Fix Microsoft Purview DLP Not Detecting ZIP Files on Network Drives
Question details
The user needs to resolve an issue where Microsoft Purview Endpoint DLP fails to block or report ZIP file activities on a mapped network drive, despite functioning correctly on local OneDrive folders.

- Product
- Microsoft Purview
- Device & OS
- not provided
- Scenario
- Attempting to monitor and block ZIP file uploads or transfers from a mapped network drive using Endpoint DLP policies.
- Observed behavior
- Endpoint DLP successfully detects ZIP files on local OneDrive folders but fails to detect, block, or report ZIP file activities originating from mapped network drives.
Ensure you have global administrator or DLP compliance management permissions in the Microsoft Purview compliance portal before modifying active policies.
Configure DLP Rules and Verify Endpoint Onboarding
Update your DLP policy to explicitly include the .zip extension and ensure all target devices and network locations are correctly onboarded.
Endpoint DLP may ignore network drive activities if the file extensions are not explicitly defined or if the network location falls outside the supported scope of your current policy.
Log in to the Microsoft Purview compliance portal, navigate to your DLP policies, edit the relevant rule, and add '.zip' to the file extension conditions alongside the required blocking actions.
Check the device onboarding status in the portal settings to ensure the client devices and file servers are actively reporting to Endpoint DLP.
Verify that mapped network drives are included in your Endpoint DLP settings and that these specific network locations are not explicitly excluded by your current policy scope.
Wait for the policy to deploy, then test by transferring a simple ZIP file. If the event is still missed, review the Endpoint DLP diagnostic logs using the Event Viewer on the client device.

Secure Your Documents with WPS Office
While Microsoft Purview handles enterprise-level data loss prevention, if you are looking for a secure, lightweight, and cost-effective office suite for your daily document management, WPS Office is the perfect choice. It offers robust local file protection, document encryption, and seamless compatibility with Microsoft formats.
- 1. Download WPS Office: Visit the official WPS website and click 'Download WPS Office Free' to get the installer.
- 2. Install the Software: Run the downloaded installer and follow the on-screen prompts to set up the suite on your device.
- 3. Open and Secure Files: Open your existing Microsoft Office documents and use the 'Encrypt' feature under the 'Protect' tab to secure your sensitive data.

Frequently Asked Questions
Why does Endpoint DLP work for local OneDrive but not network drives?
Local OneDrive folders are natively monitored and deeply integrated with Windows OS and Endpoint DLP. Mapped network drives may require explicit inclusion in your DLP network location settings or might be excluded by default network share policies.
How long does it take for a Microsoft Purview DLP policy to update?
After modifying a DLP rule, it typically takes an hour for the policy to sync in the backend, but it can take up to 24 hours to fully deploy and enforce across all onboarded endpoint devices.
Where can I find Endpoint DLP diagnostic logs?
You can view Endpoint DLP diagnostic events on the client device by opening the Event Viewer and navigating to Applications and Services Logs > Microsoft > Windows > Microsoft-Windows-SenseIR.




