Microsoft Purview: DLP and auto-labeling support for non-Microsoft applications (MC1449180, via M365 Admin)

Tag: S-2026-08-07-m365admin-purview-crosssaas-dlp Type: article (third-party republication of a Microsoft Message Center post) Author(s): João Ferreira (M365 Admin blog), republishing “Originally posted by Microsoft Aug 7, 2026” Date of source: 2026-08-07 Date ingested: 2026-08-10 Authority weight: medium — apparent verbatim republication of Microsoft’s own Message Center text (MC1449180) by an established M365 MVP blog; not verified against the admin-portal original, which requires tenant access Raw file: S-2026-08-07-m365admin-purview-crosssaas-dlp.md

What it claims

Microsoft Message Center post MC1449180 (associated with Roadmap ID 568075) announces that Microsoft Purview will support DLP and Information Protection auto-labeling policies for non-Microsoft applications, connected via Microsoft Defender for Cloud Apps connectors, with policies created and managed directly in Purview. Rollout: Public Preview beginning mid-August 2026 (complete early September 2026); GA (Worldwide) beginning early September 2026 (complete late October 2026). Supported DLP application locations: Google Workspace, Box, Dropbox, Salesforce, ServiceNow, AWS, Cisco Webex; auto-labeling locations: Google Workspace, Box. Policy conditions/actions vary by application and “may include content inspection, sensitivity labeling, notifications, quarantine actions, and access controls”. Operational requirements: Enterprise-tier Purview licensing; usage billed through the Purview At Rest Protection pay-as-you-go meter (1,000 files = 1 data asset); and — before creating Purview policies for these locations — customers must “turn off or delete any Microsoft Defender for Cloud Apps file policies for the same non-Microsoft locations” because running both “can cause unexpected policy enforcement”. Microsoft’s own compliance-considerations table confirms the change alters how customer data is processed (“enabling Microsoft Purview to scan, evaluate, and apply policy actions to data stored in those connected services”) and expands Purview compliance-control scope.

Notable quotes

“Public Preview: Beginning in mid-August 2026 and expected to complete in early September 2026” — rollout schedule

“Before you create Microsoft Purview policy for any of these non-Microsoft applications, turn off or delete any Microsoft Defender for Cloud Apps file policies for the same non-Microsoft locations. Running both at once can cause unexpected policy enforcement.” — action guidance

“Usage is billed through the Microsoft Purview At Rest Protection pay-as-you-go meter. The unit of measure for at-rest files in non-Microsoft applications is calculated at a rate of 1,000 files = 1 data asset.” — licensing/billing

What’s speculative vs. asserted

  • Asserted (as relayed Microsoft statements): the rollout schedule, supported application lists, connector mechanism, licensing/billing model, and the file-policy coexistence instruction.
  • Announced intent, not shipped capability: all dates use “beginning/expected to complete”; nothing is claimed as already delivered.
  • Hedged by Microsoft: policy conditions/actions “vary by application and may include” the listed controls — per-app parity is not asserted.
  • Not independently verified: the Message Center original and Roadmap entry 568075 were not fetched; the republication is trusted as faithful based on the blog’s track record, not confirmed.

Topics this feeds

Open questions raised

  • Does per-app enforcement reach parity with in-estate DLP (policy tips, evidence capture, alerting), given conditions/actions “vary by application”?
  • The coexistence instruction requires deleting Defender for Cloud Apps file policies before the 6 Jan 2027 retirement date if adopting the new locations early — what happens to historical file-policy match records and audit history after deletion? (Not addressed by the post.)
  • Cost exposure of the at-rest PAYG meter for large SaaS estates (1,000 files = 1 data asset) — no worked pricing given.