Purview unable to find certain SharePoint Online sites when querying to add them to a DLP policy scope

JW 20 Reputation points
2024-11-20T15:25:47.96+00:00

When attempting to add SharePoint sites to include as a part of the location scope for my DLP policies, I am unable to find a good portion of my SharePoint sites. Interestingly enough, many of the user's personal SharePoint (OneDrive) sites are able to be searched. Why is it that I wouldn't be able to search and find a SharePoint site within my tenant?

Microsoft Security | Microsoft Purview
{count} votes

1 answer

Sort by: Most helpful
  1. Smaran Thoomu 24,260 Reputation points Microsoft External Staff Moderator
    2024-11-21T08:57:19.6733333+00:00

    Hi @Josh Wilson
    Welcome to Microsoft Q&A platform and thanks for posting your query here.

    It seems you're facing issues while attempting to add SharePoint Online sites to a Data Loss Prevention (DLP) policy location scope in Microsoft Purview.

    Here are some potential reasons for this issue and suggested actions to address them:
    Search Indexing Delays or Restrictions

    • Newly created or modified SharePoint sites may not appear immediately due to search indexing delays.
    • Action: Wait up to 48 hours for indexing or manually trigger reindexing in the SharePoint Admin Center for the affected sites.

    Privacy Settings of SharePoint Sites

    • Some SharePoint sites may have privacy settings that restrict their visibility in search results.
    • Action: Verify the permissions and privacy settings of the sites to ensure they allow inclusion in DLP policies.

    Tenant-Wide Policy or Rule Constraints

    • Ensure your DLP policies adhere to Microsoft Purview's platform constraints. These include limits on the number of policies, rules, and overall policy size:
      • Maximum number of policies per tenant: 10,000
        • Maximum number of rules per tenant: 600
          • Maximum size of a policy: 100 KB
    • Action: Review your existing policies and consolidate or optimize them to remain within these constraints.
    • If the site cannot be found via the search feature, try manually adding the SharePoint site URL directly to the DLP policy configuration.

    File or Metadata Limitations

    • DLP policies have file size and regex constraints that could indirectly affect policy application. For example:
      • Maximum file size for text extraction: 2 MB
      • Regex match size: 20 KB
    • Action: Ensure your policy configurations and rules are aligned with these limitations.

    Refer these articles for more information:
    https://learn.microsoft.com/en-us/purview/dlp-policy-reference?view=o365-worldwide#before-you-begin

    https://answers.microsoft.com/en-us/msoffice/forum/all/dlp-policy-limitation-for-sharepoint-site/6ff95f58-1b5f-42f2-823c-de089f443400

    I hope this helps. Please let me know if you have any questions.

    1 person found this answer helpful.

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.