Tenant DLP Coverage and Effectiveness Audit
TL;DR: This read-only skill lists your Microsoft Purview DLP policies across Exchange, SharePoint, OneDrive, Teams and endpoints, then reports coverage gaps, overlaps and simulation-mode policies, so you can see where sensitive data is unprotected and prioritise fixes.
What does Microsoft Purview DLP coverage actually mean?
Microsoft Purview Data Loss Prevention (DLP) lets your organisation define policies that identify, monitor and automatically protect sensitive items such as credit card numbers and health records. A policy is only effective when it covers every relevant location: Exchange Online email, SharePoint sites, OneDrive accounts, Microsoft Teams chat and channel messages, and devices running Windows 10, Windows 11 or the three latest macOS versions. Learn also lists other locations (on-premises repositories, Fabric and Power BI workspaces, and Microsoft 365 Copilot, which is in preview); this skill reports them only if present in your policies.
This skill inspects how policies map to sensitive information types (SITs), sensitivity labels and retention labels across those locations so you can see your real protection surface rather than assuming it. It also reviews policies running in simulation mode, which run as if enforced but apply no actions.
When should you run this skill?
- “Show me which Microsoft 365 workloads my DLP policies actually cover and where the gaps are.”
- “Are any DLP policies still stuck in simulation mode instead of enforcing?”
- “Do I have overlapping DLP policies that conflict or create duplicate alerts?”
- “Which sensitive information types are protected in email but not in Teams or endpoints?”
- “We are preparing for an audit and need evidence of our DLP coverage posture.”
- “After onboarding new sites and devices, confirm DLP still protects them.”
- “Help me prioritise which DLP gaps to remediate first by risk.”
How this skill works, step by step
- Connect read-only to Microsoft Purview using a least-privilege reader account, requesting no write or policy-modification access.
- Enumerate every DLP policy and its rules, capturing the locations each policy targets across Exchange, SharePoint, OneDrive, Teams and devices.
- Map each policy to the sensitive information types, sensitivity labels and retention labels it relies on for detection.
- Build a coverage matrix that cross-references locations against protected sensitive information types to expose locations with no protection.
- Detect overlaps where multiple policies target the same location and information type, flagging potential conflicts or duplicate alerts.
- Identify policies in simulation mode and summarise their results so you can judge readiness to enforce.
- Review policy rules to confirm the configured action (audit only, block with override or block) matches your intent where coverage exists.
- Derive a risk rating per gap by weighting the sensitivity of unprotected data, the exposure of the location, and whether enforcement is active. This rating is the skill’s own method, not a Microsoft-defined score.
- Compile the findings into a prioritised report with clear remediation guidance.
Output format
The skill produces a structured coverage report. Each row represents a location and sensitive information type combination, with its protection status and risk rating.
| Workload | Sensitive Info Type | Coverage Status | Mode | Risk |
|---|---|---|---|---|
| Microsoft Teams | Australia tax file number | Not covered | None | High |
| SharePoint Online | Credit card number | Covered | Enforced | Low |
| Endpoints | Australia bank account number | Covered | Simulation | Medium |
A summary follows the table:
- Total DLP policies inspected and how many are enforced versus in simulation.
- Count of uncovered location and information-type combinations, grouped by risk.
- Overlapping policies that may produce conflicting actions or duplicate alerts.
- Top prioritised remediation actions ordered by risk.
How does simulation mode affect the results?
| Behaviour | What Learn documents |
|---|---|
| Actions | Not applied while a policy is in simulation mode |
| Duration | Simulations can run for up to 15 days, so results are not a point-in-time snapshot |
| SharePoint and OneDrive | Existing and new or changed items are evaluated |
| Exchange, Teams and devices | Only items that are new during the simulation are evaluated |
| Retention | Simulation run data is kept for 30 days |
Treat “no matches” in simulation as inconclusive for Exchange, Teams and devices if the simulation window was short.
Scope and safety
This skill is read-only by default and makes no changes to your tenant, policies or data. It only reads policy configuration and simulation metadata to assess posture.
This skill does NOT:
- Create, modify, enable, disable or delete any DLP policy or rule.
- Change policies from simulation mode into enforcement mode.
- Access, export or move the content of any protected message, file or chat.
- Alter sensitivity labels, sensitive information types or any other configuration.
Licensing and permissions
Licences
| Capability used | Licensing per Microsoft Learn |
|---|---|
| DLP for Exchange Online, SharePoint Online and OneDrive | Included with Microsoft 365 or Office 365 E3 and E5 (and other plans listed in the Purview service description) |
| DLP for Teams chat and channel messages | Requires an E5-tier licence (for example Microsoft 365 E5 or E5 Compliance) |
| Endpoint DLP | Listed with Microsoft 365 E5 in Microsoft’s E3 versus E5 comparison; confirm in the Purview service description |
| DLP simulation mode | See the Microsoft 365 licensing guidance; confirm for your plan |
Least-privilege roles
- Global Reader or Security Reader, which hold the View-Only DLP Compliance Management role, to view DLP policy settings and reports.
- Information Protection Analysts (view-only access to DLP policies). Information Protection Readers see DLP reports only, so they cannot enumerate policies with Get-DlpCompliancePolicy.
- Do not use Compliance Administrator, Compliance Data Administrator or Information Protection Admin for this skill: those roles can create and edit DLP policies, which breaks the read-only scope.
- Learn states that interacting with simulation mode requires the Information Protection Admin role. If your reader account cannot see simulation results, have an administrator share the simulation dashboard rather than widening the skill’s access.
Access method
- The skill reads DLP configuration through the Microsoft Purview portal and Security & Compliance PowerShell, using
Get-DlpCompliancePolicy(optionally with-IncludeSimulationResults) andGet-DlpComplianceRule. The olderGet-DlpPolicycmdlet is retired from Exchange Online and is not used. - No Microsoft Graph permissions are requested.
Related skills
- Data Classification and SIT Coverage: run before this to see where sensitive information types match content
- Purview Label Coverage: run before this to check sensitivity label coverage across SharePoint libraries
- Copilot DLP Impact and Simulation: run after this to predict what DLP would block for Microsoft 365 Copilot
- Copilot Studio DLP Gap Check: run after this to map Copilot Studio agents to the tenant DLP policy
- Governing Microsoft 365 Copilot with Microsoft Purview: pillar page for the Purview controls documented for Microsoft 365 Copilot
Sources
- Learn about data loss prevention
- Learn about data loss prevention simulation mode : simulation mode replaces the Test and Test with policy tips policy states
- Get started with DLP simulation mode : permissions for interacting with simulation mode
- Test your Data Loss Prevention policies
- Create and deploy data loss prevention policies
- Data loss prevention and Microsoft Teams
- Microsoft Purview service description
- Prepare for Microsoft Copilot by comparing E3, E5, and E7 license features
- Roles and role groups in Microsoft Defender for Office 365 and Microsoft Purview
- Get-DlpCompliancePolicy
- Get-DlpComplianceRule
- Sensitive information type entity definitions
Licensed under CC BY 4.0 by EDUC4TE .
SKILL.md— paste into Microsoft 365 Copilot or ClaudeDownload▸ View skill file▾ Hide skill file
How to use this skill
- Get the file. Download or copy the
SKILL.mdfrom the SKILL.md panel on this page. - Load it into your host:
- Microsoft 365 Copilot / Copilot Studio — add it as the instructions of a declarative agent or Copilot Studio agent.
- Claude (Cowork / Claude Code) — drop the file into your skills folder; it loads as an Agent Skill automatically.
- Any chat host — paste the file contents as your prompt.
- Grant read-only access. Assign the least-privilege roles and Microsoft Graph scopes listed in Licensing and permissions section of this article.
- Provide your tenant scope and run it (a site, a collection, or the whole tenant).
- Review the report and action the risk-ranked recommendations.
This skill is read-only by default — it inspects and reports, and never changes your tenant.
Last reviewed 2026-10-01 · Published 2026-06-02