New Microsoft 365 DLP policies may take days to work

On 11 September 2026, Microsoft 365 for IT Pros reported that tested Microsoft Purview data loss prevention policies took days to become fully effective even after policy synchronisation appeared complete. The delay came from SharePoint and Microsoft Search processing existing sharing links and indexed email so the rules applied retrospectively, after which Activity Explorer showed hundreds of matches.
Admins are used to allowing several hours for a policy change to propagate. A completed synchronisation status can therefore look like proof that a new block is live, even while older SharePoint links or external email remain available to users and Copilot. Retrospective enforcement is valuable because it brings existing content into scope, but the background scan changes how a small admin team should validate a rollout. Policy creation, portal status and real-world enforcement are separate checkpoints, and an unexplained spike in Activity Explorer may be evidence of the backlog being processed rather than new user behaviour.
Analysis
After enabling a DLP rule, test one new item and one known historical item in each affected workload. Keep the change in observation until both enforcement and Activity Explorer evidence match the policy.
Source note
Pulse published by Collab365 Spaces, reviewed by Helen Jones on . Cite as "New Microsoft 365 DLP policies may take days to work", Collab365 Spaces.