logo
search
Compliance Problems

How to Allow Specific Users or Domains Through Microsoft Purview DLP

Maira MehtabMaira Mehtab Sep 22, 2026 868 views

Question details

The user needs to know how to configure exceptions in Microsoft Purview Data Loss Prevention (DLP) to allow specific trusted users or domains to receive sensitive information.

Product
Microsoft Purview
Device & OS
not provided
Scenario
Configuring email flow rules and DLP policies to securely share sensitive data with approved external contacts.
Observed behavior
DLP policies block external messages containing financial or sensitive data by default, preventing communication with necessary external partners unless an exception is added.
Before you start

Before making changes to data loss prevention settings, ensure you have Microsoft Purview Compliance Administrator permissions and have obtained formal approval from your organization's security team.

Solution 1Recommended

Add Exceptions to Microsoft Purview DLP Policies

Modify existing DLP policies in the compliance portal to include exceptions for specific users, groups, or domains to bypass default blocking rules.

This method directly updates the central Microsoft Purview policies. It is the most secure and controlled way to allow specific external communication without broadly whitelisting recipients across your entire organization.

1
Access the Compliance Portal

Log in to the Microsoft Purview compliance portal using your administrator credentials.

2
Navigate to DLP Policies

Select 'Data loss prevention' from the left-hand menu, and then click on 'Policies'.

3
Edit the Target Policy

Select the policy you want to modify, click 'Edit policy', and proceed to the 'Advanced DLP rules' section to find the rule blocking the external messages.

4
Configure Exceptions

Under the 'Exceptions' section, click 'Add exception'. Choose 'Except if the recipient is' for individual users or 'Except if the recipient domain is' for entire organizations.

5
Save and Submit

Enter the approved email addresses or trusted domains, save the updated rule, and submit the policy to apply your changes.

Alternative to Exceptions: Depending on your policy requirements, you can configure the rule to block the content but allow users to override the block by submitting a formal business justification.
Free Microsoft Office alternative

Looking for a Lightweight, Secure Alternative to Microsoft Office?

While Microsoft 365 offers enterprise compliance tools like Purview DLP, you might just need a robust, cost-effective office suite for creating and managing daily documents. WPS Office is a highly compatible, free alternative that supports Word, Excel, and PowerPoint formats in one unified application.

  1. 1. Download WPS Office: Get the free installer from the official WPS Office website.
  2. 2. Install and Launch: Run the installer to set up the software, then open the unified WPS Office suite.
  3. 3. Secure Your Files: Use the built-in encryption feature in WPS to password-protect your sensitive documents before sending them to external recipients.
Fully compatible with Microsoft Office formats (.docx, .xlsx, .pptx).Built-in robust document encryption and password protection features for securing sensitive data before sharing.Lightweight installation and resource-friendly performance.Familiar user interface requiring zero learning curve for seamless migration.
microsoft office alternative - wps office

Frequently Asked Questions

Can I allow an override instead of fully whitelisting a domain in Purview?

Yes, Microsoft Purview DLP policies can be configured to block the email but allow the sender to override the block by providing a formal business justification in their Outlook client.

Why are my DLP policy exceptions not applying immediately?

Changes to Microsoft Purview DLP policies can take up to 24 hours to sync and fully apply across all Exchange and Microsoft 365 services within your tenant.

Who can approve exceptions to Purview DLP policies?

Exceptions must typically be reviewed and approved by your organization's compliance officers or security administrators before they are safely implemented in the Purview portal.