For the full reference on sensitivity label settings that interact with DLP policies in SharePoint Online, including encryption defaults and co-authoring behavior, see the SharePoint sensitivity label settings reference.
Frequently Asked Questions
What is the default DLP policy mode when you create a new policy in Microsoft Purview?
New DLP policies default to Test mode with policy tips enabled. The policy evaluates content and logs matches in Activity Explorer but takes no protective action. Admins switch the policy to Enforce mode when ready to block or restrict actions on matching content.
Do SharePoint DLP policies scan existing files or only new uploads?
DLP policies scan both existing files and new uploads. When a policy is first applied, Purview crawls files already in SharePoint. SharePoint triggers a rescan whenever a file is modified or moved. Initial crawls on large libraries can take hours to complete.
What happens to a file in SharePoint when a DLP policy quarantines it?
The file is moved to a quarantine location within SharePoint and replaced with a notice document in the original library position. Admins review and release quarantined files through the Purview compliance portal. This action became generally available in mid-2026 and is off by default in new rules.
How many files can Microsoft Purview auto-label per day in SharePoint?
As of July 2026, the auto-labeling throughput is 500,000 files per tenant per day, increased from the previous limit of 100,000. This applies to sensitivity label auto-labeling policies targeting SharePoint Online and OneDrive for Business content.