
A compliance lead at a mid-size firm already pays for Microsoft 365 E5. Purview is in the admin centre, already licensed. The question that follows is reasonable: if we have Purview, what is left to cover?
The useful answer comes from Microsoft’s own architecture. Purview splits communication risk across two controls that work at different moments, and the split leaves one specific gap. Understanding where that gap sits is more useful than any comparison table, so this piece starts there.
Data Loss Prevention runs before the message goes. DLP evaluates content while a message is being composed and can display a policy tip above the recipients. Configured as a dialog, it interrupts the send. Configured as a block rule, it stops the message outright. This is a genuine pre-send control and it works.
What DLP evaluates is patterns: sensitive information types, sensitivity labels, structured identifiers such as card numbers and national ID formats. It is built to recognise a category of data.
Communication Compliance runs after the message goes. It checks internal and external communications against policies, and when a policy match threshold is reached it raises an alert to a designated reviewer. The reviewer investigates, and in Teams they can remove a flagged message from view. It covers the nuanced material that pattern matching misses.
Microsoft’s own guidance describes the division plainly: use DLP to block obvious policy violations in real time, and use Communication Compliance to review the more nuanced or contextual issues that slip past DLP.
Read those two sentences together and the shape of the gap appears.
The control that acts before the send understands patterns. The control that understands context acts after the send. Contextual risk, which is where most language exposure lives, is handled as review rather than prevention.
That is a design decision, and for most of what Purview covers it is the right one. Insider risk detection, conduct monitoring, and supervisory review are review functions by nature. You cannot pre-empt a pattern of behaviour; you observe it and act.
The difficulty arrives with a specific class of obligation where the sending itself completes the breach. For those, a review queue documents what happened. It cannot undo it.
Tipping off. Under the UK Proceeds of Crime Act and the EU anti-money-laundering framework, disclosing that a suspicious activity report has been made, or that an investigation is under way, is a criminal offence. The moment the sentence reaches the customer, the offence is complete. Finding it in a review queue the next morning produces evidence of the breach and a disclosure obligation, which is a worse position than not having sent it.
Confidentiality and NDA scope. Whether a sentence is a breach depends on who is receiving it. The same paragraph sent to a counterparty under NDA is routine, and sent to a contact outside that agreement is a disclosure. Once it has gone, the information has gone. This one has a second problem: the recipient’s NDA status is organisation-specific relational data that lives in your contract files, and no general-purpose scanner has it.
Unlawful disclosure of inside information. Article 14 of the Market Abuse Regulation prohibits disclosing inside information outside the normal exercise of employment, with no trade and no profit required. As with tipping off, the message is the act. We covered a recent case where two individuals were fined a combined six figures, and the offence was complete the moment the information was passed on.
These three share a structure: the harm is done on arrival, and everything after that is documentation.
The confidentiality case above deserves more than a line, because it exposes a limit that no amount of tuning reaches.
Deciding whether a sentence is safe requires two facts: what the sentence says, and what obligation exists between your organisation and the person receiving it. The first fact is in the message. The second is in your contract files.
Purview scopes policies by domain, by group, and by internal or external status. Those are tenant facts, and they are the right facts for most of what Purview does. Whether a specific counterparty signed a mutual NDA in March, and what categories that agreement protects, is not a tenant fact. It lives in a contracts folder, a CLM system, or somebody’s inbox.
The practical consequence is that a general-purpose scanner treats every external recipient the same way. It either flags confidential-looking content to everyone outside the tenant, which trains people to dismiss the warning, or it flags nobody, which catches nothing. Neither setting distinguishes the counterparty who signed from the contact who did not, because the information required to make that distinction was never available to it.
Separately from timing, there is a category question. A DLP rule can identify a card number with high precision. Consider what it does with these:
None of these contains a pattern. Each carries real exposure: a financial promotion that is not fair, clear and not misleading; a commitment that reads as contractual; a confidentiality breach; a tipping-off risk. The risk is carried by meaning, and by who the recipient is.
Nothing here argues for replacing Purview. Retention, eDiscovery, legal hold, classification and supervisory review are Purview’s job, they are required, and a pre-send check does none of them.
The layer that fits in front is narrow by design. It reads the draft as it is written, judges meaning instead of patterns, knows which recipients are covered by which agreement, and shows the writer a safer phrasing before the message goes. What reaches Purview afterwards is a cleaner stream, which reduces the review load rather than adding to it.
| Purview DLP | Purview Communication Compliance | Pre-send language check | |
|---|---|---|---|
| When it acts | Before send | After send | Before send |
| What it reads | Patterns and labels | Context and conduct | Context and phrasing |
| Recipient-aware | By domain and group | By policy scope | By agreement signed |
| Who sees the result | The writer | A reviewer | The writer |
| Primary purpose | Prevent data loss | Supervise and investigate | Correct the sentence |
Take a month of Communication Compliance alerts and sort them into two piles. In the first, alerts where knowing afterwards was sufficient: a tone issue to coach, a pattern to watch, a conversation to have. In the second, alerts where the message reaching its recipient was itself the problem.
The first pile is Purview working as designed. The second pile is the measure of your gap, and if it is not empty, no amount of tuning the review policy will change that. Those alerts are telling you about a control that needs to sit earlier.
Purview’s split between a pattern-based pre-send control and a context-aware post-send control is documented and deliberate. The gap it leaves is contextual risk before sending, and that gap matters most for obligations where the send completes the breach. Run the two-pile test on last month’s alerts. If the second pile has anything in it, the answer is a layer in front of Purview rather than a replacement for it, and our pre-send check is built for that position.
See how VerbaPulse flags risk before an email is sent, right inside Gmail and Outlook.
See VerbaPulse in action →