How to Reduce False Credit Card Matches in Microsoft Purview DLP
Question details
The user needs to prevent Microsoft Purview DLP from incorrectly flagging Social Security Numbers (SSN) and Canadian Social Insurance Numbers (SIN) as credit card numbers.

- Product
- Microsoft Purview Data Loss Prevention
- Device & OS
- not provided
- Scenario
- Configuring Data Loss Prevention policies to accurately detect sensitive information without interrupting normal workflows with false alerts.
- Observed behavior
- Microsoft Purview DLP incorrectly identifies Social Security numbers or Canadian Social Insurance Numbers as credit card numbers, causing false positives and unnecessary security alerts.
Ensure you have the appropriate administrative permissions in the Microsoft Purview compliance portal to view, edit, or create Data Loss Prevention policies and sensitive information types.
Add SSN and SIN as Exceptions in the DLP Policy
The most efficient way to reduce false positives is to instruct your existing DLP policy to ignore matches that also qualify as SSNs or SINs.
By adding exceptions to your current DLP policy, you tell the system to bypass the credit card rule if the matched data is actually recognized as an SSN or SIN. This maintains your credit card security posture while eliminating the most common false positives.
Navigate to the Microsoft Purview compliance portal in your web browser and sign in using an account with DLP administrator privileges.
Go to 'Data loss prevention' in the left navigation pane, click on 'Policies', and select the policy that is currently detecting credit card numbers.
Click 'Edit policy' and proceed to the 'Advanced DLP rules' section. Locate the specific rule that triggers the false positive credit card matches and click the edit (pencil) icon.
Scroll down to the 'Exceptions' section. Click 'Add exception' and select 'Content contains sensitive info types'. Search for and add both 'U.S. Social Security Number (SSN)' and 'Canada Social Insurance Number' to the list.
Save your changes to the rule and submit the policy. It may take up to 24 hours for the updated policy rules to fully propagate across your organization.

Create a Custom Sensitive Information Type
If the built-in credit card information type is too broad, you can create a custom type tailored strictly to the credit card formats used in your organization to avoid overlapping with SSNs.
Looking for a Secure, Free Microsoft Office Alternative?
While you manage complex enterprise data policies in Microsoft Purview, equip your team with a lightweight, secure, and fully compatible productivity suite. WPS Office provides robust document protection features and seamless compatibility with Microsoft Office files, all at no cost.
- 1. Download and Install: Visit the official WPS website to download the free installer for your operating system and follow the quick setup wizard.
- 2. Open Microsoft Files: Launch WPS Office and directly open any existing Microsoft Word, Excel, or PowerPoint files. Your formatting and layouts will remain perfectly intact.
- 3. Secure Your Documents: Use the built-in encryption features under the 'Protect' tab to easily password-protect your sensitive files locally before sharing them.

Frequently Asked Questions
Why does Microsoft Purview DLP misidentify SSNs as credit cards?
Both credit cards and SSNs are numerical sequences. Depending on how the data is spaced or formatted, a 9-digit SSN might trigger a low-confidence credit card match if the regular expressions in the DLP policy overlap or if generic supporting keywords are present nearby.
How can I adjust the confidence level for credit card detection to reduce false positives?
In your DLP policy rule, you can change the matching threshold. Raising the required confidence level from 'Low' to 'High' means the system will require more supporting evidence (like specific keywords, formatting, or checksum validations) before flagging the number as a credit card.
Can I test my adjusted DLP policy before applying it to everyone?
Yes, Microsoft Purview allows you to run DLP policies in 'Test mode'. This helps you monitor the impact and review potential false positives in the DLP alerts dashboard without accidentally blocking legitimate user activities or disrupting workflows.




