A unified data governance solution that helps manage, protect, and discover data across your organization
Microsoft Purview: Inconsistent DLP rule behavior with exclusions — Unexpected message matches despite exclusions
Problem description
I am experiencing an issue with a Microsoft Purview Data Loss Prevention (DLP) rule configured to exclude messages that are Encrypted or Permission Controlled. Despite these exclusions, Activity Explorer shows that certain messages, including those containing sensitive information like a test U.S. Social Security Number, are still matching the rule. I am seeking clarification on why this discrepancy occurs and how to ensure the rule's exclusions are functioning correctly.
Environment
Microsoft Purview DLP in Exchange email within Microsoft 365, region not specified in case information.
What I've already tried
I have reviewed the rule configuration manually in the Purview policy editor to confirm that the exclusions for Message Type = Encrypted and Permission Controlled are present. I compared the rule behavior with an Activity Explorer event showing a match on an email containing sensitive information. The troubleshooting is limited to initial validation at case intake; no additional diagnostic outputs or configuration changes have been documented.
Current status
I am seeking assistance to understand why messages are matching the rule despite the exclusions and how to verify the message's encryption or permission control status at the time of evaluation.