How to Fix Microsoft Teams DLP Policy Not Blocking Messages
Question details
The user needs to resolve an issue where a Microsoft Teams Data Loss Prevention (DLP) policy fails to block messages containing sensitive data.

- Product
- Microsoft Teams
- Device & OS
- not provided
- Scenario
- Configuring or testing a DLP policy in Microsoft Teams to block sensitive data sharing.
- Observed behavior
- The policy fails to trigger, allowing restricted information such as credit card numbers to be sent without being blocked.
Ensure you have the necessary Global Administrator or Compliance Administrator permissions in the Microsoft Purview compliance portal before attempting to modify DLP policies.
Review and Update DLP Policy Configuration
Verify that the policy locations, sensitive information types, conditions, and actions are correctly set to actively block content.
A common reason for DLP policy failure is incorrect scoping or leaving the policy in a testing phase. Ensuring that the policy targets the right locations and has a definitive blocking action is critical for it to function.
Open the Microsoft Purview compliance portal and navigate to 'Data loss prevention' followed by 'Policies'.
Select your specific Teams DLP policy from the list and click 'Edit policy'.
Ensure that the 'Teams chat and channel messages' toggle is turned on under the Locations settings.
Review the advanced DLP rules to ensure the correct Sensitive Information Type (e.g., Credit Card Number) is selected, and confirm that the action 'Restrict access or encrypt the content in Microsoft 365 locations' is set to block users.
On the final settings page, ensure the policy mode is set to 'Turn it on right away' instead of 'Test it out', then save your changes.

Wait for Policy Propagation and Retest
New or updated DLP policies can take time to apply across the tenant, requiring a waiting period before accurate testing.
Seek Advanced Support from Microsoft Communities
If configuration and propagation are correct but the policy still fails, specialized technical assistance may be required.
Enhance Your Productivity with WPS Office
While troubleshooting complex Microsoft Teams and Purview compliance policies requires specific Microsoft admin access, your daily document work doesn't need to be complicated. WPS Office provides a free, lightweight, and highly compatible alternative to Microsoft Office for creating, editing, and securing your documents.
- 1. Download the Installer: Visit the official WPS Office website and click the Free Download button.
- 2. Install WPS Office: Run the downloaded installation file and follow the simple on-screen instructions.
- 3. Open Your Files: Launch WPS Office to immediately start working with your existing Microsoft Office documents.

Frequently Asked Questions
Why is my Teams DLP policy stuck in test mode?
When creating a DLP policy, it defaults to 'Test it out' mode to prevent accidental blocking of legitimate work. You must manually edit the policy and select 'Turn it on right away' for the blocking actions to take effect.
How long does it take for a Teams DLP policy to apply?
Changes to Data Loss Prevention policies in Microsoft Teams typically take around 1 hour to propagate. However, in some cases, it can take up to 24 hours to fully sync across all Microsoft 365 services.
Can a DLP policy block messages sent to external guests?
Yes. You can configure the DLP policy conditions to specifically detect when sensitive information is shared with people outside your organization and apply strict block actions for those scenarios.
Why did a credit card number bypass my active DLP policy?
This usually happens if the number doesn't meet the confidence level threshold set in your rules, or if it lacks expected formatting and contextual keywords (like 'cc', 'visa', or expiry dates) that Microsoft's built-in classifiers require to trigger.




