Microsoft Purview: Inconsistent DLP rule behavior with exclusions — Unexpected message matches despite exclusions

Chris Irving 0 Reputation points
2026-10-08T16:36:49.9733333+00:00

Problem description

I am experiencing an issue with a Microsoft Purview Data Loss Prevention (DLP) rule configured to exclude messages that are Encrypted or Permission Controlled. Despite these exclusions, Activity Explorer shows that certain messages, including those containing sensitive information like a test U.S. Social Security Number, are still matching the rule. I am seeking clarification on why this discrepancy occurs and how to ensure the rule's exclusions are functioning correctly.

Environment

Microsoft Purview DLP in Exchange email within Microsoft 365, region not specified in case information.

What I've already tried

I have reviewed the rule configuration manually in the Purview policy editor to confirm that the exclusions for Message Type = Encrypted and Permission Controlled are present. I compared the rule behavior with an Activity Explorer event showing a match on an email containing sensitive information. The troubleshooting is limited to initial validation at case intake; no additional diagnostic outputs or configuration changes have been documented.

Current status

I am seeking assistance to understand why messages are matching the rule despite the exclusions and how to verify the message's encryption or permission control status at the time of evaluation.

Microsoft Security | Microsoft Purview

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.