Compliance and Data ProtectionJune 10, 2026Serdar YAMAN5 min read

A Free DLP Start with Microsoft 365 and Google Workspace's Built-In Rules

A Free DLP Start with Microsoft 365 and Google Workspace's Built-In Rules

TL;DR: The right order for enabling built-in DLP: choose the data types to protect (national ID numbers, IBANs, card numbers) → start the policy in report-only mode → read a month of reports and whitelist the legitimate flows → move to the user-warning stage → enable blocking only on the clearest patterns. This staged path saves DLP projects from their usual fate: "it blocked everything, we turned it off." The built-in layer does not see everything, but it catches the bulk of leakage on email and sharing channels at zero extra licence cost.

This article answers the objection we hear most: "DLP sounds good — where does the budget come from?" In most businesses the surprising answer is: the budget is already spent. Parts of Microsoft 365's and Google Workspace's business plans include built-in DLP — real DLP that recognises patterns like ID numbers, card numbers and IBANs in email and sharing, and applies policy. What is missing is not the product but the hand that switches it on.

First, the Plan Check: What Do You Have?

Step one takes five minutes: check in your admin panel whether the DLP/data-protection section is available on your plan. On the Microsoft side these capabilities live in the upper business tiers (and compliance add-ons); on the Google side similarly in the upper business tiers; since plan names and scopes shift over time, verify the current state from the panel and plan comparison. If your plan lacks it, two routes: weigh the tier difference during a licence-optimisation window (usually only the critical users move up a tier — not everyone), or carry this article's rule logic into a third-party tool.

What to Protect: Three Starting Patterns

PatternWhy firstTypical legitimate exception
National ID numbers (in bulk)The heart of data-protection law; an email carrying many IDs is usually a list leakAccounting's filings to authorities
IBAN + amount combinationsThe intersection of financial fraud and leakageThe finance team's bank correspondence
Card-number patternsShould never travel by email in any legitimate flowNone — the strictest-rule candidate

Do not open more than three patterns at the start: what drowns DLP projects is not too few rules but the alarm flood of thirty rules opened in week one. Your data inventory already says which data is critical — DLP is that inventory's technical guard.

Three-Stage Rollout: Watch → Warn → Block

Stage 1: Report-Only (the First 30 Days)

Policies start by producing incident records and blocking nothing. This month's output is gold: who sends which data where, with what business justification — your real flow map. You look for two things in the report: genuine risks (the customer list heading to a personal address) and legitimate business flows (the raw material of the exception list).

Stage 2: the User Warning

In month two, the policy warns the sender at the moment of action: "This message appears to contain an ID number; are you sure you want to send it?" This stage's power is educational — most leakage is absent-mindedness, not malice, and the warning corrects behaviour without punishment. Sends despite the warning are logged; the pattern nominates stage three's candidates.

Stage 3: Selective Blocking

Blocking opens only on unambiguous patterns (card numbers; bulk ID lists leaving the company) — together with an exceptions process: whoever has a legitimate need must be able to do their work through a defined route (approved exception, a secure sharing channel). A user who is blocked and shown no alternative carries the data to a personal channel — DLP's bitterest irony, where DLP itself breeds shadow IT.

Coverage: What It Sees and What It Does Not

Built-in DLP's natural territory is the suite's own channels: mail flow, files and share links in the cloud storage, in-ecosystem messaging. Its blind spots must be known too: files copied to local disks, USB writes, uploads to third-party apps and screenshots — those layers belong to endpoint DLP (a separate product/tier). The honest assessment: the built-in layer covers the bulk of the typical SMB leak surface (email to the wrong recipient, the uncontrolled share link); for the remaining surface, foundation layers like disk encryption and access discipline come first, then endpoint DLP if genuinely needed.

Who Reads the Reports?

DLP's cause of death is not technical: it gets enabled, alarms pile up, nobody looks, one day it is switched off. Three duties are assigned at setup: a weekly review of incident reports (15 minutes), recurring legitimate flows bound into exceptions, and real incidents handed to the incident process. With that rhythm in place, DLP becomes not alarm noise but a quiet guard producing a few meaningful signals a month.

A DLP Start with Yamanlar Bilişim

Our DLP builds apply this article's plan: the plan/licence check, a three-pattern start, the first month in report mode, and staged tightening with the findings. For maintenance-agreement customers, the weekly report review joins our routine, and incidents are reported in the language of your compliance file.

FAQ

Frequently Asked Questions

Does DLP mean covertly monitoring employees?

No — a proper build is transparent: the policy watches data patterns, not people; users see the system's existence at the warning stage anyway, and it appears in the staff privacy notice. Covert, boundless monitoring is both an ethical and a legal problem; DLP's legitimacy lies in purpose limitation.

Won't the ID-number pattern alarm on every routine message?

Thresholds handle legitimate single-ID correspondence: the rule watches, say, messages containing more than five ID numbers — the target is the list leak, not one customer's details. The threshold is calibrated with month one's report data.

DLP cannot read encrypted/password-protected files — isn't that a hole?

Partly — which is why "an encrypted attachment whose content cannot be scanned" can itself be added to the policy as a signal. But keep perspective: the goal is not stopping the determined insider a hundred percent (a different threat model) but cutting the absent-mindedness and carelessness leaks — the vast majority of cases.

Which team should pilot first?

The one working most with sensitive data on the best-defined flows: usually accounting/HR. The pilot fills the exception list with real flows and leaves no surprises at company-wide rollout. Involve management early too — the riskiest data usually travels on the top floor.

Will this build help in a data-protection audit?

Yes, in two ways: it is a concrete answer to the "appropriate technical measures" question, and when an incident happens, the incident records and exceptions process document the organisation's diligence. DLP alone is not compliance — but it is one of the compliance file's most persuasive technical pages.

Share:
SY

Author

Serdar YAMAN

Yamanlar Bilişim Expert

Writes content on IT infrastructure, cybersecurity, and digital transformation at Yamanlar Bilişim. Get in touch for any questions.

Professional Support

Get help on this topic

Let's design the Compliance and Data Protection solution you need together. Our experts get back to you within 1 business day.

support@yamanlarbilisim.com · Response time: 1 business day