Fix Teams DLP Policy Does Not Block a Message for a Recorded Meeting
🔍 WiseChecker

Fix Teams DLP Policy Does Not Block a Message for a Recorded Meeting

Your Teams DLP policy catches sensitive content in regular chats, but a message sent during a recorded meeting slips through. Data Loss Prevention policies in Teams apply to standard chat and channel messages, yet meeting chat is treated differently. This article explains why the policy misses meeting chat and how to configure it to block or flag sensitive messages in recorded meetings.

You will learn the exact policy settings, the role of meeting chat retention, and the steps to verify your DLP policy covers meeting messages. By the end, you can enforce protection on recorded meeting chats and avoid data leakage.

Key Takeaways: Fix DLP for Teams Meeting Chat

  • Teams admin center > Data loss prevention > Policies: Create or edit a DLP policy that includes Teams chat and channel messages.
  • Meeting chat retention setting: Ensure meeting chat is saved and visible to DLP scanning by configuring retention policies.
  • Test with a sensitive info type: Use a test message with a credit card number to confirm the policy blocks or flags it in a recorded meeting.

ADVERTISEMENT

Why Teams DLP Policy Does Not Block a Message for a Recorded Meeting

DLP policies in Teams protect chat and channel messages, but meeting chat is a separate workload. When you record a meeting, the chat transcript is saved, yet the DLP engine may not scan that content if your policy does not explicitly include meeting chat. The root cause is that DLP policies for Teams are scoped to the Teams chat and channel messages workload, not to meeting transcripts or meeting chat history.

Additionally, meeting chat messages are stored in the user’s Exchange mailbox as part of the meeting item. DLP policies that target Exchange content might not apply to Teams meeting chat because the content is in a Teams-specific location. Therefore, even if your policy blocks sensitive data in regular chat, it will not catch the same data in a recorded meeting unless you adjust the policy scope and retention settings.

Another factor is the retention policy for meeting chat. If the meeting chat is set to expire quickly or is not stored, DLP may not have a chance to evaluate it. By default, meeting chat is retained for a limited time, but for recorded meetings, you can extend retention to allow DLP scanning.

How DLP Scans Meeting Chat

DLP scans messages when they are sent, but only if the policy applies to the chat type. For meeting chat, the policy must include the Teams chat workload and the condition that the message is part of a meeting. The Teams admin center provides a location picker where you can select Teams chat and channel messages, which covers meeting chat as well.

However, meeting chat messages are not scanned in real time if the meeting is recorded and the chat is stored separately. The DLP engine may only evaluate the chat after the meeting ends, depending on how the policy is configured. This delay can cause the policy to appear ineffective, especially if users expect immediate blocking.

Steps to Configure DLP Policy for Recorded Meeting Chat

Follow these steps to ensure your DLP policy blocks sensitive messages in recorded meetings.

  1. Open the Microsoft Purview compliance portal
    Go to compliance.microsoft.com and sign in with an account that has DLP compliance admin permissions. In the left navigation, select Data loss prevention, then Policies.
  2. Create or edit a DLP policy for Teams
    Click Create policy or select an existing policy that applies to Teams. If creating a new policy, choose the template that includes Teams chat and channel messages, such as the Privacy template or Custom policy.
  3. Select the location for Teams chat
    In the Locations section, ensure Teams chat and channel messages is toggled on. This location covers meeting chat, including chat in recorded meetings. Do not select only Exchange email or SharePoint sites, as those will not cover Teams meeting chat.
  4. Define the sensitive info types
    In the Policy settings, choose the sensitive information types you want to detect, such as credit card numbers or social security numbers. You can also use the default templates that include these types.
  5. Set the action to block or restrict
    Under Actions, select Block or Restrict access. For Teams chat, you can choose to block the message and notify the sender. Ensure the action is set to Block, not just Audit, to prevent the message from being sent.
  6. Test the policy with a recorded meeting
    Start a Teams meeting, record it, and send a test message containing a credit card number in the meeting chat. The policy should block the message or flag it immediately. If it does not, check the policy status and the meeting chat retention settings.
  7. Verify policy status in the compliance portal
    After testing, go back to the DLP policy and check the Status column. It should show Turned on. Also review the Policy matches tab to see if the test message was detected.

Adjust Meeting Chat Retention for Recorded Meetings

If your DLP policy still does not block messages, the meeting chat may not be retained long enough for scanning. To fix this, create a retention policy for Teams meeting chat.

  1. Go to Information governance in the compliance portal
    In the Microsoft Purview compliance portal, select Data lifecycle management, then Retention policies. Click New retention policy.
  2. Name the policy and choose Teams meeting chat
    Give the policy a name, then under Locations, select Teams channel messages and Teams chats. This includes meeting chat.
  3. Set the retention period
    Choose a retention period that is long enough, such as 7 days or more, to allow DLP to scan the content. For recorded meetings, you may want to retain the chat for the same period as the recording.
  4. Save and apply the policy
    Click Save to apply the retention policy. Wait a few hours for the policy to take effect, then test again.

ADVERTISEMENT

If Teams DLP Still Does Not Block Meeting Chat

Teams DLP Policy Shows No Matches for Meeting Chat

If your policy shows no matches, verify that the sensitive info type is correctly defined. Some types, like credit card numbers, require a minimum number of digits and a checksum. Test with a realistic sample, such as a valid test credit card number from a documentation source.

Meeting Chat Is Not Saved for Recorded Meetings

If meeting chat is not saved, DLP cannot scan it. Check the meeting recording settings in Teams admin center. Go to Teams admin center > Meetings > Meeting policies, and ensure the setting Allow transcription is on. Also confirm that the meeting organizer has enabled recording and that the chat is available in the meeting details after the meeting.

DLP Policy Applies Only to Channel Messages, Not Meeting Chat

Some policies are scoped to channel messages only. To include meeting chat, edit the policy and ensure the location is Teams chat and channel messages, not just Channel messages. This is a common mistake.

Teams DLP Policy for Recorded Meeting vs Regular Chat: Key Differences

Item Regular Chat Recorded Meeting Chat
DLP scanning Real-time when message is sent May be delayed until after meeting ends
Storage location Teams chat in user mailbox Stored as part of meeting item in Exchange
Retention policy Default chat retention applies Requires explicit retention policy for meeting chat
Policy location required Teams chat and channel messages Teams chat and channel messages, plus retention
Blocking action Blocks message instantly May only flag if policy is set to audit

Now you can configure a DLP policy that covers meeting chat and verify that sensitive messages are blocked in recorded meetings. Test with a known sensitive info type and check the policy matches in the compliance portal. For advanced protection, enable the policy to notify the sender and the compliance admin when a message is blocked.

ADVERTISEMENT