A unified data governance solution that helps manage, protect, and discover data across your organization
Based on the described results, the DLP rule configuration is at least matching and enforcing the configured actions, because the notification email confirms the rule matched, NotifyUser executed, alerts were generated, and the policy mode is AuditAndNotify.
For Outlook on the web, DLP policy tips are supported while composing a new email when content matches a DLP rule that uses policy tips. The tip appears at the top of the message above the recipients. Policy tips can evaluate content in the message body, subject, and attachments. There can be latency between adding sensitive information and the policy tip appearing.
For Outlook Classic, the refresh behavior is not ideal but some delay can occur. Microsoft documents latency between adding sensitive information and the policy tip appearing. In Outlook for Microsoft 365, DLP processing is also limited to the first 4 MB of message content and up to 2 MB of attachments for policy tip classification.
What is not supported by the available documentation is a statement that this difference between Classic Outlook and OWA is expected for the same correctly matched Exchange Online DLP policy. The documented expectation is that OWA should show policy tips when the composed message matches a DLP rule configured to use them.
Specific checks for OWA:
- Verify the policy is configured to use User notifications and that the policy status matches the rule settings. A known configuration problem is when the rule is configured for notifications but the policy status is still Test it out first.
- Review the rule design for overlapping or duplicate rules that detect the same data with the same instance count and confidence level. Microsoft documents that only one such rule should be used.
- In Microsoft Purview portal, go to Data Loss Prevention > Policies > Edit Policy and confirm:
- the configured condition actually matches the draft message content
- thresholds and confidence settings are not too strict
- the policy is correctly published and assigned
- For OWA specifically, run the HAR diagnostic in the Microsoft Purview portal. It can determine whether:
- policy tips are not enabled in policy settings
- the message content does not match the configured policy conditions
- OWA did not send a
GetDlpPolicyTipsrequest
- If the HAR diagnostic shows no DLP evaluation request or a service evaluation error, the documented next step is to contact Microsoft Support.
Important limitations and prerequisites from the documentation:
- Mailboxes must be hosted in Exchange Online.
- Policy tips can work either with DLP policies and mail flow rules created in the Exchange admin center, or with DLP policies, but not both at the same time for policy tip sourcing.
- When emails are encrypted with Microsoft Purview Message Encryption and the detection uses the detected encryption condition, policy tips do not appear.
- In Outlook for Microsoft 365, only the first 4 MB of message content and up to 2 MB of attachments are processed for policy tips.
On sensitivity label descriptions in OWA, the available documentation does not provide supported guidance about prerequisites or limitations for displaying the label description text itself. Only the DLP policy tip behavior is documented here.
So, for the questions:
- No documented evidence shows that Classic displaying the tip while OWA does not is expected behavior.
- DLP policy tips are supported in OWA for matching Exchange Online DLP policies, with latency possible. No supported guidance is available here for sensitivity label description display in OWA.
- Yes, the current DLP configuration is matching and executing actions. That confirms the rule is functioning at the policy/action level, but not that OWA client display is healthy.
- The documented next validation for OWA is the HAR diagnostic in Purview, followed by support if no evaluation request or a service error is found.
- Some latency is expected; immediate appearance is not guaranteed by the documentation.