Fix Teams DLP Policy Does Not Block a Message for a Guest Conversation
🔍 WiseChecker

Fix Teams DLP Policy Does Not Block a Message for a Guest Conversation

When a Microsoft Teams data loss prevention policy does not block a message in a conversation that includes a guest, the policy is often configured to exclude external or guest users. This article explains why DLP policies can miss guest conversations and provides step-by-step fixes to ensure your sensitive data stays protected.

You will learn how to check your DLP policy scope, adjust the policy to include guests, and verify that the policy applies to Teams chat and channel messages. The fix involves editing the policy in the Microsoft Purview compliance portal and confirming the correct user and location settings.

By the end, you will be able to configure DLP policies that consistently block sensitive content in guest conversations, reducing the risk of data leakage.

Key Takeaways: Fixing DLP Policy Gaps for Guest Conversations

  • Microsoft Purview compliance portal > Data loss prevention > Policies: Edit the policy to include guests and external users in the scope.
  • Locations > Teams chat and channel messages: Ensure this location is selected so DLP applies to guest conversations.
  • User scope > Include specific users or groups: Add guest accounts or the guest user group to guarantee coverage.

ADVERTISEMENT

Why DLP Policies Do Not Block Messages in Guest Conversations

Data loss prevention policies in Microsoft 365 are designed to detect and block sensitive information such as credit card numbers, social security numbers, or confidential labels in messages. However, by default, many DLP policies are scoped to exclude external or guest users. This exclusion stems from the policy configuration, not from a technical limitation of Teams.

When you create a DLP policy in the Microsoft Purview compliance portal, you choose the scope under User scope. The available options are All users, Specific users or groups, and All users and specific groups. If you select All users, the policy applies to everyone in your organization, but it does not automatically include guest users who are outside your Azure AD tenant. Guests are treated as external users, so they fall outside the default scope.

Another reason is the Locations setting. DLP policies can apply to Exchange email, SharePoint sites, OneDrive accounts, Teams chat and channel messages, and Microsoft Defender for Cloud Apps. If the Teams chat and channel messages location is not enabled, the policy will never inspect Teams messages, regardless of the user scope.

Finally, the policy might be set to Audit only mode instead of Block. In audit mode, the policy logs the violation but does not block the message. This is a common oversight when testing DLP policies.

Steps to Fix DLP Policy for Guest Conversations

Follow these steps to modify your DLP policy so it blocks sensitive content in guest conversations. You need global administrator or compliance administrator permissions to complete these steps.

  1. Open the Microsoft Purview compliance portal
    Go to https://compliance.microsoft.com and sign in with your admin account. In the left navigation, select Data loss prevention and then Policies.
  2. Locate the DLP policy that is not blocking guest messages
    Find the policy that should apply to Teams messages. If you have many policies, use the search box to filter by name. Click on the policy name to open its details.
  3. Edit the policy
    Click Edit policy at the top of the policy details page. This opens the policy configuration wizard.
  4. Adjust the user scope to include guests
    In the User scope section, select All users and specific groups or Specific users or groups. If you choose the latter, click Include and search for the guest user account or a group that contains guests. For example, you can create a group named All Guests and add all guest users to it, then include that group in the policy scope.
  5. Verify the Teams location is enabled
    In the Locations section, ensure that Teams chat and channel messages is toggled on. If it is off, turn it on. You can also enable Exchange email and SharePoint sites if needed, but for Teams conversations, the Teams location is essential.
  6. Set the action to block the message
    In the Action section, choose Block or Block with override. If you select Block, the message will be blocked and the sender will see a policy tip. If you select Block with override, the sender can override the block with a business justification, but the message is still blocked by default.
  7. Save the policy changes
    Click Next through the remaining steps and then click Submit. Wait for the policy to propagate, which can take up to 24 hours. To test, send a message with sensitive content in a chat that includes a guest.

ADVERTISEMENT

If Teams Still Has Issues After the Main Fix

DLP Policy Is in Audit Mode and Does Not Block Anything

If your policy is set to Audit mode, it only logs violations and does not block messages. To change this, edit the policy and in the Action section, select Block or Block with override. After saving, test again with a guest conversation.

Guest User Is Not Included Because the Policy Uses a Group That Does Not Contain Guests

If you used a specific group in the policy scope, verify that the guest user is a member of that group. Open Azure Active Directory, go to Groups, select the group, and check the Members list. If the guest is missing, add them. If you do not want to manage group membership manually, use All users and specific groups to include all users automatically.

DLP Policy Applies Only to Channels, Not to Private Chats

Teams chat and channel messages are separate locations in DLP policies. If you enabled only Channel messages, private chats with guests are not covered. Edit the policy and enable Chat messages as well. In the same location setting, you can choose to apply the policy to all chats or specific chats.

DLP Policy Does Not Detect the Sensitive Info Type in Guest Messages

The policy might be using a custom sensitive info type that is not present in the guest message. Check the Content contains condition in the policy. If you are using built-in types like Credit Card Number, test with a valid test number. If you are using a custom type, verify the pattern and the confidence level.

DLP Policy Scope and Locations Comparison

Item All users All users and specific groups
Guest users included No Yes, if the group contains guests
External users included No Yes, if the group contains external users
Management effort Low Medium, requires group maintenance
Best for Internal-only policies Policies that must cover guests

ADVERTISEMENT

Conclusion

You can now adjust your DLP policy to block sensitive messages in guest conversations by editing the user scope, enabling Teams locations, and setting the action to Block. Always verify the policy mode and test with a real guest conversation after saving changes.

For stronger protection, consider creating a dedicated DLP policy for guests with stricter conditions, such as blocking all sensitive info types without override. Use the Policy tips feature to notify users when their message is blocked, and review the DLP reports in the compliance portal to monitor violations.

Remember to check the policy propagation time, which can take up to 24 hours, and retest if the block does not appear immediately.

ADVERTISEMENT