logo
search
Security Policy Errors

How to Fix Microsoft Teams DLP Policy Not Blocking Messages

John WilsonJohn Wilson Sep 27, 2026 869 views

Question details

The user needs to resolve an issue where a Microsoft Teams Data Loss Prevention (DLP) policy fails to block messages containing sensitive data.

How to Fix a Microsoft Teams DLP Policy That Does Not Block Messages
Product
Microsoft Teams
Device & OS
not provided
Scenario
Configuring or testing a DLP policy in Microsoft Teams to block sensitive data sharing.
Observed behavior
The policy fails to trigger, allowing restricted information such as credit card numbers to be sent without being blocked.
Before you start

Ensure you have the necessary Global Administrator or Compliance Administrator permissions in the Microsoft Purview compliance portal before attempting to modify DLP policies.

Solution 1Recommended

Review and Update DLP Policy Configuration

Verify that the policy locations, sensitive information types, conditions, and actions are correctly set to actively block content.

A common reason for DLP policy failure is incorrect scoping or leaving the policy in a testing phase. Ensuring that the policy targets the right locations and has a definitive blocking action is critical for it to function.

1
Access Compliance Portal

Open the Microsoft Purview compliance portal and navigate to 'Data loss prevention' followed by 'Policies'.

2
Edit the Policy

Select your specific Teams DLP policy from the list and click 'Edit policy'.

3
Verify Policy Locations

Ensure that the 'Teams chat and channel messages' toggle is turned on under the Locations settings.

4
Check Rules and Actions

Review the advanced DLP rules to ensure the correct Sensitive Information Type (e.g., Credit Card Number) is selected, and confirm that the action 'Restrict access or encrypt the content in Microsoft 365 locations' is set to block users.

5
Enable the Policy

On the final settings page, ensure the policy mode is set to 'Turn it on right away' instead of 'Test it out', then save your changes.

Review and Update DLP Policy Configuration
Test Mode Restriction: Policies left in 'Test it out' mode will only generate alerts and will not actively block users from sending sensitive information.
Free Microsoft Office alternative

Enhance Your Productivity with WPS Office

While troubleshooting complex Microsoft Teams and Purview compliance policies requires specific Microsoft admin access, your daily document work doesn't need to be complicated. WPS Office provides a free, lightweight, and highly compatible alternative to Microsoft Office for creating, editing, and securing your documents.

  1. 1. Download the Installer: Visit the official WPS Office website and click the Free Download button.
  2. 2. Install WPS Office: Run the downloaded installation file and follow the simple on-screen instructions.
  3. 3. Open Your Files: Launch WPS Office to immediately start working with your existing Microsoft Office documents.
Fully compatible with Microsoft Word, Excel, and PowerPoint file formats (.docx, .xlsx, .pptx).Lightweight design ensures fast installation and smooth performance on any device.Built-in PDF toolkit for viewing, editing, and encrypting files to enhance document security.Familiar, intuitive user interface that requires zero learning curve for Office users.
microsoft office alternative - wps office

Frequently Asked Questions

Why is my Teams DLP policy stuck in test mode?

When creating a DLP policy, it defaults to 'Test it out' mode to prevent accidental blocking of legitimate work. You must manually edit the policy and select 'Turn it on right away' for the blocking actions to take effect.

How long does it take for a Teams DLP policy to apply?

Changes to Data Loss Prevention policies in Microsoft Teams typically take around 1 hour to propagate. However, in some cases, it can take up to 24 hours to fully sync across all Microsoft 365 services.

Can a DLP policy block messages sent to external guests?

Yes. You can configure the DLP policy conditions to specifically detect when sensitive information is shared with people outside your organization and apply strict block actions for those scenarios.

Why did a credit card number bypass my active DLP policy?

This usually happens if the number doesn't meet the confidence level threshold set in your rules, or if it lacks expected formatting and contextual keywords (like 'cc', 'visa', or expiry dates) that Microsoft's built-in classifiers require to trigger.