Onboarding devices in MS purview for DLP

Prasant Chettri 146 Reputation points
2024-12-06T04:56:44.3033333+00:00

Onboarding devices with Defender in passive mode in MS purview for DLP endpoint protection automatically started showing device as green and policy updated without even running script on the device. Does that mean it is actually showing policy update based on defender or actual DLP policy hitting the device?

How do I know the difference in status between endpoint with script on boarded vs not. Is the only way to know the end point with cmd script vs without it is not actually target Endpoint DLP test on both devices and test the result or there is other way to view on the device onboarded report where is shows all devices checked it.

Microsoft Security | Microsoft Purview
0 comments No comments
{count} votes

Accepted answer
  1. Smaran Thoomu 25,165 Reputation points Microsoft External Staff Moderator
    2024-12-06T11:03:16.5466667+00:00

    Hi @Prasant Chettri
    Welcome to Microsoft Q&A platform and thanks for posting your query here.

    Great question! When you onboard devices in MS Purview with Defender in passive mode, the device might show as "green" and reflect policy updates without the script actually running. This could mean that the policy update is being applied through Defender's passive monitoring, but it doesn't necessarily indicate that the full DLP policy has been enforced yet.

    To distinguish between endpoints that are onboarded with the script vs. those that aren't, one way to check is by looking at the device's onboard status in the device management report. However, the most reliable method would be to run the Endpoint DLP test on both types of devices and compare the results. This test should help clarify whether the policy is being actively applied by the Defender or if it's fully enforced via DLP.

    Hope this helps. Do let us know if you any further queries.


    If this answers your query, do click Accept Answer and Yes for was this answer helpful. And, if you have any further query do let us know.

    0 comments No comments

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.