Clarification required on DLP policy scoping when using an Administrative Unit

Nancy Daniel 20 Reputation points
2026-09-24T10:09:28.8633333+00:00

Hello Team,

I'm configuring a Microsoft Purview DLP policy in our REF tenant to test a user-facing policy tip for external sharing of content labelled Högt Skyddsvärde (High Confidential).

The policy is currently configured as follows:

  • Administrative Unit: AU-F Purview groups (Just 6 members)
  • Exchange email: All accounts
  • SharePoint sites: All sites
  • OneDrive accounts: All accounts
  • Policy mode: On

The selected Administrative Unit contains the users intended to participate in the REF test.

I need clarification on how the Administrative Unit interacts with the individual location scopes.

Questions:

When an Administrative Unit is assigned to the DLP policy, does the Administrative Unit automatically restrict the policy to its members, even when the locations are configured as:

  • Exchange email: All accounts
    • SharePoint sites: All sites
      • OneDrive accounts: All accounts
      For Exchange Online and OneDrive, do we also need to select the same test users or groups under the location settings, or would this be unnecessary duplicate scoping? For SharePoint Online, an Administrative Unit contains users and groups rather than sites. If All sites is selected, will the policy evaluate activity performed by the Administrative Unit members across all SharePoint sites, or will it apply to all users and activity across all sites? What is the Microsoft-recommended configuration if the expected result is:
      - Only users included in the Administrative Unit should be part of the REF test.
      
         - The policy should evaluate their external-sharing activity across Exchange Online, SharePoint Online and OneDrive.
      
            - Users outside the Administrative Unit should not receive the policy tip.
      

Please confirm whether our current configuration meets this expected result or whether the location scopes must also be changed to specific users, groups, or SharePoint sites.

Thanks for the support!
Nancy

Microsoft Security | Microsoft Purview
0 comments No comments

1 answer

Sort by: Most helpful
  1. AI answer

    2026-09-24T10:09:54.9066667+00:00

    The current configuration does not mean the policy will evaluate all users everywhere just because the locations are set to All accounts or All sites.

    Supported behavior by location is:

    • Exchange Online supports Administrative Units.
    • SharePoint supports Administrative Units.
    • OneDrive supports Administrative Units.

    For these locations, when the policy is scoped to an Administrative Unit, the policy is limited to that Administrative Unit for the supported workload.

    For the expected result described:

    • only users in the Administrative Unit participate in the REF test
    • their activity is evaluated in Exchange Online, SharePoint Online, and OneDrive
    • users outside the Administrative Unit do not receive the policy tip

    the Administrative Unit is the key boundary for the policy.

    Specific guidance by workload:

    1. Exchange Online
      • Exchange supports Administrative Units.
      • If the policy is scoped to the Administrative Unit, selecting All accounts at the Exchange location does not require duplicating the same users or groups again under Exchange scoping.
      • Adding the same users/groups again would be unnecessary duplicate scoping.
    2. OneDrive
      • OneDrive supports Administrative Units.
      • If the policy is scoped to the Administrative Unit, selecting All accounts for OneDrive does not require selecting the same users or groups again under the OneDrive location.
      • Duplicate user/group scoping is unnecessary unless there is a separate need to narrow the scope further.
    3. SharePoint Online
      • SharePoint supports Administrative Units.
      • The documented behavior is explicit: if the policy is scoped to an Administrative Unit that includes SharePoint sites, the policy will only apply to all sites in the Administrative Unit, and no further scoping is possible.
      • This means SharePoint behavior depends on whether the Administrative Unit includes SharePoint sites. It is not described as “all activity on all sites by AU users.”
      • With All sites selected, the policy does not become tenant-wide for all users if the policy is scoped to an Administrative Unit. For SharePoint, the Administrative Unit still constrains scope.

    Recommended configuration for the test objective:

    1. Scope the DLP policy to the Administrative Unit that contains the intended REF test population.
    2. Keep Exchange email = All accounts.
    3. Keep OneDrive accounts = All accounts.
    4. For SharePoint, verify that the Administrative Unit includes the SharePoint sites that should be in scope.
    5. Do not add the same test users/groups again under Exchange or OneDrive unless there is a deliberate need to narrow scope further.

    Important SharePoint caveat:

    • SharePoint scoping under an Administrative Unit is site-based at the Administrative Unit level.
    • If the relevant SharePoint sites are not part of the Administrative Unit, the policy will not apply to those sites.
    • Also, when the policy is scoped to an Administrative Unit that includes SharePoint sites, no additional SharePoint site scoping is available.

    So, the current configuration meets the expected result for Exchange Online and OneDrive without needing duplicate user/group selection in those locations.

    For SharePoint Online, the current configuration meets the expected result only if the Administrative Unit includes the SharePoint sites intended for the REF test. If the Administrative Unit contains only users/groups and not the needed SharePoint sites, then the SharePoint portion will not align with the expected result.


    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.