A Free DLP Start with Microsoft 365 and Google Workspace's Built-In Rules

TL;DR: The right order for enabling built-in DLP: choose the data types to protect (national ID numbers, IBANs, card numbers) → start the policy in report-only mode → read a month of reports and whitelist the legitimate flows → move to the user-warning stage → enable blocking only on the clearest patterns. This staged path saves DLP projects from their usual fate: "it blocked everything, we turned it off." The built-in layer does not see everything, but it catches the bulk of leakage on email and sharing channels at zero extra licence cost.
This article answers the objection we hear most: "DLP sounds good — where does the budget come from?" In most businesses the surprising answer is: the budget is already spent. Parts of Microsoft 365's and Google Workspace's business plans include built-in DLP — real DLP that recognises patterns like ID numbers, card numbers and IBANs in email and sharing, and applies policy. What is missing is not the product but the hand that switches it on.
First, the Plan Check: What Do You Have?
Step one takes five minutes: check in your admin panel whether the DLP/data-protection section is available on your plan. On the Microsoft side these capabilities live in the upper business tiers (and compliance add-ons); on the Google side similarly in the upper business tiers; since plan names and scopes shift over time, verify the current state from the panel and plan comparison. If your plan lacks it, two routes: weigh the tier difference during a licence-optimisation window (usually only the critical users move up a tier — not everyone), or carry this article's rule logic into a third-party tool.
What to Protect: Three Starting Patterns
| Pattern | Why first | Typical legitimate exception |
|---|---|---|
| National ID numbers (in bulk) | The heart of data-protection law; an email carrying many IDs is usually a list leak | Accounting's filings to authorities |
| IBAN + amount combinations | The intersection of financial fraud and leakage | The finance team's bank correspondence |
| Card-number patterns | Should never travel by email in any legitimate flow | None — the strictest-rule candidate |
Do not open more than three patterns at the start: what drowns DLP projects is not too few rules but the alarm flood of thirty rules opened in week one. Your data inventory already says which data is critical — DLP is that inventory's technical guard.
Three-Stage Rollout: Watch → Warn → Block
Stage 1: Report-Only (the First 30 Days)
Policies start by producing incident records and blocking nothing. This month's output is gold: who sends which data where, with what business justification — your real flow map. You look for two things in the report: genuine risks (the customer list heading to a personal address) and legitimate business flows (the raw material of the exception list).
Stage 2: the User Warning
In month two, the policy warns the sender at the moment of action: "This message appears to contain an ID number; are you sure you want to send it?" This stage's power is educational — most leakage is absent-mindedness, not malice, and the warning corrects behaviour without punishment. Sends despite the warning are logged; the pattern nominates stage three's candidates.
Stage 3: Selective Blocking
Blocking opens only on unambiguous patterns (card numbers; bulk ID lists leaving the company) — together with an exceptions process: whoever has a legitimate need must be able to do their work through a defined route (approved exception, a secure sharing channel). A user who is blocked and shown no alternative carries the data to a personal channel — DLP's bitterest irony, where DLP itself breeds shadow IT.
Coverage: What It Sees and What It Does Not
Built-in DLP's natural territory is the suite's own channels: mail flow, files and share links in the cloud storage, in-ecosystem messaging. Its blind spots must be known too: files copied to local disks, USB writes, uploads to third-party apps and screenshots — those layers belong to endpoint DLP (a separate product/tier). The honest assessment: the built-in layer covers the bulk of the typical SMB leak surface (email to the wrong recipient, the uncontrolled share link); for the remaining surface, foundation layers like disk encryption and access discipline come first, then endpoint DLP if genuinely needed.
Who Reads the Reports?
DLP's cause of death is not technical: it gets enabled, alarms pile up, nobody looks, one day it is switched off. Three duties are assigned at setup: a weekly review of incident reports (15 minutes), recurring legitimate flows bound into exceptions, and real incidents handed to the incident process. With that rhythm in place, DLP becomes not alarm noise but a quiet guard producing a few meaningful signals a month.
A DLP Start with Yamanlar Bilişim
Our DLP builds apply this article's plan: the plan/licence check, a three-pattern start, the first month in report mode, and staged tightening with the findings. For maintenance-agreement customers, the weekly report review joins our routine, and incidents are reported in the language of your compliance file.
FAQ
Frequently Asked Questions
Does DLP mean covertly monitoring employees?
No — a proper build is transparent: the policy watches data patterns, not people; users see the system's existence at the warning stage anyway, and it appears in the staff privacy notice. Covert, boundless monitoring is both an ethical and a legal problem; DLP's legitimacy lies in purpose limitation.
Won't the ID-number pattern alarm on every routine message?
Thresholds handle legitimate single-ID correspondence: the rule watches, say, messages containing more than five ID numbers — the target is the list leak, not one customer's details. The threshold is calibrated with month one's report data.
DLP cannot read encrypted/password-protected files — isn't that a hole?
Partly — which is why "an encrypted attachment whose content cannot be scanned" can itself be added to the policy as a signal. But keep perspective: the goal is not stopping the determined insider a hundred percent (a different threat model) but cutting the absent-mindedness and carelessness leaks — the vast majority of cases.
Which team should pilot first?
The one working most with sensitive data on the best-defined flows: usually accounting/HR. The pilot fills the exception list with real flows and leaves no surprises at company-wide rollout. Involve management early too — the riskiest data usually travels on the top floor.
Will this build help in a data-protection audit?
Yes, in two ways: it is a concrete answer to the "appropriate technical measures" question, and when an incident happens, the incident records and exceptions process document the organisation's diligence. DLP alone is not compliance — but it is one of the compliance file's most persuasive technical pages.
Author
Serdar YAMAN
Yamanlar Bilişim Expert
Writes content on IT infrastructure, cybersecurity, and digital transformation at Yamanlar Bilişim. Get in touch for any questions.
Professional Support
Get help on this topic
Let's design the Compliance and Data Protection solution you need together. Our experts get back to you within 1 business day.
support@yamanlarbilisim.com · Response time: 1 business day
Keep Reading
Related Articles

Turkey's KVKK and Cross-Border Data Transfers: a Cloud Reality Check
If your company email or files are hosted in a data centre outside Turkey, the KVKK's cross-border transfer rules apply to you. The standard-contract regime introduced in 2024, the cloud service inventory, and the concrete IT-side steps — in plain language.

NIS2 and Turkish Suppliers: What Will Your EU Customer Ask of You?
Europe's NIS2 directive obliges in-scope companies to secure their supply chains too. Turkish SMBs selling into the EU are now receiving security questionnaires and contract clauses — here is what will be asked, and how to be ready before it arrives.

Disposing of Old Computers Securely: the Data Destruction and e-Waste Guide
Old computers gathering dust in the store room are not assets — they are open filing cabinets with customer data on their disks. Why formatting is not enough, the right destruction method per disk type, the record-keeping, and the e-waste handover, step by step.