Three layers that work like a good team and slides to show it
Data Loss Prevention (DLP) is not new, many use it daily without ever even knowing it, but with AI bringing faster results for productivity so does the risk of data leakage. That is where we take a layered approach, meeting the end user exactly where they are working, on a device, or in a browser, or through that cute cat Office add-in that had to be installed. But don’t think of layered protection as three products but more as three specialists who are each excellent at their own job and have the good sense not to try doing everyone else’s.
- Endpoint DLP lives on the device. USB and removable media, clipboard, print, restricted apps. It carries the deepest classification support, EDM, fingerprinting, OCR, and it works offline, which turns out to be more useful than it sounds at 30,000 feet.
- Browser Data Security lives in the session, inline in Edge for Business, checking content before an upload or a form submission. It is the most precise layer for AI prompts and for activity happening inside a managed web app, where nothing else is standing close enough to help.
- Network Data Security lives on the wire, via Entra Global Secure Access or a third-party SASE. It handles traffic that never touches a browser at all, desktop apps, Office add-ins quietly phoning a friend, and it is the layer that supports inbound classification of content coming back from cloud and AI apps.
Each one has natural technical boundaries, and those are a design decision rather than an oversight. A network proxy is never going to have strong opinions about a USB stick. An endpoint agent is not positioned to unwrap an encrypted API call from a third-party add-in. Ask any one of them to cover all three domains and you would end up with something slower and less capable at each.
Deployed together, though, the edges line up rather nicely. That is the entire premise of layered protection, and it is what I built this asset to show.
What is actually in the slides
- A coverage view across all three layers. Common activities — removable media, RDP sessions, add-in API calls, in-session copy and paste, inbound AI content, classification depth, inline prompt inspection — matched to the layer best positioned for each.
- Six scenario walkthroughs. Realistic situations traced attempt by attempt, including one determined individual who tries three separate routes to get the same file to a consumer AI service. A departing employee and a USB drive. A contractor on a personal laptop. Files headed to personal cloud storage. Each shows which layer engages, and why.
- Deployment flows you can follow. Prerequisites, permissions, policy names, conditions, actions. Both browser patterns (managed device with unmanaged apps, unmanaged device with managed apps) and both network paths (Entra GSA, and third-party SASE including Netskope and iBoss).
- Four reference architectures. Traffic flow diagrams for each browser and network model — what gets evaluated, where the Purview verdict comes from, where enforcement lands.
- Collection policies explained thoroughly. The unsung plumbing underneath all of it. Anatomy, the full flow from event source to Activity Explorer, Insider Risk Management, eDiscovery, and Data Security Posture Management (DSPM), plus the operational details that are much nicer to learn about in a deck than in production.
Collection policy break down from end to end
The parts people keep coming back to
The coverage view is usually where planning conversations start. It gives everyone a shared picture of what is deployed today and what a sensible next step looks like; adding the browser layer to an existing Endpoint DLP footprint, say, or bringing in the network layer to extend coverage to add-ins and desktop apps.
The scenario walkthroughs are where it tends to click for a wider audience. Following one situation through several routes and watching a different layer step in at each turn, does more for the story than any static diagram I have drawn.
And the deployment flows are genuinely meant to be executed. Everyone is written to run against a pilot group first, with Conditional Access in report-only mode in production until you have confirmed the behavior. Please do that part. Your future self will appreciate it.
Who it is for
Architects scoping a deployment. Partners running workshops. Admins with Endpoint DLP already humming along who are working out what comes next. Anyone who would like a single starting point instead of a browser window that has stopped showing page titles.
Take whatever is useful. Pull individual slides into your own narrative or run the whole thing end to end it was built to be borrowed.
Things to keep in mind
Several capabilities in here are in preview or Pay-As-You-Go backed, and network-layer coverage depends on supported SASE/SSE integrations and how traffic is routed. The deck flags this as it goes. Check current availability on Microsoft Learn, and with your SASE provider for the network layer.
Now the fun
The full slide set is at https://aka.ms/purviewlayeredprotection.
It is a living reference, and it will keep evolving with the product. If it helps you plan something, or if there is a scenario you would like to see in the next version, I would love to hear about it.


