Security Architecture

M365 Data Loss Prevention vs Backup: A Control Matrix

Published Jul 25, 20266 min readBy Security Engineering

Direct answer: Microsoft Purview Data Loss Prevention can identify, monitor, warn, restrict, or block supported activities when the policy's location, users, content, and action are in scope. Backup can retain recovery points and restore supported objects after loss or corruption. DLP does not restore data, and backup does not prevent disclosure. Neither replaces identity security, audit, retention, incident response, or tested native recovery.

Outcome Control Matrix

ScenarioPrimary controlsDLP contributionBackup contribution
User sends sensitive data externallyDLP, labels/classifiers, identity, approved sharingCan audit, warn, restrict, or block when configured and supportedPreserves a copy but does not stop disclosure
Compromised account downloads or shares filesIdentity risk, Conditional Access, Defender, DLP, auditCan still evaluate in-scope activity performed with valid credentialsDoes not prevent access or exfiltration
User deletes SharePoint filesAudit, native recovery, retention, backupNot the primary deletion-recovery controlMay restore tested supported objects from a retained recovery point
Synced files are corrupted or encryptedEndpoint response, version history, native restore, backupMay detect some sensitive-data movement, not file healthMay provide an earlier tested copy
Admin changes protection policiesLeast privilege, PIM, audit, alerts, change controlRemains effective according to current policy until changed; scope and exclusions matterAdministrative separation can reduce correlated compromise risk
Content must be preserved for a matterAuthorized eDiscovery hold and retentionNot a preservation substituteNot a legal-hold or eDiscovery substitute

A valid credential does not automatically bypass DLP. If the actor, location, activity, and content match an enforced policy, DLP can still respond. A sufficiently privileged attacker might try to alter policies, roles, or alerts, but that is a privileged-access and change-detection scenario, not an inherent DLP exemption. Verify actual exclusions and administrative permissions rather than assuming them.

Likewise, a retained backup copy is not automatically isolated, immutable, searchable, or restorable. Those outcomes depend on storage administration, retention and deletion controls, monitoring, object coverage, restore implementation, and successful tests. Record each property separately in the control register.

Roles and Decision Fields

Runbook: Design DLP Around a Specific Decision

  1. Name the prohibited or monitored action. For example: "A member of the Finance group sends a file containing confirmed customer account data to an unapproved external recipient." Avoid broad goals such as "protect PII."
  2. Choose supported locations. Exchange, SharePoint, OneDrive, Teams, devices, browsers, cloud apps, and other locations have different actions, prerequisites, and licenses. Review Microsoft's current DLP overview.
  3. Choose detection. Document sensitive information types, trainable classifiers, exact data match, sensitivity labels, or other conditions. Maintain a test set with expected matches and non-matches.
  4. Set scope and response. Record included and excluded users, groups, sites, rule order, thresholds, user notification, override, block action, alert severity, and incident owner.
  5. Simulate first. Run test or simulation mode long enough to sample normal activity. Measure false positives, false negatives, operational volume, and business impact with the data owner.
  6. Enforce incrementally. Begin with an approved cohort, generate controlled events, verify user experience and alerts, then expand. Retain rollback and exception procedures.

Microsoft's DLP policy reference documents policy scoping, locations, and administration. Licensing and supported actions change, so record the documentation review date with each policy.

Runbook: Design Recovery Separately

  1. List each required object type, including files, messages, structure, membership, permissions, metadata, and versions where applicable.
  2. Record workload-specific native recovery, Purview retention, Microsoft 365 Backup, and independent backup as separate rows. The retention control guide explains their different outcomes.
  3. For backup, document capture frequency, retained recovery points, item-level failures, administrative boundary, deletion controls, supported destinations, and restore handlers.
  4. Perform a restore using a representative object and recovery point. Record duration, fidelity, changed identifiers or timestamps, unsupported content, and data-owner acceptance.
  5. Exercise the combined scenario. Trigger the DLP test, confirm its alert or restriction, simulate loss using approved test data, and prove the recovery path without assuming either control covered the other.

Evidence Checklist

Limitations and Product Boundary

DLP detection is probabilistic when it relies on classifiers or patterns, and supported responses vary by location, application, file type, device state, policy scope, and license. Backup availability also does not prove that every object can be restored with original structure or metadata. Use the admin security checklist for identity and audit dependencies and the ransomware recovery runbook for destructive-event response.

North Brook Vault supplies managed backup and selective restore for supported objects. It does not configure Purview DLP, prevent exfiltration, administer legal holds, enforce native Object Lock, guarantee recovery, or restore/export Teams messages. Review the managed backup service boundary, then validate required handlers and restore fidelity before rollout.

Discuss a recovery consultation