logo
search
Data Protection Issues

Fix Microsoft Purview DLP Not Detecting ZIP Files on Network Drives

Phi Hung VoPhi Hung Vo Sep 30, 2026 869 views

Question details

The user needs to resolve an issue where Microsoft Purview Endpoint DLP fails to block or report ZIP file activities on a mapped network drive, despite functioning correctly on local OneDrive folders.

Fix Microsoft Purview DLP Not Detecting ZIP Files on Network Drives
Product
Microsoft Purview
Device & OS
not provided
Scenario
Attempting to monitor and block ZIP file uploads or transfers from a mapped network drive using Endpoint DLP policies.
Observed behavior
Endpoint DLP successfully detects ZIP files on local OneDrive folders but fails to detect, block, or report ZIP file activities originating from mapped network drives.
Before you start

Ensure you have global administrator or DLP compliance management permissions in the Microsoft Purview compliance portal before modifying active policies.

Solution 1Recommended

Configure DLP Rules and Verify Endpoint Onboarding

Update your DLP policy to explicitly include the .zip extension and ensure all target devices and network locations are correctly onboarded.

Endpoint DLP may ignore network drive activities if the file extensions are not explicitly defined or if the network location falls outside the supported scope of your current policy.

1
Update File Extension Conditions

Log in to the Microsoft Purview compliance portal, navigate to your DLP policies, edit the relevant rule, and add '.zip' to the file extension conditions alongside the required blocking actions.

2
Verify Device Onboarding

Check the device onboarding status in the portal settings to ensure the client devices and file servers are actively reporting to Endpoint DLP.

3
Confirm Network Location Support

Verify that mapped network drives are included in your Endpoint DLP settings and that these specific network locations are not explicitly excluded by your current policy scope.

4
Test and Review Logs

Wait for the policy to deploy, then test by transferring a simple ZIP file. If the event is still missed, review the Endpoint DLP diagnostic logs using the Event Viewer on the client device.

Configure DLP Rules and Verify Endpoint Onboarding
Policy Deployment Time: DLP policy updates can take up to 24 hours to fully sync and apply to all onboarded endpoint devices.
Free Microsoft Office alternative

Secure Your Documents with WPS Office

While Microsoft Purview handles enterprise-level data loss prevention, if you are looking for a secure, lightweight, and cost-effective office suite for your daily document management, WPS Office is the perfect choice. It offers robust local file protection, document encryption, and seamless compatibility with Microsoft formats.

  1. 1. Download WPS Office: Visit the official WPS website and click 'Download WPS Office Free' to get the installer.
  2. 2. Install the Software: Run the downloaded installer and follow the on-screen prompts to set up the suite on your device.
  3. 3. Open and Secure Files: Open your existing Microsoft Office documents and use the 'Encrypt' feature under the 'Protect' tab to secure your sensitive data.
Fully compatible with Microsoft Word, Excel, and PowerPoint formats (.docx, .xlsx, .pptx).Built-in document encryption and permission settings to secure sensitive files locally.Lightweight design with fast installation and smooth operation on any device.Free to use with a familiar user interface, requiring zero learning curve.
microsoft office alternative - wps office

Frequently Asked Questions

Why does Endpoint DLP work for local OneDrive but not network drives?

Local OneDrive folders are natively monitored and deeply integrated with Windows OS and Endpoint DLP. Mapped network drives may require explicit inclusion in your DLP network location settings or might be excluded by default network share policies.

How long does it take for a Microsoft Purview DLP policy to update?

After modifying a DLP rule, it typically takes an hour for the policy to sync in the backend, but it can take up to 24 hours to fully deploy and enforce across all onboarded endpoint devices.

Where can I find Endpoint DLP diagnostic logs?

You can view Endpoint DLP diagnostic events on the client device by opening the Event Viewer and navigating to Applications and Services Logs > Microsoft > Windows > Microsoft-Windows-SenseIR.