How to Configure Microsoft Purview DLP Rules for External Teams Users
Question details
The user needs to configure a Microsoft Purview Data Loss Prevention (DLP) rule to block sensitive information from being sent to external Microsoft Teams users without accidentally blocking internal messages.
- Product
- Microsoft Purview
- Device & OS
- not provided
- Scenario
- Setting up a DLP policy to prevent sensitive data leaks to external recipients in Microsoft Teams conversations.
- Observed behavior
- The DLP rule incorrectly blocks everyone, including internal users, because its access scope or conditions are misconfigured.
Ensure you have the Microsoft Purview Compliance Administrator role assigned in your organization and have access to the Microsoft 365 admin center before modifying any Data Loss Prevention policies.
Verify DLP Rule Conditions and PowerShell Parameters
Review the access scope and user conditions in the Microsoft Purview portal or via PowerShell to ensure the rule specifically targets external recipients rather than all users.
When a DLP rule designed for external users begins blocking internal communication, the issue typically lies within the condition scope of the policy. The rule must explicitly distinguish between internal organization members and external contacts.
Log in to the Microsoft Purview compliance portal using an administrator account. Navigate to 'Data loss prevention' in the left-hand menu, then select the 'Policies' tab.
Locate and select the DLP policy affecting Microsoft Teams. Click on 'Edit policy' to access its configuration settings.
Navigate to the 'Conditions' section of the rule. Ensure that the condition is strictly set to 'Content is shared from Microsoft 365 with people outside my organization'. Remove any overly broad conditions that apply to all users.
If you are managing rules via PowerShell, review your script. Ensure the `Set-DlpComplianceRule` command correctly specifies parameters that target only external recipients.
Looking for a Secure and Lightweight Alternative to Microsoft Office?
While enterprise data protection requires complex administration tools like Microsoft Purview, your daily document creation shouldn't be complicated. WPS Office offers a free, lightweight, and highly compatible alternative to Microsoft Office. Enjoy a familiar interface, robust built-in document encryption, and seamless migration without the heavy administrative overhead.
- 1. Download the Software: Visit the official WPS Office website and click the free download button for your operating system.
- 2. Install the Suite: Run the downloaded installer and follow the simple on-screen instructions to set up the application.
- 3. Open Your Documents: Launch WPS Office and instantly open your existing Microsoft Office files with perfect formatting retained.

Frequently Asked Questions
Why is my Microsoft Purview DLP rule blocking internal Teams messages?
This usually happens when the rule's conditions are set too broadly. Ensure that the policy conditions specifically target 'People outside my organization' and that no conflicting rules are overriding this setting.
Can I test a Purview DLP rule before applying it to all Teams users?
Yes, Microsoft Purview allows you to run DLP policies in 'Simulation mode' (test mode). This lets you review policy matches and alerts in the compliance center without actually blocking users' messages in Microsoft Teams.
What PowerShell command is used to modify DLP compliance rules?
Administrators use the 'Set-DlpComplianceRule' cmdlet in Exchange Online PowerShell or Security & Compliance PowerShell to modify existing Data Loss Prevention rules, including updating conditions, exceptions, and actions.
Does Microsoft Purview DLP support blocking specific sensitive data types in Teams?
Yes, you can configure DLP rules in Purview to identify and block over 300 built-in sensitive information types (like credit card numbers or social security numbers), or you can create custom data types tailored to your organization.




