Power BI DLP (Data Loss Prevention) is essential for organizations handling sensitive or confidential data. Traditional access controls like role-level security or data masking are useful but often too manual or limited. Microsoft Purview now makes it easier to monitor and secure sensitive data automatically across Power BI and Fabric with powerful DLP policies. In this guide, you’ll learn how to set up, test, and refine DLP policies tailored for your data environment.
What Is DLP in Microsoft Purview?
Data Loss Prevention (DLP) helps organizations detect and prevent the unauthorized sharing of sensitive data. With Purview, DLP is integrated across Microsoft 365, including Power BI and Fabric.
Key benefits:
- Identify sensitive data using labels or content types
- Monitor activity across reports and datasets
- Automate alerts, encryption, and access restrictions
- Provide user policy tips to promote secure behavior
Setting Up a DLP Policy for Power BI & Fabric
1. Navigate to Microsoft Purview
Start in Microsoft Purview, where all DLP configurations are managed. Go to Solutions → Explore All → Data Security → Data Loss Prevention.
2. Create a Custom DLP Policy
Since templates for Power BI and Fabric aren’t available, choose “Create Policy” using a custom template.
- Name: “Highly Confidential Data Monitor”
- Scope: Apply to full directory (admin units not yet supported for Fabric/Power BI)
- Target Location: Power BI and Microsoft Fabric workspaces

3. Define DLP Rules and Conditions
Create a rule called “Highly Confidential Data” and define conditions such as:
- Label Match: Content labeled as Highly Confidential
- Sensitive Info Match: Detect US Passport Numbers or similar
- Confidence Level: High
- Match Count: Between 1 and any number

4. Set Enforcement Actions
Choose how to respond when sensitive content is detected:
- Restrict Access to users outside your organization
- Notify Users via in-context policy tips
- Allow Overrides for false positives or business exceptions
Example Policy Tip:
“You are accessing highly confidential data. Only access, share, or store it if necessary for your role.”
5. Configure Incident Reporting
Set the severity level and who should be notified:
- Severity: High
- Email Alerts: Admin or data protection officer
- Thresholds: Only notify if multiple matches are found, or for every detection
Run the Policy in Simulation Mode
Before enforcing actions, test the policy in simulation mode:
- Allows you to see how the policy performs
- View which reports or semantic models trigger alerts
- Fine-tune the policy rules as needed
Testing DLP in Action
Example 1: Sensitivity Label Applied
- A Power BI report is labeled “Highly Confidential”
- Upon publishing, a policy tip appears warning the user
- The user can choose to override or report a false positive
Example 2: Detected Sensitive Info
- Another report contains email addresses and US passport numbers
- Even though it’s labeled “General Use”, DLP detects content based on rules
- The report triggers a simulation match
- Admins can view details in Purview and decide on action
Admin Dashboard: Monitor Policy Matches
In Purview:
- Go to your DLP Policy Overview
- View active matches and affected assets (e.g., HR Report)
- Drill down to review flagged items, adjust rules, or enforce actions
Current Limitations & Support
Power BI and Fabric DLP support is still evolving. Currently supported asset types include:
- Semantic Models
- Lakehouses
- KQL Databases
- Mirrored Databases
Final Thoughts: Secure Your BI with Confidence
DLP in Microsoft Purview gives you more than just access controls it offers a proactive, intelligent framework for data governance. Whether you’re managing hundreds of reports or trying to protect PII data across Fabric, DLP helps you stay ahead.
Start small with simulation mode, tune your rules, and scale up enforcement when ready.
Learn More
Get Expert Power BI Training
Take your skills further with Power BI Training by Data Bear





