Microsoft Purview DLP Paste Blocking Differences Across Browsers in Microsoft 365 Business Premium

Atharva Deshpande 20 Reputation points
2025-11-27T11:00:58+00:00

We are using Microsoft 365 Business Premium with Microsoft Purview Suite and have implemented DLP policies. We notice that copy-paste of text containing sensitive data is blocked on Edge and Chrome as expected. However, in browsers like Firefox and Brave, copy-paste still works for sensitive text. Interestingly, file uploads appear to be blocked in Firefox and Brave, while text paste is not.

Can someone clarify why file upload blocking works on Firefox and Brave but paste blocking doesn't? Are there additional configurations or extensions required for Firefox and Brave to fully enforce Purview DLP for copy-paste? Any guidance on best practices for consistent DLP enforcement across these browsers would be appreciated.

Update

Why File Upload Is Blocked but Copy-Paste Isn’t

  • Endpoint DLP policies in Microsoft Purview primarily monitor and restrict file-level activities (e.g., upload, print, copy to USB).
  • Copy-paste of text is treated differently because:
    • Text copied from Word or other apps is not always classified as a “file” operation.
      • DLP relies on content inspection and classification (sensitive info types, labels) to trigger restrictions.
        • Browser behavior (Firefox, Brave) does not expose clipboard events in the same way as file operations, so enforcement is limited.

 Is It a Browser Limitation?

  • Partially. Chromium-based browsers (Edge, Chrome) have better integration with Microsoft Purview DLP.
  • Firefox and Brave do not fully support the same APIs for clipboard monitoring, so copy-paste blocking is inconsistent.

 Policy Limitation

  • Endpoint DLP does not universally block all copy-paste actions unless:
    • The content matches a sensitive info type or label.
      • The app/browser supports the required telemetry.

 What You Can Do

  1. Verify Sensitive Info Types
    • Ensure the policy is configured to detect specific sensitive data (e.g., credit card numbers, PII).
      • Generic text may not trigger the block.
      1. Use Microsoft Edge for Testing
        • Edge provides full DLP integration, including better clipboard monitoring.
  2. Consider App Control
    • For strict copy-paste prevention, combine DLP with AppLocker or Microsoft Defender for Endpoint policies.Why File Upload Is Blocked but Copy-Paste Isn’t
    • Endpoint DLP policies in Microsoft Purview primarily monitor and restrict file-level activities (e.g., upload, print, copy to USB).
    • Copy-paste of text is treated differently because:
      • Text copied from Word or other apps is not always classified as a “file” operation.
      • DLP relies on content inspection and classification (sensitive info types, labels) to trigger restrictions.
      • Browser behavior (Firefox, Brave) does not expose clipboard events in the same way as file operations, so enforcement is limited.

     Is It a Browser Limitation?

    • Partially. Chromium-based browsers (Edge, Chrome) have better integration with Microsoft Purview DLP.
    • Firefox and Brave do not fully support the same APIs for clipboard monitoring, so copy-paste blocking is inconsistent.
     

     Policy Limitation

    • Endpoint DLP does not universally block all copy-paste actions unless:
      • The content matches a sensitive info type or label.
      • The app/browser supports the required telemetry.

     What You Can Do

    1. Verify Sensitive Info Types
      • Ensure the policy is configured to detect specific sensitive data (e.g., credit card numbers, PII).
      • Generic text may not trigger the block.
    2. Use Microsoft Edge for Testing
      • Edge provides full DLP integration, including better clipboard monitoring.
    3. Consider App Control
      • For strict copy-paste prevention, combine DLP with AppLocker or Microsoft Defender for Endpoint policies.
Microsoft Security | Microsoft Purview
0 comments No comments
{count} votes

3 answers

Sort by: Most helpful
  1. Q&A Assist
    2025-11-27T11:01:10.0166667+00:00
    AI generated content. This question contains an answer created with AI from Q&A Assist. Learn more

    The behavior you're observing with Microsoft Purview DLP policies regarding copy-paste and file uploads across different browsers is influenced by how these browsers interact with the DLP settings.

    1. Paste Blocking: The Paste to browser action is supported in Microsoft Edge and Google Chrome (with the Microsoft Purview extension). However, for Mozilla Firefox and Brave, while file uploads are blocked, the paste action may not be enforced as effectively. This is likely due to the fact that the paste action in these browsers does not follow the same behavior defined in the Service Domain list unless the appropriate extensions are installed and configured. The Paste to browser action does not work with the Service domains endpoint DLP setting, which could explain why you're seeing inconsistencies.
    2. File Upload Blocking: File uploads are detected and blocked in Firefox and Brave when users attempt to upload items to restricted service domains. This functionality is supported as long as the Microsoft Purview extension is installed in the browsers that support it.

    To ensure consistent DLP enforcement across all browsers, consider the following best practices:

    • Install Microsoft Purview Extensions: Ensure that the Microsoft Purview extension is installed in Firefox and any other browsers you wish to enforce DLP policies on.
    • Regularly Update Browsers and Extensions: Keep all browsers and extensions updated to the latest versions to ensure compatibility with DLP features.
    • Review DLP Policy Configurations: Double-check your DLP policy settings to ensure they are correctly configured for all browsers, including any exceptions or specific rules that may apply to different browsers.
    • Test DLP Policies: Conduct regular testing of your DLP policies across all supported browsers to identify any discrepancies in behavior and address them promptly.

    By following these practices, you can enhance the effectiveness of your DLP policies across different browsers.

    0 comments No comments

  2. Atharva Deshpande 20 Reputation points
    2025-11-27T12:20:39.5533333+00:00

    Update posted in the question

    0 comments No comments

  3. VRISHABHANATH PATIL 1,820 Reputation points Microsoft External Staff Moderator
    2025-12-04T06:55:16.1033333+00:00

    Hi @Atharva Deshpande **

    **Thank you for contacting to Microsoft QA, below are few step-by-step mitigation details that may help you to resolve the issue.

    It seems you’re noticing some inconsistencies with Microsoft Purview DLP policies when using different browsers, especially around copy-paste functionality. Let’s break it down and make sense of what’s happening:

    Why File Uploads Are Blocked but Copy-Paste Isn’t

    • File Operations vs. Copy-Paste: DLP policies are designed to monitor file-level actions like uploads and printing. Copying and pasting text is treated differently because it doesn’t always count as a file operation. Restrictions usually kick in based on content classification, which may not apply to simple text copied from apps like Word or a browser.
    • Browser Differences: Browsers like Edge and Chrome (both Chromium-based) work more smoothly with Microsoft Purview DLP because they support the necessary APIs for clipboard monitoring. Firefox and Brave don’t fully support these APIs, which is why copy-paste enforcement can feel inconsistent.

    How to Make DLP Enforcement More Consistent

    • Check Sensitive Info Types: Ensure your DLP policy is set up to detect the right sensitive data types (e.g., PII, credit card numbers). Generic text often won’t trigger any blocks.
    • Test in Microsoft Edge: Edge offers the best integration for clipboard monitoring and DLP actions, so it’s ideal for testing.
    • Consider App Control: If you need stricter copy-paste prevention, combine DLP with AppLocker or Microsoft Defender for Endpoint policies for a more robust approach.
    • Look into Protected Clipboard: This feature (currently in preview) in Microsoft Edge for Business gives organizations better control over copy-paste actions, helping prevent data from being pasted into unmanaged apps or outside approved boundaries.

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.