Your input shapes our product. Suggest a feature now →
  1. Home
  2. Tools
  3. DLP Policy Defaults Reference

SharePoint Online DLP Policy Defaults Reference

Quick-reference tables for SharePoint Online Data Loss Prevention policy defaults, modes, and site-level behaviors as configured through the Microsoft Purview compliance portal.

Area Default value or behavior
New policy mode Test mode with policy tips enabled
Sensitive info type instance count (minimum) 1 (at least one instance triggers the rule)
Sensitive info type instance count (maximum) Any (no upper cap unless specified)
Confidence threshold High confidence (75% or above for most built-in types)
Policy tip display Enabled by default when Test mode is selected
Auto-labeling throughput per tenant per day 500,000 files (increased from 100,000 in July 2026)
DLP alert email Disabled by default; configured manually per rule
Incident report severity High severity incidents reported by default
Existing file scan on policy creation Files crawled on initial policy application; new uploads scanned on save
Quarantine action availability Generally available from mid-2026; off by default in new rules

What are the DLP policy modes in SharePoint Online?

Every Microsoft Purview DLP policy runs in one of three modes that determine whether it blocks actions, shows policy tips, or just observes and logs.

Mode Protective actions taken? Policy tips shown? Matches logged? Typical use
Test (policy tips off) No No Yes Silent baselining: understand match volume before users see anything
Test (policy tips on) [default for new policies] No Yes Yes User awareness: surface policy tips without blocking any action
Enforce Yes Yes Yes Full enforcement: blocks or restricts actions on matching content
Note: Microsoft recommends running a new DLP policy in Test mode for at least one week before switching to Enforce. Activity Explorer in the Purview compliance portal shows match counts and affected files during the test window, letting you tune rules before enforcement begins and avoid blocking legitimate business content.
See how Report Master surfaces SharePoint file and permissions data

SharePoint-specific DLP actions and their defaults

SharePoint Online's DLP actions differ from those in Exchange Online or Teams - and most are off by default even when a policy is in Enforce mode.

Action Default state in new rules What it does User override available?
Block external sharing Off Removes external sharing links on the matching file; external users lose access immediately Yes, if business justification override is configured in the rule
Block all sharing Off Prevents any sharing (internal or external) of the file until the policy is removed or the file is remediated No; admin must change the file or the policy
Quarantine file Off (GA from mid-2026) Moves the matching file to a quarantine location; replaces it with a notice document at the original position; admin reviews and releases from Purview portal No; only compliance admins can release
Policy tip On in Test mode; configurable in Enforce Shows an in-context notification to users when they upload or share content matching the policy User can dismiss; business justification can be captured if rule is configured for it
Incident report High severity events reported; email recipient must be set manually Sends an email or Microsoft Teams notification to configured recipients when a rule triggers N/A (notification only)
Notify user (email) Off Sends an email to the content owner or last modifier explaining the policy match N/A (notification only)
Note: DLP content inspection does not apply to password-protected files or files encrypted with third-party tools. These files will not trigger content-based DLP rules regardless of what they contain - only filename and metadata are evaluated in those cases.

For step-by-step guidance on recovering a file that a DLP quarantine action has moved out of its original library location, see the guide: how to restore a file from SharePoint DLP quarantine.

Sensitive information type defaults for SharePoint

Built-in sensitive information types in Microsoft Purview carry confidence and instance count defaults that control how many matches are required before a DLP rule triggers. The values below apply when adding a sensitive information type to a new rule without customisation.

Default setting Value out of the box Adjustable?
Minimum instance count 1 Yes (1 to any)
Maximum instance count Any (no upper cap) Yes
Confidence level High (75% and above for most built-in types) Yes (Low, Medium, or High)
Supporting keyword evidence required Not required; keyword groups are optional corroboration Yes (add keyword groups to reduce false positives)
File extension exclusions All file extensions scanned Yes (exclude specific file types from the rule)
Sensitivity label exclusion No label exclusions by default Yes (exclude files already carrying a specific sensitivity or retention label)
SharePoint site scope All SharePoint sites and OneDrive accounts in the tenant Yes (include or exclude specific sites or OneDrive accounts)

For the full reference on sensitivity label settings that interact with DLP policies in SharePoint Online, including encryption defaults and co-authoring behavior, see the SharePoint sensitivity label settings reference.

Frequently Asked Questions

What is the default DLP policy mode when you create a new policy in Microsoft Purview?

New DLP policies default to Test mode with policy tips enabled. The policy evaluates content and logs matches in Activity Explorer but takes no protective action. Admins switch the policy to Enforce mode when ready to block or restrict actions on matching content.

Do SharePoint DLP policies scan existing files or only new uploads?

DLP policies scan both existing files and new uploads. When a policy is first applied, Purview crawls files already in SharePoint. SharePoint triggers a rescan whenever a file is modified or moved. Initial crawls on large libraries can take hours to complete.

What happens to a file in SharePoint when a DLP policy quarantines it?

The file is moved to a quarantine location within SharePoint and replaced with a notice document in the original library position. Admins review and release quarantined files through the Purview compliance portal. This action became generally available in mid-2026 and is off by default in new rules.

How many files can Microsoft Purview auto-label per day in SharePoint?

As of July 2026, the auto-labeling throughput is 500,000 files per tenant per day, increased from the previous limit of 100,000. This applies to sensitivity label auto-labeling policies targeting SharePoint Online and OneDrive for Business content.