Why your DLP policy tip didn't appear
The tip shows in Outlook on the web and nowhere else, or the mail is blocked with no explanation. The policy is usually fine. Email is checked twice, and only the first check can warn the user.
The tip and the block are different checks
You test a DLP rule in Outlook on the web and the tip appears straight away. The first person to try it on their laptop sees nothing. Or a send is blocked and the user never saw a warning at all.
The instinct is to assume the policy is broken. It rarely is. Email is checked twice. The client checks the draft as the user types, and that is the only check that can show a tip. Then the policy is evaluated again on the way out, and that is where the rule's actions apply. The second check runs whether or not the first one could.
So "did the rule apply" and "did the user see a tip" are separate questions, and when a tip goes missing it is almost always the first check that failed.
Outlook desktop has a cliff
Outlook classic and new Outlook only reach their full list of conditions when three things line up:
- An E5 licence, or one that includes the Information Protection for Office 365 Premium service plan
- Connected experiences switched on
- A recent build: 2303 (16.0.16216.10000) on current channel, or 2302 (16.0.16130.20478) on semi-annual
Miss any one and the client falls back to the E3 set: two conditions (content contains a sensitive info type, and content is shared from Microsoft 365) and about 100 built-in SITs. There is no error and no warning. An E5 user on an old build simply gets the E3 experience.
Check the build under File, Office Account, About Outlook, and read the build number rather than the year. Then check whether a device policy is turning connected experiences off.
One condition can silence a whole client
Outlook on the web accepts 23 conditions. Outlook classic accepts 16 at most, and new Outlook 14.
Put a web-only condition in the rule, such as subject or body contains words, document size, or message importance, and the desktop tip disappears for the whole rule. It does not matter that every other condition is supported.
Do not go looking for a sentence that says so. Microsoft publishes what each client supports, never what it leaves out, so the only way to spot this is to put the lists side by side. If a rule needs a web-only condition, move it into its own rule so the desktop-facing one stays inside the shorter list.
Two related traps:
Word, Excel and PowerPoint on the desktop are stricter still. They only show a tip if the entire policy stays within content contains a SIT, access scope, notify user, block everyone and incident reports. Anything else, anywhere in the policy, and the tip goes.
Someone may have moved Outlook on the web. Set-OrganizationConfig -DlpViaDcsEnabled $True makes the web client follow the new Outlook list instead of its own longer one, so a rule that used to show a tip there can stop.
Only one tip wins
Content can match several rules across several policies, but the user only sees the tip from the most restrictive rule at the highest priority. Policies in simulation mode take part in that contest. A simulation policy you forgot about can win the tip, and if nobody configured a notification on it, the user sees nothing.
Two more settings hide Purview tips while enforcement carries on:
Tips on Exchange mail flow rules. Tips come from the Exchange admin center or from Purview, never both. While any are configured on mail flow rules, every Purview tip in Outlook stays hidden.
A non-mail-enabled security group in the policy scope. Microsoft states that tips are not displayed in classic Outlook for those policies, while the rule actions are still enforced.
And the cheapest check of all: open the rule and confirm notify users is switched on, with the policy tip ticked. A block with no notification behaves exactly like a broken tip.
Outlook on phones and Macs: supported, and off
The old answer for Outlook on Mac, iOS and Android was simple: no tips. That has changed. Microsoft now documents policy tips on all three, and the oversharing dialog on Android and iOS.
The catch is that they are switched off by default, so you can test and train people first. Nothing in the DLP policy turns them on. Go to the Microsoft 365 Apps admin center, then Customization, Policy Management, and enable Enable Purview Data Loss Prevention (DLP) policy tips in Outlook. It can be targeted at groups, so start with a pilot.
Hold two things loosely. The reference page for these clients still has empty licensing and conditions sections and points back to the Outlook classic lists. It also says retention labels drive tips, which every other client page says they do not. Test before you promise either. Android and iOS do not support wait on send yet.
The Office mobile apps and the OneDrive sync client still never show a tip. For those users an email notification is the only signal you can give, because it does not depend on the client.
Describe the rule once and see which clients will actually warn the user, and what is stopping the rest.
Check your rule in the Policy Tip CheckerPlan this in a tool
Free planners to design and test this before you deploy. No login.