Block all external sharing of Protected Health Information (PHI) across Microsoft 365 workloads using one reliable Microsoft Purview DLP policy.
Tools Used
Microsoft Purview Data Loss Prevention (DLP)
Microsoft 365 E5
Exchange Online, SharePoint Online, OneDrive, Microsoft Teams
Sensitive Info Types: SSN, Medical Identifiers, ICD codes, custom HIPAA classifiers
π Summary
This lab demonstrates a single-policy design that blocks any external sharing of PHI across Exchange, SharePoint, OneDrive and Teams.
βοΈ Approach
Create one DLP policy named HIPAA External Block.
Scope the policy explicitly to the four workloads (Exchange, SharePoint, OneDrive, Teams) using the location picker.
Include all users and groups in scope (default), no exclusions required for this lab.
Rule condition: content contains configured HIPAA sensitive info types or matching classifiers.
Action: Block external sharing/delivery; show inline policy tip; send endβuser notification; create Purview incident and alert to admins.
Validate externally-targeted sharing attempts from each workload are blocked and generate alerts.
Policy Configuration (high-level)
Name: HIPAA External Block β Global Locations: Select specific locations β Exchange mailboxes; SharePoint sites; OneDrive accounts; Teams chat and channel messages Users in scope: All users and groups (no exclusions in this lab) Condition: Contains HIPAA sensitive info types / classifiers Actions: Block external sharing/delivery; Show policy tip; Send user notification; Create incident/alert.
Steps Taken
Create custom DLP policy using the Purview portal and name it per above.
Choose specific locations and enable Exchange, SharePoint, OneDrive and Teams.
Select sensitive info types and any trainable classifiers that represent PHI.
Set action to block external sharing/delivery; configure policy tip and notify options.
Publish policy and allow propagation (test after 30β60 minutes; final confirmation next day).
Perform external sharing tests from each workload and capture results (blocked tip, NDR, Purview incident/alert).
Screenshot: Policy Overview
Click to view full-size: DLP policy overview showing name, location selections and actions
Screenshot: Locations Picker (selected workloads)
Click to view full-size: Locations panel with Exchange, SharePoint, OneDrive and Teams selected (avoid All locations)
Per-workload test placeholders & expected artifacts
SharePoint / OneDrive
Policy tip in SharePoint/OneDrive when attempting to share a file externally
SharePoint / OneDrive
Email Notification, undeliberable
Teams
Policy tip displayed in Teams when trying to send PHI to an external guestPolicy tip displayed in Teams when trying to send PHI to an external guestReceiving chat example
Exchange
Outlook compose tip and/or NDR that indicates the external send was blocked
Screenshot: Admin side artifacts
Purview alert view showing details of the policy match/blockAlert email where admin receives notifications about blocked external sharing and policy matchEmail notification to Admin showing policy match
Outcome
Single global external-block policy prevents PHI from leaving the tenant across all major M365 workloads. This simplified design reduces scoping complexity. Admins receive incidents and alerts for auditing and response.