It watches the USB stick, the print job, the clipboard and the browser upload. It cannot watch what was never saved.
Endpoint DLP extends Purview data loss prevention to Windows 10 and 11, supported Windows Server versions and the three latest macOS releases. Microsoft is explicit about one limit that changes how you design policy: if data is never saved to a file on the local device, Endpoint DLP cannot scan or classify it.

- 12 activitiesUSB, print, clipboard, browser, RDP and more
- Windows and macOSPlus supported Windows Server versions
- User and deviceBoth must be in scope for enforcement
- Defender onboardingAlready-onboarded devices appear automatically
Eight things to understand before you write a single rule.
Removable media, with forensic detail
Copy to USB removable device can be blocked, warned on or audited. The evidence Microsoft lists for a USB copy is unusually complete: activity type, target file path, timestamp, file name and extension, size, sensitive information type, both SHA1 and SHA256 hashes, the application that performed the copy, and the removable media device manufacturer, model and serial number. That last group is what turns an incident into an investigation.
Browser uploads and unallowed browsers
Uploads to a restricted service domain can be blocked, warned on or audited based on the allowed and unallowed domain lists. Microsoft describes an unallowed browser having the upload blocked and the user redirected to Microsoft Edge, which then allows or blocks based on the policy. Pasting into supported browsers is monitored separately, and Microsoft notes that evaluation is on the pasted content, independent of how the source item was classified.
Clipboard, with a behaviour worth knowing in advance
With Block or Block with override, Microsoft states copying is blocked when the source content is sensitive except where the destination is within the same Microsoft 365 Office application. There is a second behaviour that generates support calls: when a blocking rule applies to an open file, copying from any other file within the same application is restricted while the blocked file is open, even files with no rules applied.
Print, network shares and virtual desktop paths
Printing and copying to any network share can each be blocked, warned on or audited. Microsoft notes these extend into Azure Virtual Desktop with Windows 365, covering redirected printers, redirected clipboards, and redirected USB devices that present as network shares. For UAE organisations running virtual desktops for contractors, those redirected paths are usually the ones nobody had considered.
Bluetooth, RDP and restricted applications
Copying to an unallowed Bluetooth application, copying or moving using RDP, and access by applications on the restricted apps list are all monitored. RDP is supported on Windows and, per the published table, not supported on macOS. Creating and renaming an item are auditable but not restrictable, which makes them useful for investigation rather than prevention.
Classification happens on create, modify and read
Microsoft describes a full scan for sensitive information types and labels every time a file is created or modified, then evaluation against policies and rules. When an already classified file is read, it checks for changes to policies, rules or sensitive information types and re-evaluates if the configuration changed, but it does not re-extract the text. Understanding that is what makes performance conversations rational.
Offline behaviour, which differs by platform
On a Windows device that goes offline, existing policies continue to be enforced on existing files, and just-in-time protection in block mode still prevents a newly created file from being shared until evaluation completes on reconnection. Policies updated while the device was offline are not pushed until it returns, and the outdated policy continues to be enforced meanwhile. Microsoft states this functionality is not supported on macOS.
Servers are supported, with three real caveats
Windows Server 2019 and later can be onboarded, but Endpoint DLP is not enabled for Windows servers by default when they are onboarded. Installing the supported Windows Server updates disables the classification feature on the server, so files classified after that point are not classified, though previously classified files remain protected. And it is not supported on domain controllers or on Core Server installations at all.
Save straight to the USB stick and Endpoint DLP never sees the file.
Microsoft states this plainly, and it is the single most consequential limit on the product. Designing around it is a policy exercise, not a technical one.
- Quoted from the documentation: if data is never saved to a file on the local device, Endpoint DLP cannot scan or classify it. The published example is a user opening a document in Word and saving it directly to a USB device without first storing it locally.
- That means the removable media control cannot be the only control. It has to be paired with something that governs the device itself, which is where Defender for Endpoint device control for removable storage belongs, and Microsoft points there directly.
- The same reasoning applies to any egress path where the data never lands on local disk. Coverage assumptions built on file activity alone will have a hole in exactly the scenario people worry about most.
- The practical answer is layered: device control decides whether removable storage is usable at all, Endpoint DLP governs what happens to files that do exist locally, and sensitivity labelling makes the classification travel with the document.
Four things that decide whether endpoint DLP survives contact with users.
We watch before we block
Microsoft notes that once a device is onboarded, information about audited activities flows into Activity Explorer before any policy with devices as a location is configured. That free visibility period is the most valuable part of the project. It tells you which egress paths people actually use, which is almost never the set anyone predicted.
We get the scoping right, both halves of it
Microsoft is explicit that for a policy to be enforced on an endpoint, both the user and the device must be in scope. Separately, all devices onboarded into Purview are scanned regardless of whether the user is in scope, because a device can support multiple accounts. Those two statements together explain most of the confusion we are called in to unpick.
We pair it with device control rather than pretending it is complete
Because Endpoint DLP cannot see data that never touches local disk, removable media needs a second layer. Microsoft points to Defender for Endpoint device control for removable storage, and the sensible design is that device control decides whether the port is usable while DLP governs content on files that do exist locally.
We write the policy tips as carefully as the rules
The policy tip is the entire user experience of this product. Business justification in policy tips is supported on both Windows and macOS, and used well it converts a block into a decision the user records rather than a wall they route around. Used badly it generates a ticket, then an exception, then a hole.
Six UAE situations where endpoint DLP is the right control.
A financial firm under a data residency obligation
Client data may be entirely legitimate on an analyst laptop and entirely unacceptable uploaded to a personal cloud service. Browser and domain restrictions, with an allowed and unallowed service domain list, address that directly, and the unallowed browser handling routes users to Edge where the policy can actually be applied.
A professional services firm at the end of an engagement
The highest-risk window is a departing consultant with legitimate access to client material. Copy to USB, copy to a network share and print are the three paths that matter, and the evidence Endpoint DLP captures on a USB copy, down to the device serial number, is what makes an investigation conclusive rather than suggestive.
A healthcare provider handling patient records
Clinical staff need to print, and they need to move files between systems that were never designed to talk to each other. Blanket blocking fails immediately. Content-aware rules, warn mode with a business justification, and audit-only on the paths that are genuinely necessary give a control that clinicians can work with.
An engineering business protecting drawings and designs
Design files are frequently in formats DLP does not classify by content, which makes the file extension and unsupported file extension controls relevant, alongside restricted app groups. The archive formats Endpoint DLP does monitor cover the common exfiltration wrapper, since people rarely copy a folder of drawings without zipping it first.
A group running virtual desktops for contractors
Azure Virtual Desktop and Windows 365 introduce redirected clipboards, redirected printers and redirected USB devices that present as network shares. Microsoft states Endpoint DLP covers all three. Organisations that adopted virtual desktops specifically to contain contractor access usually have not verified whether those paths were closed.
An organisation preparing for a data protection audit
Activity Explorer produces evidence of what actually happens to sensitive data on endpoints, which is a materially stronger answer to an auditor than a policy document. Because auditing begins as soon as devices are onboarded, that evidence can exist before any enforcement decision has been made.
How UAE organisations control data leaving endpoints.
| Feature | Endpoint DLP with policy | USB blocked, nothing else | No endpoint controls |
|---|---|---|---|
USB copies controlled by content | Yes | Blanket only | No |
Browser uploads controlled | Yes | No | No |
Printing controlled | Yes | No | No |
Clipboard controlled | Yes | No | No |
Network share copies controlled | Yes | No | No |
Virtual desktop redirected paths covered | Yes | No | No |
Activity visible before enforcement | Yes | No | No |
Forensic detail on an incident | Yes | Minimal | None |
Users told why they were blocked | Yes | No | Not applicable |
Business disruption | Managed | High where USB is needed | None |
Twelve activities, and which ones you can actually block.
| Activity | Windows | macOS | Auditable or restrictable | |
|---|---|---|---|---|
| Upload to restricted domain or unallowed browser | Supported | Supported | Auditable and restrictable | |
| Paste to supported browsers | Supported | Preview | Auditable and restrictable | |
| Copy to clipboard | Supported | Supported | Auditable and restrictable | |
| Copy to USB removable device | Supported | Supported | Auditable and restrictable | |
| Copy to a network share | Supported | Supported | Auditable and restrictable | |
| Supported | Supported | Auditable and restrictable | ||
| Copy or move using unallowed Bluetooth app | Supported | Supported | Auditable and restrictable | |
| Copy or move using RDP | Supported | Not supported | Auditable and restrictable | |
| Create an item | Supported | Supported | Auditable only | |
| Rename an item | Supported | Supported | Auditable only | |
| Access by restricted apps | Supported | Supported | Detection of access attempts | |
| Create Windows Recall snapshots, in preview | Supported on x64 | Not supported | Auditable and restrictable |
Five steps, and the watching phase is where the value is.
- 1
Onboard devices and turn on monitoring
Where devices are already onboarded through Defender for Endpoint they appear in Purview automatically and only need device monitoring turned on. Otherwise onboarding runs by local script for up to ten machines, group policy, Configuration Manager version 1610 or later, Intune, or the VDI scripts for non-persistent machines. Windows servers need Endpoint DLP explicitly enabled after onboarding.
- 2
Watch Activity Explorer before writing rules
Audited activity flows in before any device-scoped policy exists. We use that period to establish which egress paths are actually used, by whom, and how often, which is the difference between a policy set that reflects your business and one copied from a template.
- 3
Design narrow policies with correct scoping
Starting with one clearly defined sensitive information type and one activity rather than everything at once. Both the user and the device must be in policy scope for enforcement, so we verify both. Policy tips and business justification wording are drafted here, not bolted on later.
- 4
Run in audit, then warn, then block
Each activity moves independently rather than all together. Warn with business justification is often the right permanent state for paths the business genuinely needs, since it records a decision without stopping work. Block is reserved for paths with no legitimate use.
- 5
Operationalise the alerts and the exceptions
Alerts reviewed in the DLP alerts dashboard or investigated in Defender XDR, false positives routed to someone who can adjust the rule, and exceptions carrying an owner and a review date. We also confirm the offline and server behaviours match what the policy assumes, since both differ from the online Windows workstation case.
What organisations ask about Endpoint DLP.
Fifteen checks that keep a rollout out of the support queue.
Coverage
- Which devices are already Defender-onboarded?They appear in Purview automatically.
- Are macOS devices in scope?Three latest major versions, and RDP is not covered.
- Any Windows servers in scope?Not domain controllers, not Core installations.
- Is device monitoring turned on?Onboarding alone is not enough.
- Is Azure Virtual Desktop or Windows 365 in use?Redirected paths are covered.
Scoping
- Which users are in policy scope?Policies are scoped to users.
- Which devices are in policy scope?Both must match for enforcement.
- Are shared devices handled?A device can carry several users policies.
- Which sensitive information types matter?Start narrow and specific.
- Are labels part of the condition?Labels and types can both trigger.
User experience
- Block, warn, or block with override?Override needs a justification design.
- Are policy tips written in plain language?The tip is the whole user experience.
- Does the clipboard behaviour need explaining?Same-app restriction surprises people.
- Who handles a false positive?There will be some in week one.
- Have you told users before enforcing?Silent blocking generates tickets, not compliance.
The pages around this one.
DLP solutions
The vendor-neutral view of data loss prevention across email, cloud and endpoints.
Sensitivity labels
The classification that travels with the document and feeds endpoint policy conditions.
Defender for Endpoint
The onboarding path most estates already have, and the device control that covers what DLP cannot see.
Onboard a pilot group and look at what your people already do.
Audited activity flows into Activity Explorer before any policy exists, so the first useful output costs nothing but time. Almost every organisation finds one egress path in that data they had not thought about.
Related Services
Explore more solutions that work great with this service
Data Discovery Audit
Where the sensitive data is, and who can reach it
DLP Solutions
Microsoft Purview DLP and labels
Sensitivity Labels
Classification that travels with the file, and governs what Copilot sees
Defender for Endpoint
Business, Plan 1 or Plan 2, and what each actually gives you
Microsoft Purview
Data governance and compliance solutions
Insider Risk Management
Data theft by departing staff, detected with users pseudonymised
UAE PDPL Compliance
Federal Decree-Law 45 of 2021 readiness and operations
Microsoft Security Dubai
Entra, Defender, Purview, Sentinel, and what you already own