logo
search
Data Protection Issues

How to Configure Microsoft Purview DLP Rules for External Teams Users

Maira MehtabMaira Mehtab Sep 28, 2026 870 views

Question details

The user needs to configure a Microsoft Purview Data Loss Prevention (DLP) rule to block sensitive information from being sent to external Microsoft Teams users without accidentally blocking internal messages.

Product
Microsoft Purview
Device & OS
not provided
Scenario
Setting up a DLP policy to prevent sensitive data leaks to external recipients in Microsoft Teams conversations.
Observed behavior
The DLP rule incorrectly blocks everyone, including internal users, because its access scope or conditions are misconfigured.
Before you start

Ensure you have the Microsoft Purview Compliance Administrator role assigned in your organization and have access to the Microsoft 365 admin center before modifying any Data Loss Prevention policies.

Solution 1Recommended

Verify DLP Rule Conditions and PowerShell Parameters

Review the access scope and user conditions in the Microsoft Purview portal or via PowerShell to ensure the rule specifically targets external recipients rather than all users.

When a DLP rule designed for external users begins blocking internal communication, the issue typically lies within the condition scope of the policy. The rule must explicitly distinguish between internal organization members and external contacts.

1
Open the Purview Compliance Portal

Log in to the Microsoft Purview compliance portal using an administrator account. Navigate to 'Data loss prevention' in the left-hand menu, then select the 'Policies' tab.

2
Edit the Teams DLP Policy

Locate and select the DLP policy affecting Microsoft Teams. Click on 'Edit policy' to access its configuration settings.

3
Verify Access Scope and Conditions

Navigate to the 'Conditions' section of the rule. Ensure that the condition is strictly set to 'Content is shared from Microsoft 365 with people outside my organization'. Remove any overly broad conditions that apply to all users.

4
Review PowerShell Parameters (If Applicable)

If you are managing rules via PowerShell, review your script. Ensure the `Set-DlpComplianceRule` command correctly specifies parameters that target only external recipients.

Seek Specialized Assistance: Because Purview PowerShell configuration and compliance rules can be highly complex, consider posting in the Microsoft PowerShell or Microsoft Power Platform community, or consulting a Microsoft 365 specialist if you cannot isolate the configuration error.
Free Microsoft Office alternative

Looking for a Secure and Lightweight Alternative to Microsoft Office?

While enterprise data protection requires complex administration tools like Microsoft Purview, your daily document creation shouldn't be complicated. WPS Office offers a free, lightweight, and highly compatible alternative to Microsoft Office. Enjoy a familiar interface, robust built-in document encryption, and seamless migration without the heavy administrative overhead.

  1. 1. Download the Software: Visit the official WPS Office website and click the free download button for your operating system.
  2. 2. Install the Suite: Run the downloaded installer and follow the simple on-screen instructions to set up the application.
  3. 3. Open Your Documents: Launch WPS Office and instantly open your existing Microsoft Office files with perfect formatting retained.
Fully compatible with Microsoft Word, Excel, and PowerPoint formats (.docx, .xlsx, .pptx).Built-in robust document encryption and password protection features to keep your local data secure.Lightweight installation with incredibly fast startup times.Free to use with a familiar tabbed interface, ensuring zero learning curve for seamless migration.
microsoft office alternative - wps office

Frequently Asked Questions

Why is my Microsoft Purview DLP rule blocking internal Teams messages?

This usually happens when the rule's conditions are set too broadly. Ensure that the policy conditions specifically target 'People outside my organization' and that no conflicting rules are overriding this setting.

Can I test a Purview DLP rule before applying it to all Teams users?

Yes, Microsoft Purview allows you to run DLP policies in 'Simulation mode' (test mode). This lets you review policy matches and alerts in the compliance center without actually blocking users' messages in Microsoft Teams.

What PowerShell command is used to modify DLP compliance rules?

Administrators use the 'Set-DlpComplianceRule' cmdlet in Exchange Online PowerShell or Security & Compliance PowerShell to modify existing Data Loss Prevention rules, including updating conditions, exceptions, and actions.

Does Microsoft Purview DLP support blocking specific sensitive data types in Teams?

Yes, you can configure DLP rules in Purview to identify and block over 300 built-in sensitive information types (like credit card numbers or social security numbers), or you can create custom data types tailored to your organization.