Microsoft Purview not Blocking when I copy sensitive data to clipboard from browser

Vernon Polius 0 Reputation points
2026-02-20T17:09:04.6266667+00:00

Hi,

I am currently in the process of setting up Purview to detect and block copying of Sensitive data and confidential labeled documents in Microsoft Word. Currently the policy works and blocks successfully when I open the documents in the Word Desktop app. When I open the document in the browser version of Word however this does not work. I thought the purview extension in Edge would allow me to do this. I am looking for guidance on how to use purview to block copying of sensitive data or words when the document is opened in the browser version of Word.

Microsoft Security | Microsoft Purview
0 comments No comments

2 answers

Sort by: Most helpful
  1. SAI JAGADEESH KUDIPUDI 3,640 Reputation points Microsoft External Staff Moderator
    2026-03-16T14:29:44.1533333+00:00

    Hi Vernon Polius,
    The behavior you are experiencing is expected due to how Microsoft Purview DLP enforces protection in Desktop apps vs Web apps.

    When the document is opened in Microsoft Word Desktop, the enforcement occurs through Endpoint DLP integrated with the Office client, which allows actions such as Copy to clipboard to be blocked and logged in Activity Explorer.

    However, when the same document is opened in Word Online (Word for the Web), the content is rendered through SharePoint/OneDrive in the browser, and clipboard actions depend on browser-based enforcement instead of Office client enforcement. Because of this architectural difference, clipboard blocking may not trigger in Word Online even if the Endpoint DLP policy is configured correctly, and Activity Explorer may not record the event.

    Since you confirmed that:

    • Devices are successfully onboarded to Endpoint DLP

    The DLP rule includes “Copy to clipboard = Block”

    The policy is scoped to the users and devices

    Clipboard blocking works correctly in Word Desktop

    This indicates that the policy configuration is correct, and the difference is due to how DLP enforcement works in browser-based Office applications.

    For browser scenarios, Microsoft recommends using Microsoft Edge with additional browser protections such as Edge for Business cloud sharing restrictions and protected clipboard policies, which provide deeper integration with Microsoft Purview.
    The configuration appears correct, and the difference occurs because Word Desktop uses Office client enforcement while Word Online relies on browser-based enforcement. Implementing Edge browser protection policies together with Endpoint DLP is the recommended approach to provide stronger protection for browser-based Office applications.

    Reference Links:
    Endpoint Data Loss Prevention overview
    Configure Endpoint DLP settings
    Prevent cloud sharing from Microsoft Edge for Business

    Hope this helps. If you have any follow-up questions, please let me know. I would be happy to help.

    Please do not forget to "up-vote" wherever the information provided helps you, as this can be beneficial to other community members.

    Was this answer helpful?

    1 person found this answer helpful.

  2. Jerome Suggs 5 Reputation points
    2026-02-21T20:38:09.6833333+00:00

    Based on how Purview enforcement typically works, this difference between Desktop Word and Word Online is usually related to where enforcement is happening.

    Desktop Word uses the Office client + endpoint DLP integration, so blocking clipboard actions works there.

    Word Online relies on service-side DLP (SharePoint/OneDrive) and endpoint/browser integration. The Edge extension alone doesn’t automatically enforce clipboard blocking unless Endpoint DLP and browser-based protections are fully configured.

    I would check:

    Whether the device is onboarded to Endpoint DLP

    Whether the DLP policy targets endpoint devices (not just Exchange/SharePoint)

    Whether browser protection settings are enabled

    Whether the sensitivity label includes protection vs just classification

    If desktop works but browser does not, it usually indicates enforcement is happening at the Office client layer but not the endpoint/browser layer.

    You may find this helpful: https://learn.microsoft.com/microsoft-365/compliance/endpoint-dlp

    Was this answer helpful?


Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.