Request for Microsoft Confirmation – DLP Integration with Third-Party Applications

Ganesh Kitte 0 Reputation points
2026-09-07T02:19:26.7+00:00

DLP and Third-Party Application Integration

The customer has a requirement to extend DLP controls to third-party applications such as:

Keka HR

Salesforce

Other third-party SaaS applications that may be introduced in the future

With the Microsoft 365 Business Premium licensing currently available, we understand that Microsoft Purview DLP can provide protection for supported Microsoft 365 workloads such as Exchange Online, Microsoft Teams, SharePoint Online, and OneDrive, including detection/blocking of sensitive information such as Aadhaar numbers.

However, we would like to confirm the options available for extending DLP controls to third-party SaaS applications.

Specifically, please confirm:

Can Microsoft Purview DLP with Microsoft 365 Business Premium provide DLP controls for applications such as Keka HR and Salesforce?

If not, can Microsoft Defender for Cloud Apps (CASB) be used to provide the required visibility and DLP controls for these third-party applications?

What additional Microsoft licensing or add-ons would be required for this use case?

Can Defender for Cloud Apps provide controls such as monitoring, blocking, or restricting uploads of sensitive information to third-party SaaS applications?

Are there any prerequisites or limitations when integrating third-party applications with Microsoft Purview DLP / Defender for Cloud Apps?

For future SaaS applications, is there a recommended Microsoft architecture that would allow us to onboard additional applications and apply centralized DLP controls?

Request

Please review the above requirements and provide us with:

Microsoft's recommended architecture/configuration

Confirmation of supported scenarios

Any licensing prerequisites

Configuration prerequisites

Known limitations or considerations

Relevant Microsoft documentation, if available

This confirmation will help us finalize the solution design and proceed with the customer's implementation without impacting their existing user profiles or business operations.

Microsoft Security | Microsoft Purview

3 answers

Sort by: Most helpful
  1. Deleted

    This answer has been deleted due to a violation of our Code of Conduct. The answer was manually reported or identified through automated detection before action was taken. Please refer to our Code of Conduct for more information.


    Comments have been turned off. Learn more

  2. SIVASANKAR YEDDULA 170 Reputation points Microsoft External Staff Moderator
    2026-09-12T07:48:25.69+00:00

    Hello @Ganesh Kitte ,

    Thank you for sharing your requirements regarding extending Data Loss Prevention (DLP) controls to third-party SaaS applications such as Salesforce, Keka HR, and future cloud applications.

    Based on our analysis, Microsoft 365 Business Premium provides Microsoft Purview DLP protection for Microsoft 365 workloads, including Exchange Online, SharePoint Online, OneDrive, and Microsoft Teams. However, additional capabilities are required to extend DLP and real-time protection to third-party SaaS applications. Use data loss prevention policies for non-Microsoft cloud apps

    Recommended Mitigation and Architecture

    • Utilize Microsoft Defender for Cloud Apps (MDCA) to provide visibility and governance for supported third-party SaaS applications.
    • Configure Microsoft Purview DLP policies for supported connected applications such as Salesforce. Use data loss prevention policies for non-Microsoft cloud apps citeturn4search9
    • Implement Conditional Access App Control through Microsoft Defender for Cloud Apps to monitor user activities and enforce real-time controls such as:
    • Blocking sensitive uploads
    • Restricting downloads
    • Preventing data exfiltration
      • Session monitoring and access control Conditional Access app control - Microsoft Defender for Cloud Apps
      • For Keka HR and future SaaS applications, validate support for Microsoft Entra ID Single Sign-On (SSO), SAML 2.0, or OpenID Connect authentication, as these are prerequisites for onboarding custom applications through Conditional Access App Control. Manual onboarding of apps using Microsoft Entra ID citeturn4search7
      • Adopt a centralized security model using:
        • Microsoft Purview DLP
          • Microsoft Defender for Cloud Apps
            • Microsoft Entra Conditional Access

    Next Steps

    1. Review current licensing to determine the required Microsoft Defender for Cloud Apps and Microsoft Purview add-ons.
    2. Validate third-party application compatibility with Microsoft Entra ID federation.
    3. Identify applications requiring data-at-rest protection versus real-time session controls.
    4. Design and test onboarding for supported SaaS applications before production deployment.

    Please let us know if you would like assistance reviewing the licensing requirements or validating specific SaaS applications for onboarding and DLP enforcement.

    Best Regards,

    Sivasankar Yeddula
    Microsoft Azure Support.

    Was this answer helpful?

    0 comments No comments

  3. Deleted

    This answer has been deleted due to a violation of our Code of Conduct. The answer was manually reported or identified through automated detection before action was taken. Please refer to our Code of Conduct for more information.


    Comments have been turned off. Learn more

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.