Expanding Purview DLP and Information Protection to Foreign Platforms

Use Microsoft Defender for Cloud Apps Connectors to Make Data from External Services Available for DLP and Information Protection to Process

Message center notification MC1449180 (6 August 2026, Microsoft 365 roadmap item 568075) announces that Microsoft Purview is expanding Data Loss Prevention (DLP) policies and Information Protection auto-labeling policies to “non-Microsoft applications” like Google Workspace and Box. It all sounds like an interesting and worthwhile advance, but this is not a tweaking of out-of-the-box solutions. Significant work and funding is required to implement the functionality.

Preview availability is slated for mid-August 2026 with general availability following in early September 2026 with full worldwide deployment complete in late October 2026.

The Defender for Cloud Apps Connection

Purview uses Microsoft Defender for Cloud Apps connectors to access and process information held in external infrastructures. For example, if you want to process Google Workspace data, you must configure the Google Workspace connector. This is not an action that a Microsoft 365 tenant administrator can take on their own; it requires the involvement of a Google Workspace “Super admin” to configure a project to allow Defender for Cloud Apps to retrieve data using the project credentials.

In general, Cloud App connectors retrieve lists of users, activities, and files from target platforms. The Purview solutions can process the information to take whatever action is deemed necessary by the deployed policies. For example, once the connectors are in place, DLP policies can be configured for the Managed cloud apps location (Figure 1).

DLP policy for managed cloud apps location.

External services.
Figure 1: Configuring a DLP policy

DLP can apply policies to data from Google Workspace, Box, Dropbox, Salesforce, ServiceNow, AWS, and Cisco Webex. Information Protection auto-labeling can assign sensitivity labels to Google Workspace and Box files.

It would be unreasonable to assume that Purview can impose the same range of actions on external data that is available for Microsoft 365 locations. Microsoft says that “available policy conditions and actions vary by application.” This means that the ability of DLP policies or Information Protection to interact with files is dependent on the actions enabled through a connector. For example, it might not be possible to use the DLP move to quarantine action for external platforms because the files are not stored in SharePoint Online. See the documentation for further guidance about the supported actions for each platform.

A big part of deployment planning is to assess and test exactly what is possible for the target platforms before deciding whether the available functionality warrants the expected cost.

Microsoft also cautions that existing Defender for Cloud Apps file policies for the target platforms should be disabled or removed before attempting to use the Purview policies. Failure to do this runs the risk of “unexpected policy enforcement.” In other words, the file policies can interfere with Purview policies.

Before you create Microsoft Purview policy for any of these non-Microsoft applications, turn off or delete any Microsoft Defender for Cloud Apps file policies for the same non-Microsoft locations. Running both at once can cause unexpected policy enforcement. File policies are due to be retired on January 6, 2027, and Microsoft recommends that organizations which use these policies should migrate to Purview policies.

Computing the Cost

The cost of deploying Purview to non-Microsoft locations divides into two buckets:

  • “Enterprise tier Microsoft Purview licensing.” Microsoft has not yet published detailed licensing guidance. My reading is that organizations will likely require Microsoft 365 E5 Compliance or Microsoft 365 E5 Information Protection and Governance licences for users benefiting from the service. It’s worth checking the exact cost with Microsoft licensing specialists.
  • Purview At Rest Protection. This is an Azure service to store the data retrieved by connectors for the Purview solutions. Microsoft says that “Usage is billed through the Microsoft Purview At Rest Protection pay-as-you-go meter. The unit of measure for at-rest files in non-Microsoft applications is calculated at a rate of 1,000 files = 1 data asset.” The current price for a data asset is $0.50 per month.

The total cost comprises the required E5-class licensing plus Purview At Rest Protection charges for the files retrieved through connectors.

An Esoteric Solution

It’s fair to say that importing data from non-Microsoft platforms into Azure so that Purview DLP and Information Protection can process that information is not something that the average Microsoft 365 tenant will do. This is clearly an enterprise-focused play aimed at organizations that manage corporate information across multiple cloud platforms. For those companies, a unified DLP and information protection strategy might justify the cost and complexity. For most Microsoft 365 tenants, however, the combination of connector configuration, licensing requirements, and ongoing storage charges will make this a niche solution.


Support the work of the Microsoft 365 for IT Pros team by subscribing to the Microsoft 365 for IT Pros eBook. Your support pays for the time we need to track, analyze, and document the changing world of Microsoft 365 and Office 365. Only humans contribute to our work!

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.