Skip to content

Q3 2026 — Purview DLP Enforce Mode Review

Purpose

Microsoft Purview DLP is currently running in report-only (audit) mode across SharePoint, OneDrive, Teams, Exchange, and Endpoint DLP locations. Enforce mode — actually blocking prohibited actions such as PHI exfiltration — is the target end state. Before flipping enforce mode on, we want one Q3 review cycle to confirm the false-positive rate is acceptable and the workforce understands the policies.

This document defines that Q3 2026 review: when it happens, what to check, who approves the decision, and the template for recording the result.

Related story: COMP-036. Related projects: PURVIEW (Purview DLP Audit).


Schedule

  • Window: Q3 2026 — July, August, September
  • Review day: First Friday of September 2026 (gives a full quarter of report-only data and leaves time before end-of-quarter evidence cutoff)
  • Duration: 90 minutes
  • Attendees:
    • Rory (infrastructure / security — decision owner)
    • Adriana (compliance — final approver on enforce-mode activation)
    • Optionally Kevin or Greg (as DR/ops sanity check)

What to Check

1. False-positive rate from Purview audit logs

  • [ ] Pull Purview DLP alerts for the Q3 window (July 1 – September 30) from the Purview compliance portal: Compliance portal → Data loss prevention → Alerts
  • [ ] Export alerts to CSV for the whole quarter
  • [ ] Triage each alert into one of: true_positive, false_positive, borderline
  • [ ] Compute FP rate = false_positive / (true_positive + false_positive + borderline)
  • [ ] Acceptance threshold: FP rate ≤ 10% across all locations, and ≤ 15% in any single location (SharePoint, Teams, Endpoint)
  • [ ] If above threshold, identify the top 3 FP-generating policies and tune them (add exceptions, refine sensitive-info types, adjust thresholds) before considering enforce mode

2. Top offenders and repeat-offender profile

  • [ ] Group alerts by user for the quarter
  • [ ] Identify any user with 10+ triggers — investigate whether it is a training gap (user does not understand the policy) or a workflow gap (the user is doing something legitimate that DLP is blocking and the policy needs adjustment)
  • [ ] Record remediation taken (user coached, policy tuned, or exception granted)

3. User training completion

Before enforce mode flips on, the workforce must have received training on what the DLP policies do and how to request exceptions.

  • [ ] Confirm KnowBe4 (or the selected awareness platform) has a "Data Loss Prevention / PHI Handling" module assigned to all users
  • [ ] Confirm completion rate ≥ 95% across the workforce (allow ≤ 1 user outstanding, documented)
  • [ ] Confirm a written "how to request a DLP exception" procedure is published in SharePoint and linked from the end-user Intune portal

4. Exception process in place

  • [ ] Confirm the exception-request workflow is live — user raises a request, Rory evaluates, Adriana signs off if a policy change is needed
  • [ ] Confirm the exception log is captured in SecOps (COMP project stories) with a link back to the DLP policy ID

5. Technical readiness

  • [ ] Confirm Purview policies are published and active in report-only mode across all intended locations — no policies in "off" state
  • [ ] Confirm Endpoint DLP is deployed and reporting on all Intune-managed endpoints (count matches managed device count in CMDB)
  • [ ] Confirm no Purview service health incidents are outstanding at Microsoft side on review day

Decision

Three possible outcomes at the end of the review:

  1. GO — flip enforce mode on, all locations, with a 7-day watch window
  2. STAGED GO — flip enforce mode on only in the location(s) passing all criteria (e.g. SharePoint + OneDrive) and hold Endpoint/Teams in report-only until their FP rate is in range
  3. NO-GO — remain in report-only for another quarter; capture a remediation list and schedule Q4 2026 re-review

Adriana (compliance) has final approval on GO / STAGED GO. Rory (infra) has veto on technical risk (e.g. unresolved Purview service issues). NO-GO does not require approval — anyone can call it if criteria are missed.


Decision Template

Copy this into SharePoint → Compliance → Purview DLP → 2026-Q3-enforce-review.md at review time.

# Purview DLP Enforce Mode Review — 2026-Q3

Date: 2026-09-DD
Attendees: Rory, Adriana, ...

## Criteria

| Criterion | Threshold | Actual | PASS/FAIL |
|---|---|---|---|
| Overall FP rate | ≤ 10% | X% | |
| Worst-location FP rate | ≤ 15% | X% (location) | |
| User training completion | ≥ 95% | X% | |
| Exception process live | required | yes/no | |
| Technical readiness | all active | yes/no | |

## Repeat offenders
- user@ciriusgroup.com — N alerts — remediation: ...

## Decision
[GO / STAGED GO / NO-GO]

Rationale (2–3 sentences):
...

## Rollout plan (if GO or STAGED GO)

- Day 0 (review day): Enforce mode enabled on [list of locations]
- Day 0–7: 24-hour watch, any blocking false-positive escalates to Rory within
  15 minutes, Rory can revert to report-only without further approval
- Day 7: Review day-by-day block counts; if healthy, close the watch window

## Approvals

- Rory (technical): ___
- Adriana (compliance): ___

## Next review
[Q4 2026 date if NO-GO or STAGED GO; next annual review if GO]

What Auditors Want to See

For SOC2 and HIPAA, the auditor-facing evidence is:

  1. This review document (signed)
  2. The CSV export of DLP alerts for the quarter (with FP classification)
  3. Training completion roster from the awareness platform
  4. Change record in SecOps showing the enforce-mode flip (or justification for remaining in report-only another quarter)

File all four in SharePoint → Compliance → Purview DLP → 2026-Q3 and reference from the SOC2 evidence binder.


SOC2 / HIPAA Mapping

  • HIPAA 164.308(a)(1)(ii)(A) — risk analysis, validation of controls
  • HIPAA 164.308(a)(5) — workforce training (completion prerequisite)
  • HIPAA 164.312(a)(1) — access control (DLP as PHI exfil guardrail)
  • HIPAA 164.312(b) — audit controls (Purview alert evidence)
  • SOC2 CC6.7 — restricts transmission and movement of information
  • SOC2 CC7.2 — monitors system components for anomalies

Internal use only — Cirius Group