DLP Policy Tip displays in Outlook Classic but not in Outlook on the Web despite successful DLP rule match

Nancy Daniel 20 Reputation points
2026-09-28T09:10:42.6333333+00:00

Hello Team,

I'm testing a Microsoft Purview DLP policy in our REF tenant and would like assistance understanding an inconsistency between Outlook Classic and Outlook on the Web (OWA).

DLP Policy Configuration

Location

  • Exchange Online

Admin Unit

  • Full Directory

Policy Mode

  • Show policy tips while in simulation mode

DLP Rule Conditions

Condition 1 Content contains one of the following sensitivity labels:

  • Högt Skyddsvärde
  • Högt Skyddsvärde / Sveriges Radio - Begränsa behörighet
  • Högt Skyddsvärde / SRF - Begränsa behörighet
  • Högt Skyddsvärde / Sveriges Radio Högt Skyddsvärde

Evaluation:

  • Message or attachment

Condition 2

Sender domain is:

  • refXXXXX.com
  • groups.refXXXXX.com
  • groups.refXXXXX.com

Condition 3

Content is shared from Microsoft 365 with people outside the organization.

Actions

  • Notify users with email and policy tips
  • Generate administrator alerts
  • Generate incident reports

Test Performed

A test email was sent:
From: internal ID
To: external ID
**The email and attachment were labelled with a Högt Skyddsvärde sensitivity label.

DLP Rule Match Confirmed**

The DLP notification email confirms that the following conditions matched:

  • Contains sensitive information
  • Sender Domain
  • External recipients

The notification also confirms:

  • Rule matched successfully
  • NotifyUser action executed
  • GenerateAlert action executed
  • Policy Mode: AuditAndNotify
  • Type: SensitivityLabel

Outlook Classic

Initially no Policy Tip was shown.

After refreshing the compose window:

✅ Sensitivity label description appeared.

✅ DLP Policy Tip appeared.

**Outlook on the Web (OWA)
**Using the same sender, recipients and labelled content:

❌ No DLP Policy Tip displayed.

❌ No sensitivity label description displayed.

The label itself is visible and applied, but the descriptive text and DLP Policy Tip are not displayed.

Questions

  1. Is this behaviour expected between Outlook Classic and Outlook on the Web?
  2. Are there any known limitations or prerequisites for displaying:
    • DLP Policy Tips in OWA
    • Sensitivity label descriptions in OWA
  3. Given that:
    • the DLP rule matched successfully,
    • notifications were generated,
    • alerts were generated,
    • the Policy Tip appears in Outlook Classic,
    does Microsoft consider the current DLP configuration to be correct?
  4. Are there additional service-side or client-side settings that must be enabled for OWA to display:
    • DLP Policy Tips
    • Sensitivity label descriptions
  5. Is the refresh behaviour observed in Outlook Classic expected, or should the Policy Tip appear immediately without manual refresh?
Microsoft Security | Microsoft Purview
0 comments No comments

1 answer

Sort by: Most helpful
  1. AI answer

    2026-09-28T09:11:06.02+00:00

    Based on the described results, the DLP rule configuration is at least matching and enforcing the configured actions, because the notification email confirms the rule matched, NotifyUser executed, alerts were generated, and the policy mode is AuditAndNotify.

    For Outlook on the web, DLP policy tips are supported while composing a new email when content matches a DLP rule that uses policy tips. The tip appears at the top of the message above the recipients. Policy tips can evaluate content in the message body, subject, and attachments. There can be latency between adding sensitive information and the policy tip appearing.

    For Outlook Classic, the refresh behavior is not ideal but some delay can occur. Microsoft documents latency between adding sensitive information and the policy tip appearing. In Outlook for Microsoft 365, DLP processing is also limited to the first 4 MB of message content and up to 2 MB of attachments for policy tip classification.

    What is not supported by the available documentation is a statement that this difference between Classic Outlook and OWA is expected for the same correctly matched Exchange Online DLP policy. The documented expectation is that OWA should show policy tips when the composed message matches a DLP rule configured to use them.

    Specific checks for OWA:

    1. Verify the policy is configured to use User notifications and that the policy status matches the rule settings. A known configuration problem is when the rule is configured for notifications but the policy status is still Test it out first.
    2. Review the rule design for overlapping or duplicate rules that detect the same data with the same instance count and confidence level. Microsoft documents that only one such rule should be used.
    3. In Microsoft Purview portal, go to Data Loss Prevention > Policies > Edit Policy and confirm:
      • the configured condition actually matches the draft message content
      • thresholds and confidence settings are not too strict
      • the policy is correctly published and assigned
    4. For OWA specifically, run the HAR diagnostic in the Microsoft Purview portal. It can determine whether:
      • policy tips are not enabled in policy settings
      • the message content does not match the configured policy conditions
      • OWA did not send a GetDlpPolicyTips request
    5. If the HAR diagnostic shows no DLP evaluation request or a service evaluation error, the documented next step is to contact Microsoft Support.

    Important limitations and prerequisites from the documentation:

    • Mailboxes must be hosted in Exchange Online.
    • Policy tips can work either with DLP policies and mail flow rules created in the Exchange admin center, or with DLP policies, but not both at the same time for policy tip sourcing.
    • When emails are encrypted with Microsoft Purview Message Encryption and the detection uses the detected encryption condition, policy tips do not appear.
    • In Outlook for Microsoft 365, only the first 4 MB of message content and up to 2 MB of attachments are processed for policy tips.

    On sensitivity label descriptions in OWA, the available documentation does not provide supported guidance about prerequisites or limitations for displaying the label description text itself. Only the DLP policy tip behavior is documented here.

    So, for the questions:

    1. No documented evidence shows that Classic displaying the tip while OWA does not is expected behavior.
    2. DLP policy tips are supported in OWA for matching Exchange Online DLP policies, with latency possible. No supported guidance is available here for sensitivity label description display in OWA.
    3. Yes, the current DLP configuration is matching and executing actions. That confirms the rule is functioning at the policy/action level, but not that OWA client display is healthy.
    4. The documented next validation for OWA is the HAR diagnostic in Purview, followed by support if no evaluation request or a service error is found.
    5. Some latency is expected; immediate appearance is not guaranteed by the documentation.

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.