How to Block PHI or PII Uploads on a Specific SharePoint Site
Question details
A healthcare organization needs to prevent files containing Protected Health Information (PHI) or Personally Identifiable Information (PII) from being uploaded to a specific SharePoint site while permitting uploads to other sites.

- Product
- Microsoft SharePoint
- Device & OS
- not provided
- Scenario
- Administrators want to enforce data protection regulations by restricting sensitive information uploads on a per-site basis within SharePoint.
- Observed behavior
- SharePoint lacks a native, built-in setting directly on the site level to block specific sensitive information types like PHI or PII.
Ensure you have the necessary Compliance Administrator or Global Administrator privileges in your Microsoft 365 tenant to access and configure Microsoft Purview.
Configure Microsoft Purview Data Loss Prevention (DLP) Policies
Use Microsoft Purview to create a targeted DLP policy that detects and blocks the upload of sensitive information to your specific SharePoint site.
While SharePoint does not have a localized setting to block PHI/PII uploads, Microsoft Purview provides tenant-wide compliance tools. You can create a DLP policy customized to recognize health and personal data and restrict its application exclusively to the URL of the SharePoint site in question.
Log in to the Microsoft Purview compliance portal with administrator credentials and navigate to the 'Data loss prevention' section in the left-hand menu.
Click on 'Policies' and then select 'Create policy'. Choose a template under 'Medical and health' or 'Privacy' that covers the specific PHI or PII types you need to protect, and click 'Next'.
In the 'Locations to apply the policy' step, toggle the status for 'SharePoint sites' to On. Click 'Edit' or 'Choose sites' and enter the specific URL of the SharePoint site you wish to restrict, ensuring other sites are excluded.
Under the 'Policy settings', configure the rules to block users from sharing, saving, or uploading documents that contain the selected sensitive information types to this location. Save and turn on the policy.

Submit Feature Feedback to the SharePoint Team
Request that Microsoft adds a native site-level setting to block sensitive uploads directly within SharePoint.
Need a Fast, Secure Office Suite for Daily Tasks?
While you manage complex Microsoft 365 compliance and DLP policies, you may need a reliable, standalone office suite for daily document processing. WPS Office offers a lightweight, highly compatible alternative for securely creating and editing files offline.
- 1. Download WPS Office: Visit the official WPS Office website and download the free installation package for your operating system.
- 2. Install and Set Up: Run the installer and follow the on-screen prompts to set up WPS Office on your computer.
- 3. Secure Your Documents: Open your documents in WPS Office and use the built-in encryption features under the 'Menu' > 'Document Encryption' to protect sensitive data before sharing.

Frequently Asked Questions
Can I block PHI uploads using SharePoint's native site settings menu?
No, SharePoint currently does not offer a built-in, localized feature within the site settings to selectively block files based on sensitive information types like PHI or PII.
What is Microsoft Purview and how does it help with SharePoint data?
Microsoft Purview is a comprehensive suite of data governance and compliance solutions. It allows organizations to discover, classify, and protect sensitive data across Microsoft 365 services, including enforcing Data Loss Prevention (DLP) rules on SharePoint sites.
Can Microsoft Purview DLP policies be applied to just one SharePoint site?
Yes. When configuring the 'Locations' setting in a Microsoft Purview DLP policy, administrators can specifically include or exclude individual SharePoint site URLs to ensure the rules only apply where needed.




