Outlook on the web: New setting to use data classification services for DLP evaluation [MC1315220]

Outlook on the web: New setting to use data classification services for DLP evaluation [MC1315220]

Message ID: MC1315220

Introduction

We are introducing a new organization-level setting that allows admins to migrate Outlook on the web (OWA) from Exchange-based Data Loss Prevention (DLP) policy evaluation to Data Classification Services (DCS)-based DLP policy evaluation. This change brings OWA in line with the new Outlook experience, enabling enhanced capabilities such as the new oversharing policy tips experience and “Wait to send.” This update helps provide a more consistent, modern, and scalable DLP experience across Outlook clients.

When this will happen:

  • General Availability (Worldwide): Rollout will begin mid-May 2026 and complete by late May 2026.
  • General Availability (GCC): Rollout will begin mid-May 2026 and complete by mid-June 2026.

How this affects your organization:

Who is affected:

  • Admins managing Exchange Online and Microsoft Purview DLP policies
  • Organizations using DLP policies in Outlook on the web

What will happen:

  • A new organization-level setting (DlpViaDcsEnabled) will be available to control DLP evaluation mode in OWA.
  • By default, the setting is False, meaning Exchange-based DLP remains in use.
  • Admins can manually enable DCS-based DLP evaluation for OWA using PowerShell.
  • Once enabled, OWA will use DCS-based DLP policy evaluation instead of Exchange-based evaluation.
  • Users may experience enhanced DLP features, including:
    • Improved oversharing policy tips
    • “Wait to send” functionality
    • Alignment with new Outlook DLP behavior
  • Some legacy Exchange-based DLP predicates will no longer be supported after migration. Refer to Data loss prevention policy tip reference for Outlook for Microsoft 365 | Microsoft Learn for details about supported features.

What you can do to prepare:

  • If you plan to continue using Exchange-based DLP evaluation, no action is required.
  • If you plan to migrate to DCS-based DLP evaluation by enabling the DlpViaDcsEnabled setting:
    • Important: Review existing DLP policies before enabling this setting. Some Exchange-based predicates are not supported with DCS-based DLP and policies using them may no longer work as expected after migration.
    • Test DCS-based DLP evaluation in a controlled environment
    • Enable the setting using Exchange Online PowerShell:
    Get-OrganizationConfig | Select DlpViaDcsEnabled
    Set-OrganizationConfig -DlpViaDcsEnabled $true
    
    • Communicate changes to compliance teams.
    • Update internal documentation.

Learn more: Set-OrganizationConfig (ExchangePowerShell) | Microsoft Learn

Compliance considerations:

Compliance areaExplanation
Alters how existing customer data is processedDLP evaluation shifts from Exchange-based processing to DCS-based processing, which may change how email content is analyzed and classified. This is existing analyzation classification flows for New Outlook and Classic Outlook.
Modifies Purview Data Loss Prevention (DLP) policies or enforcementSome Exchange-based predicates are no longer supported, and enforcement behavior may differ under DCS-based evaluation.
Includes an admin control

Admins can enable or disable the feature using the DlpViaDcsEnabled organization setting.

Source: Microsoft

Latest Posts

Pass It On
Leave a Comment

Comments

No comments yet. Why don’t you start the discussion?

Leave a Reply