By clicking “Accept”, you agree to the storing of cookies on your device to enhance site navigation, analyze site usage, and assist in our marketing efforts. View our Cookie Policy for more information.
Icon Rounded Closed - BRIX Templates
Insights

Purview DLP for Box, Google Workspace, Dropbox, and Salesforce

5 mins
share on
Purview DLP for Box, Google Workspace, Dropbox, and Salesforce

Your DLP Stops at Microsoft 365. Your Data Doesn't

There is a date on your calendar you may not have put there. On January 6, 2027, file policies in Microsoft Defender for Cloud Apps stop being enforced.

Not deprecated with a grace period. Not supported in a reduced capacity. They stop running, and anything they were catching stops being caught.

If your organization uses Defender for Cloud Apps file policies to scan content in Box, Google Drive, Dropbox or Salesforce, that is a migration project with a hard deadline and a live exposure window at the end of it.

The good news is that Microsoft has shipped the replacement, and it is genuinely better than what it replaces.

The problem: sensitive data rarely stays in one productivity suite

Ask most security leaders where their sensitive data lives and the honest answer is "everywhere." Sales runs on Salesforce. Marketing shares decks through Box or Dropbox. Engineering builds on AWS. The service desk logs tickets, some of them containing customer records, in ServiceNow.

Meanwhile the DLP policy you spent three months tuning covers Exchange, SharePoint, OneDrive and Teams. Everything beyond that boundary has been a separate console, a separate policy language and a separate set of people to chase when something goes wrong.

That fragmentation is expensive in three ways:

  • Inconsistent enforcement. The same customer record is blocked in SharePoint and freely shareable in Box.
  • Duplicated taxonomy. Two definitions of "sensitive," maintained by two teams, drifting apart quarter by quarter.
  • Audit gaps. When a regulator asks how you protect PII, "it depends which system" is not a satisfying answer.

If you are still mapping which Purview capabilities your licence actually unlocks before tackling any of this, start with our breakdown of Purview licensing across E3, E5 and add-ons.

What is supported, precisely

This is where organizations get tripped up, because two authoritative Microsoft sources currently say slightly different things.

  • DLP policy locations. The Message Center notice (MC1449180, Roadmap ID 568075) lists Google Workspace, Box, Dropbox, Salesforce, ServiceNow, AWS and Cisco Webex. The Microsoft Learn documentation, as published, lists a narrower set: Box, Dropbox, Google Workspace and Salesforce.
  • Auto-labeling locations. Both sources agree, and the list is short: Google Workspace and Box only.

Microsoft notes that these apps are rolling out in phases and that not every app will appear in every tenant at the same time.

The takeaway: do not design your target architecture off a blog post. Open the Purview portal, look at which locations are actually available in your tenant today, and scope your migration to what you can see.

DLP condition and action availability by non-Microsoft application

The January 6, 2027 retirement and what you must rebuild

Two things retire together, and it is worth being precise about both:

  1. Defender for Cloud Apps file policies stop being supported and enforced.
  2. The Instances policy location in Purview DLP, along with its policy creation experience, retires on the same date. Microsoft's guidance is to recreate those policies using the new dedicated application locations before then.

That second point catches people out. If you already moved third-party DLP into Purview by scoping policies to Instances, you are not finished. You are on the same deadline as everyone else.

The rebuild splits cleanly along intent:

  • Policies that detect sensitive content and respond (alert, quarantine, restrict sharing) become Purview DLP policies.
  • Policies that apply a sensitivity label based on content become Purview auto-labeling policies.
  • A single Defender policy doing both becomes two Purview policies.

One important limitation: Microsoft's DLP to Purview migration tool currently supports SharePoint and OneDrive file policies only. DLP and auto-labeling migration for non-Microsoft apps, including Google Workspace, Box, Dropbox and Salesforce, is not yet supported and appears in the wizard as a "coming soon" callout. Your third-party policies are a manual rebuild today. Plan the hours accordingly.

For a broader view of sequencing a Purview move without opening a protection gap, see our migration strategies guide for IT leaders.

How it works under the hood

There is no new agent and no new connector framework to learn. Purview reuses the existing Microsoft Defender for Cloud Apps app connectors to reach into these applications. Connect the app in Defender, then build the policy in Purview.

More importantly, you keep your classification investment. The same sensitive information types, trainable classifiers and sensitivity labels you already use for Microsoft 365 apply to Box and Google Drive content. One taxonomy, more destinations.

If your classification foundation is thin, that becomes the bottleneck rather than the connectors. Our primer on Purview data classification and sensitivity labels covers what "good" looks like before you extend it across clouds.

The honest caveats

This is not a lift-and-shift, and anyone telling you otherwise has not read the fine print.

  • Enforcement is not identical across apps. Microsoft states plainly that available conditions and actions vary by application, spanning content inspection, labeling, notifications, quarantine and access controls. Expect asymmetry between what you can enforce in Box and what you can enforce in Salesforce. Document it rather than assuming parity.
  • Connecting Google Workspace needs Google-side authority. The Defender for Cloud Apps connector is not something your M365 admin can complete alone. Involve whoever holds Google Super Admin early, because waiting on that access mid-project is a classic schedule killer.
  • Do not run both engines at once. Microsoft is explicit: turn off or delete existing Defender for Cloud Apps file policies for a location before creating Purview policies for that same location. Running both can produce unexpected enforcement.
  • Roles are not shared. The admin who manages Defender file policies today may have no Purview DLP access at all. Verify role assignments before you start.
  • It is still preview. The non-Microsoft connected apps experience carries preview terms. Pilot it, do not bet your audit on it yet.

Rollout timing

  • Public preview: began mid-August 2026, expected to complete early September 2026.
  • General availability (worldwide): beginning early September 2026, expected to complete late October 2026.

Which means the realistic planning window is short. GA completes late October 2026, and Defender file policies stop enforcing January 6, 2027. That is roughly ten weeks of overlap for design, pilot, validation and cutover. Treat this as a Q4 2026 project, not a 2027 one.

Cost and least-privilege setup

Two things to settle before anyone clicks Enable.

  • Pricing. Usage bills through the Microsoft Purview At Rest Protection pay-as-you-go meter, where at-rest files in non-Microsoft applications are metered at 1,000 files equal to one data asset. If you are pointing this at a Box tenant with millions of files, model the cost before the pilot, not after the first invoice.
  • Permissions. Microsoft's guidance is unambiguous: use Compliance Administrator, Compliance Data Administrator, Information Protection, Information Protection Admin or Security Administrator. Global Administrator should be reserved for scenarios where nothing lesser will work.

Map your multi-cloud data exposure before the deadline

Most organizations we work with discover the same thing when they inventory their Defender file policies: a third are redundant, a third no longer match how the business actually handles data, and the remaining third are load-bearing in ways nobody documented.

A migration with a fixed date is the rare chance to fix that rather than faithfully rebuilding a decade of accumulated policy debt.

Book a governance assessment and we will map where your sensitive data actually lives, which policies are worth carrying forward, and what your Purview target state should look like well before January 2027.

Frequently asked questions

Which non-Microsoft apps does Purview DLP support?

Microsoft's Message Center notice lists Google Workspace, Box, Dropbox, Salesforce, ServiceNow, AWS and Cisco Webex, while the Learn documentation currently lists Box, Dropbox, Google Workspace and Salesforce. Apps roll out in phases, so confirm availability in your own tenant.

Can Purview auto-label files in Google Workspace?

Yes, auto-labeling support covers Google Workspace and Box only, using the same sensitive information types and classifiers you already use for Microsoft 365 content.

When are Defender for Cloud Apps file policies retired?

January 6, 2027. The Instances policy location in Purview DLP retires on the same date.

Do I need Defender for Cloud Apps to use this?

Yes, Purview relies on existing Defender for Cloud Apps app connectors to reach the third-party application. Defender continues to handle SaaS discovery, posture management and threat detection. Only file-based data protection moves to Purview.

Does Purview DLP work the same way in Box as in SharePoint?

Not identically. The classification engine is shared, but available conditions and actions vary by application. Validate enforcement behaviour per app rather than assuming your SharePoint policy translates one to one.

Map your multi-cloud data exposure before the deadline.
Case Study Details

Similar posts

Get our perspectives on the latest developments in technology and business.
Love the way you work. Together.™
Next steps
Have a question, or just say hi. 🖐 Let's talk about your next big project.
Contact us
Mailing list
Occasionally we like to send clients and friends curated articles that have helped us improve.
Close Modal