Data protection controls are often most effective when they are both easy to deploy and difficult to bypass. Recent Microsoft Purview announcements focus on both sides of that equation, removing some long-standing deployment and licensing requirements while expanding protection coverage in areas that were previously out of scope.
In this post, we'll look at three updates affecting browser-based protections, network data security, and Endpoint DLP, all aimed at making data protection capabilities simpler to adopt and more comprehensive in practice.
Edge for Business DLP protections no longer require pay-as-you-go
Security controls are easier to adopt when administrative and licensing requirements are kept to a minimum. Microsoft is removing the pay-as-you-go (PAYG) requirement for Microsoft Purview collection policies and Data Loss Prevention (DLP) policies that protect supported interactions with unmanaged cloud applications in Microsoft Edge for Business.
The change removes the Azure billing subscription requirement previously associated with this scenario. Existing collection and DLP policies will continue to work without modification, and policy enforcement remains unchanged.
This is a licensing and administration change rather than an expansion of functionality. Supported applications, browsers, devices, and protection capabilities remain the same. Organizations already using these controls will continue to receive the same protections without incurring charges through the In Transit Protection meter.
The result is a simpler deployment process for browser-based data protection in Microsoft Edge for Business.
Rollout is expected to begin in mid-October 2026 and complete by late October 2026. As always, Microsoft timelines may change.
More information:
- Collection policies reference
- Learn about DLP for cloud apps in Edge for Business
- Learn about Microsoft Purview billing models
- Microsoft Purview service description and licensing guidance
Network data security policies no longer require pay-as-you-go configuration
Microsoft Purview network data security policies help discover and protect sensitive information shared with unmanaged cloud apps, websites, and AI services. Microsoft is now removing the pay-as-you-go (PAYG) requirement needed to create and manage these policies.
Coverage extends across browsers, applications, add-ins, APIs, and other channels where data may leave the organization.
For customers using Microsoft Entra Global Secure Access Internet Access with the required licensing, these protections can now be deployed without a PAYG subscription. Existing network-based Purview policies will continue to function without interruption.
The change does not apply to every integration scenario. Policies can still be created for supported third-party SASE and secure browser partners, but those integrations will not function until PAYG has been configured.
For organizations using Microsoft's own security stack, the change removes another licensing dependency from network-based DLP deployments.
Rollout is expected to begin in late September 2026 and complete by late October 2026. As always, Microsoft timelines may change.
More information:
- Learn about Microsoft Purview Network Data Security
- Protect sensitive data in SaaS and AI applications with Purview and Entra
- How to configure content filtering in Entra Global Secure Access
Endpoint DLP expands protection to previously excluded Windows folders
Sensitive files do not always remain in approved storage locations. Temporary folders and user-writable directories such as AppData can often become part of everyday workflows, creating potential blind spots for data protection policies.
Microsoft Purview Endpoint DLP is closing part of that gap by extending protection to files stored in commonly excluded Windows folders. Previously, files located in these paths were outside Endpoint DLP policy enforcement. With this update, policy checks can be applied when users attempt actions such as copying files, printing, saving to network shares, or uploading content to cloud services.
The change expands protection coverage rather than introducing new enforcement actions. Users operating under audit-mode policies can continue their activities while actions are logged, whereas block-mode policies can prevent restricted actions involving sensitive files. Where both modes apply, block enforcement takes precedence.
Unlike the previous two announcements, this update focuses on expanding protection coverage. Organizations using Endpoint DLP should review whether locations such as AppData or temporary directories contain sensitive files that should be brought under policy enforcement.
Microsoft recommends starting with audit mode before enabling enforcement actions. Administrators should also verify that devices are running Microsoft Defender anti-malware client version 4.18.26051 or later, which is required for the feature.
Rollout is expected to begin in mid-December 2026 and complete by the end of December 2026. This timeline was previously scheduled for September 2026 and was later updated by Microsoft. As always, Microsoft timelines may change.
More information:
- Microsoft 365 Roadmap item 562992:
Taken together, these announcements point in the same direction. Two of the updates remove licensing and deployment requirements that may have slowed adoption, while the third expands protection to locations that could previously fall outside policy enforcement.
None of the changes introduce entirely new protection capabilities. Instead, they focus on making existing controls easier to use, easier to deploy, and more consistent across different scenarios. For organizations already invested in Microsoft Purview, small changes like these can often have a larger operational impact than a headline-grabbing new feature.
If you'd like to stay up to date with Microsoft 365, Copilot, Teams, security, compliance, and AI-related announcements, you can follow me on LinkedIn

Comments