Create content policies for network content filtering
In brief
Discover how to configure network content filtering with Global Secure Access to enforce data protection policies for files and text content in real time.
Documentation change
Create a content policy to filter network file content
Create content policies for network content filtering
Global Secure Access supports network content filtering through content policies. This feature helps you safeguard against unintended data exposure and prevents inline data leaks to generative AI applications and internet destinations. By extending data protection capabilities to the network layer through Global Secure Access, network content filtering enables your organization to enforce data policies on network traffic in real time. You can discover and protect files shared with unsanctioned destinations, such as generative AI and unmanaged cloud apps, from managed endpoints through browsers, applications, add-ins, APIs, and more.
Global Secure Access supports network content filtering through content policies. This feature helps you safeguard against unintended data exposure and prevents inline data leaks to generative AI applications and internet destinations. By extending data protection capabilities to the network layer through Global Secure Access, network content filtering enables your organization to enforce data policies on network traffic in real time. You can discover and protect files and text content shared with unsanctioned destinations, such as generative AI and unmanaged cloud apps, from managed endpoints through browsers, applications, add-ins, APIs, and more.
The network content filtering solution brings together Microsoft Purview's data classification service and the identity-centric network security policies in Global Secure Access. This combination creates an advanced network-layer data security solution, Data Loss Prevention (DLP), that's identity-centric and policy-driven. By combining content inspection with real-time user risk evaluation, you can enforce granular controls over sensitive data movement across the network without compromising user productivity or security posture.
High-level architecture
:::image type="content" source="media/how-to-network-content-filtering/network-content-filtering-architecture.png" alt-text="Diagram showing the architecture of network content filtering with Global Secure Access and Microsoft Purview." lightbox="media/how-to-network-content-filtering/network-content-filtering-architecture.png"::: This article explains how to create a content policy to filter internet traffic flowing through Global Secure Access.
Supported scenarios
Network content filtering supports the following key scenarios and outcomes for HTTP/1.1 traffic:
- Using Basic content policy, you can block files based on supported file MIME types.
- Using the Scan with Purview action (preview) in content policy, you can audit and block files based on:
- Using the Scan with Purview action (preview) in content policy, you can audit and block selected file and text content based on:
- Microsoft Purview sensitivity labels
- Sensitive content in the file
- Sensitive content in files or text
- The user's risk level
- When you use Scan with Purview, you can generate Data Loss Prevention (DLP) admin alerts for rule matches.
Prerequisites
- A valid Microsoft Entra tenant.
- Licensing for the product. For details, see the licensing section of What is Global Secure Access. If needed, you can purchase licenses or get trial licenses.
- A valid Microsoft Entra Internet Access license.
- A valid Microsoft Purview license, required for **Scan with Purview** inspection.
- You must set up [pay-as-you-go billing](/purview/purview-billing-models#pay-as-you-go-billing-model) to use **Scan with Purview**.
- A valid Microsoft Purview license, required for **Scan with Purview** inspection.
- Network data security requires Microsoft Purview pay-as-you-go billing to be configured before you create Purview collection or DLP policies. For more information, see [Learn about Microsoft Purview billing models](/purview/purview-billing-models).
- You can use basic content policy without a Purview license.
- A user with the Global Secure Access Administrator role in Microsoft Entra ID to configure Global Secure Access settings.
- A Conditional Access Administrator role to configure Conditional Access policies.
- The Global Secure Access client requires a device (or virtual machine) that is either Microsoft Entra ID joined or Microsoft Entra ID Hybrid joined.
- A user with the Global Secure Access Administrator role in Microsoft Entra ID to configure Global Secure Access settings.
- A Conditional Access Administrator role to configure Conditional Access policies.
- The Global Secure Access client requires a device (or virtual machine) that is either Microsoft Entra ID joined or Microsoft Entra ID Hybrid joined.
- To use web categories as a content policy destination, you must also configure a web content filtering policy.
- User Datagram Protocol (UDP) traffic (that is, QUIC) isn't supported. Most websites support fallback to Transmission Control Protocol (TCP) when QUIC can't be established. For an improved user experience, you can deploy a Windows Firewall rule that blocks outbound UDP 443:
Initial configuration
To configure content policies, complete the following initial setup steps:
- Enable the Internet Access traffic forwarding profile and ensure correct user assignments.
- Enable the Internet Access traffic forwarding profile and ensure correct user assignments.
- Configure the Transport Layer Security (TLS) inspection policy.
- Install and configure the Global Secure Access client:
- Install the Global Secure Access client on Windows or macOS.
1. Select the **Global Secure Access** icon and select the Troubleshooting tab.
1. Under **Advanced Diagnostics**, select **Run tool**.
1. In the Global Secure Access Advanced Diagnostics window, select the **Forwarding Profile** tab.
1. Verify that **Internet Access** rules are present in the **Rules** section. This configuration might take up to 15 minutes to apply to clients after enabling the Internet Access traffic profile in the Microsoft Entra admin center.
1. Under **Advanced Diagnostics**, select **Run tool**.
1. In the Global Secure Access Advanced Diagnostics window, select the **Forwarding Profile** tab.
1. Verify that **Internet Access** rules are present in the **Rules** section. This configuration might take up to 15 minutes to apply to clients after enabling the Internet Access traffic profile in the Microsoft Entra admin center.
:::image type="content" source="media/how-to-network-content-filtering/internet-access-rules.png" alt-text="Screenshot of the Global Secure Access Advanced Diagnostics window on the Forwarding Profile tab, showing Internet Access rules in the Rules section." lightbox="media/how-to-network-content-filtering/internet-access-rules.png":::
Confirm access to web applications you plan for content policies.
- To use data policies configured in Microsoft Purview, select **Scan with Purview** (preview). :::image type="content" source="media/how-to-network-content-filtering/scan-with-purview.png" alt-text="Screenshot of the content rule screen with the Action menu expanded and the Scan with Purview option selected." lightbox="media/how-to-network-content-filtering/scan-with-purview.png":::- For Matching conditions, select the appropriate Activities and Content types.
- For basic content policy, select the file content types to allow or block.
- For **Scan with Purview**, select the file content types and text content types that you want Microsoft Purview to inspect. File content type selection is optional for text-only scenarios.
:::image type="content" source="media/how-to-network-content-filtering/content-rule-content-types.png" alt-text="Screenshot of the Add Content Rule page showing the Matching conditions section with Activities set to Upload, and the Content types dropdown expanded with PDF selected." lightbox="media/how-to-network-content-filtering/content-rule-content-types.png":::
1. Select **+ Add destination** and configure the destinations.
- For application-specific control, you can add the exact upload URLs and related FQDNs that the app uses. Use browser developer tools or network traffic analysis to identify the endpoints used during file upload.
- For application-specific control, you can add the exact URLs and related FQDNs that the app uses. Use browser developer tools or network traffic analysis to identify the endpoints used during file upload, text submission, or other protected traffic.
- You can also select web categories as a destination. If you select web categories, you must also configure a [web content filtering policy](how-to-configure-web-content-filtering.md).
- Select Next.
- On the Review tab, review your settings.
- Select Create to create the policy.
Link the content policy to a security profile
- Select the security profile you want to modify.
- Switch to the Link policies view.
- Configure the link content policy:
1. Select **+ Link a policy** > **Existing Content policy**.
1. From the **Policy name** menu, select the content policy you created.
1. Keep the default values for **Position** and **State**.
1. Select **Add**.
1. Select **+ Link a policy** > **Existing Content policy**.
1. From the **Policy name** menu, select the content policy you created.
1. Keep the default values for **Position** and **State**.
1. Select **Add**.
- Close the security profile.
Configure a Conditional Access policy
- Under Session, select Use Global Secure Access Security Profile and select the security profile you created.
- To create the policy, select Create.
For more information, see Create and link a Conditional Access policy.
For more information, see Create and link a Conditional Access policy.
The content policy is successfully configured.
Configure a Purview DLP policy for network data security
If you selected the Scan with Purview action in your content policy, you must configure a corresponding data loss prevention (DLP) policy in Microsoft Purview. The DLP policy defines how Purview classifies and acts on files that Global Secure Access routes for inspection.
If you selected the Scan with Purview action in your content policy, you must configure a corresponding data loss prevention (DLP) policy in Microsoft Purview. The DLP policy defines how Purview classifies and acts on file and text content that Global Secure Access routes for inspection.
Prerequisites for Purview integration
- Microsoft Purview pay-as-you-go billing configured for your tenant. For network data security DLP scenarios, the pay-as-you-go subscription is all you need. If you use other DLP functionality, per-seat licensing is required. For more information, see Learn about Microsoft Purview billing models.
- Microsoft Purview pay-as-you-go billing configured for your tenant. You must configure pay-as-you-go billing before you set up Microsoft Purview collection or DLP policies for network data security. For more information, see Learn about Microsoft Purview billing models.
For detailed steps on SASE provider integration, see Use Network Data Security to help prevent sharing sensitive information with unmanaged AI -- SASE provider integration.
If you don't see Data loss prevention in Microsoft Purview, your account might not have the required permissions or your tenant might not have the required licensing. You need a role such as DLP Compliance Management or Information Protection Admin, and a Microsoft 365 E5/A5 subscription or a Microsoft Purview DLP add-on. For more information, see Permissions in the Microsoft Purview portal.
Create a DLP policy for network data security
1. On the **Adaptive app scopes** tab, choose the app categories you want to protect against (for example, **All unmanaged AI apps**).
1. Select **Add**.
- Select Next.
- On the Choose where to enforce the policy page, ensure Network is enabled, then select Next. You can only select Network when pay-as-you-go billing is set up. For more information, see Learn about Microsoft Purview billing models.
- On the Choose where to enforce the policy page, ensure Network and non-Microsoft secure browsers is enabled, then select Next. You can only select network enforcement when pay-as-you-go billing is set up. For more information, see Learn about Microsoft Purview billing models.
- Select Create or customize advanced DLP rules and select Next.
- Select + Create rule and configure the rule:
- Enter a Name and optional description.
- Under Conditions, select + Add condition > Content contains.
- Add the sensitive information types or sensitivity labels that match your organization's data protection requirements.
- Under Actions, select + Add an action > Restrict browser and network activities.
1. Select **File uploaded to or shared with cloud or AI apps** and set the action to **Audit** or **Block** as appropriate.
1. Select the actions that match your content policy scenario and set each action to **Audit** or **Block** as appropriate:
- **Text sent to or shared with cloud or AI apps**
- **Text received from cloud or AI apps**
- **File uploaded to or shared with cloud or AI apps**
- **File downloaded from cloud or AI apps**
1. Configure **Incident reports** and alert settings as needed.
1. Select **Save**.
- Review the rule, ensure its status is On, and select Next.
- Select Next, review the policy, and select Submit.
For a detailed walkthrough with example configurations, see Use Network Data Security to help prevent sharing sensitive information with unmanaged AI.
Test the content policy
Test the configuration by attempting to upload or download files that match the content policy conditions. Verify that the policy settings block or allow the actions.
Test the configuration by attempting to upload or download files, or send text content, that matches the content policy conditions. Verify that the policy settings audit or block the actions.
Example: Block sensitive text sent through Gmail
This example walks through an end-to-end test scenario that blocks text containing sensitive data, such as credit card numbers or Social Security numbers, from being sent in a Gmail message body.
Step 1: Configure the content policy destination
When you create or edit your content policy rule, configure the following settings:
- Action: Select Scan with Purview (preview).
- Activities: Select Upload.
- Text content types: Select the text content types that you want Microsoft Purview to inspect.
- Destination: Add
mail.google.comas an FQDN.
For text-only scenarios, you don't need to select a file content type.
Step 2: Configure a Purview DLP policy
If you select Scan with Purview as the content policy action, you must also configure a corresponding Microsoft Purview DLP policy to inspect the text content and make the audit or block decision.
- In the Microsoft Purview portal, create an Inline web traffic DLP policy.
- On the Choose where to enforce the policy page, ensure Network and non-Microsoft secure browsers is enabled.
- Configure the DLP rule to detect the sensitive information types you want to block, such as credit card numbers or Social Security numbers.
- Under Actions, select Restrict browser and network activities.
- Select Text sent to or shared with cloud or AI apps and set the action to Block.
- Configure incident reports and alert settings as needed.
- Save and apply the policy.
Step 3: Validate the policy
- On a managed device with the Global Secure Access client installed, open a browser and go to Gmail.
- Create a message that contains sensitive data, such as sample credit card numbers or Social Security numbers.
- Attempt to send the message.
- Verify that the message is blocked.
- To confirm the block, check the traffic logs in the Microsoft Entra admin center under Global Secure Access > Monitor > Traffic logs.
- Review the corresponding alert or activity details in Microsoft Purview.
Example: Block sensitive PDF uploads to ChatGPT
https://chatgpt.com/backend-api/files/process_upload_stream(add as URL)*.oaiusercontent.com(add as FQDN)
For Content types, select PDF (and other file types you want to inspect).
For Content types, select PDF and other file types you want to inspect.
Step 2: Configure a Purview DLP policy (for Scan with Purview action)
If you select Scan with Purview as the content policy action, you must also configure a corresponding Microsoft Purview DLP policy to inspect the file content and make the allow or deny decision.
If you select Scan with Purview as the content policy action, you must also configure a corresponding Microsoft Purview DLP policy to inspect the file content and make the audit or block decision.
- In the Microsoft Purview portal.
- Sign in to the Microsoft Purview portal.
- Follow the steps in Use Network Data Security to help prevent sharing sensitive information with unmanaged AI to create a new DLP policy.
- In the Cloud apps step, search for and add ChatGPT.
- Configure the DLP rule to detect the sensitive information types you want to block (for example, credit card numbers or Social Security numbers).
For more information about Purview DLP policies for network traffic, see Learn about Microsoft Purview Network Data Security.
Step 3: Validate the policy
Known limitations
- Network content filtering doesn't support text. It only supports files.
- Basic content policy doesn't inspect text. Text content type inspection requires Scan with Purview and a matching Purview DLP policy.
- Network content filtering doesn't support User Datagram Protocol (UDP) traffic, including QUIC.
- Compressed content is detected in ZIP format. The content isn't decompressed.
- True file type detection might not be 100% accurate.
- Destination applications that use WebSocket, such as Copilot, aren't supported.
- Top level and second level domains don't support wildcards (like
*,*.com,*contoso.com) while configuring FQDNs.
- Top-level and second-level domains don't support wildcards (like
*,*.com,*contoso.com) while configuring FQDNs. - Microsoft Purview network data security policies don't apply to B2B guest users.
Monitoring and logging
diff --git a/docs/global-secure-access/how-to-network-content-filtering.md b/docs/global-secure-access/how-to-network-content-filtering.md
index e19b1d49c1e..46927e52b30 100644
--- a/docs/global-secure-access/how-to-network-content-filtering.md
+++ b/docs/global-secure-access/how-to-network-content-filtering.md
@@ -1,8 +1,8 @@
---
title: Create content policies for network content filtering
-description: "Discover how to configure network content filtering with Global Secure Access to enforce data protection policies and secure sensitive files in real time."
+description: "Discover how to configure network content filtering with Global Secure Access to enforce data protection policies for files and text content in real time."
ms.topic: how-to
-ms.date: 04/18/2026
+ms.date: 06/30/2026
ms.reviewer: buzaher,shkhalid
ms.custom: sfi-image-nochange
ai-usage: ai-assisted
@@ -11,14 +11,14 @@ ai-usage: ai-assisted
---
-# Create a content policy to filter network file content
+# Create content policies for network content filtering
-Global Secure Access supports network content filtering through content policies. This feature helps you safeguard against unintended data exposure and prevents inline data leaks to generative AI applications and internet destinations. By extending data protection capabilities to the network layer through Global Secure Access, network content filtering enables your organization to enforce data policies on network traffic in real time. You can discover and protect files shared with unsanctioned destinations, such as generative AI and unmanaged cloud apps, from managed endpoints through browsers, applications, add-ins, APIs, and more.
+Global Secure Access supports network content filtering through content policies. This feature helps you safeguard against unintended data exposure and prevents inline data leaks to generative AI applications and internet destinations. By extending data protection capabilities to the network layer through Global Secure Access, network content filtering enables your organization to enforce data policies on network traffic in real time. You can discover and protect files and text content shared with unsanctioned destinations, such as generative AI and unmanaged cloud apps, from managed endpoints through browsers, applications, add-ins, APIs, and more.
The network content filtering solution brings together Microsoft Purview's data classification service and the identity-centric network security policies in Global Secure Access. This combination creates an advanced network-layer data security solution, Data Loss Prevention (DLP), that's identity-centric and policy-driven. By combining content inspection with real-time user risk evaluation, you can enforce granular controls over sensitive data movement across the network without compromising user productivity or security posture.
> [!NOTE]
-> Basic content policy (block or allow by file MIME type) is generally available. The **Scan with Purview** action in content policies is currently in preview. This information relates to a prerelease product that might be substantially modified before release. Microsoft makes no warranties, expressed or implied, with respect to the information provided here.
+> Basic content policy (block or allow by file MIME type) is generally available. The **Scan with Purview** action in content policies is currently in preview and supports inspection for selected file and text content types. This information relates to a prerelease product that might be substantially modified before release. Microsoft makes no warranties, expressed or implied, with respect to the information provided here.
### High-level architecture
:::image type="content" source="media/how-to-network-content-filtering/network-content-filtering-architecture.png" alt-text="Diagram showing the architecture of network content filtering with Global Secure Access and Microsoft Purview." lightbox="media/how-to-network-content-filtering/network-content-filtering-architecture.png":::
@@ -26,20 +26,20 @@ The network content filtering solution brings together Microsoft Purview's data
This article explains how to create a content policy to filter internet traffic flowing through Global Secure Access.
> [!NOTE]
-> Basic content policy detects the file MIME type and enforces the **Allow** or **Block** action in Global Secure Access. Microsoft Purview is only involved when you choose **Scan with Purview**.
+> Basic content policy detects the file MIME type and enforces the **Allow** or **Block** action in Global Secure Access. Microsoft Purview is only involved when you choose **Scan with Purview**. Text content type inspection requires **Scan with Purview** and a corresponding Microsoft Purview DLP policy.
## Supported scenarios
Network content filtering supports the following key scenarios and outcomes for HTTP/1.1 traffic:
- Using **Basic content policy**, you can block files based on supported file MIME types.
-- Using the **Scan with Purview** action (preview) in content policy, you can audit and block files based on:
+- Using the **Scan with Purview** action (preview) in content policy, you can audit and block selected file and text content based on:
- Microsoft Purview sensitivity labels
- - Sensitive content in the file
+ - Sensitive content in files or text
- The user's risk level
- When you use **Scan with Purview**, you can generate Data Loss Prevention (DLP) admin alerts for rule matches.
> [!IMPORTANT]
-> Network content filtering supports only files over HTTP/1.1. It doesn't support network content filtering for text.
+> Basic content policy doesn't inspect text. To inspect text sent to or received from cloud or AI apps, use **Scan with Purview** and configure the matching text activities in Microsoft Purview.
## Prerequisites
@@ -47,12 +47,12 @@ To use the content policy feature, you need the following prerequisites:
- A valid Microsoft Entra tenant.
- Licensing for the product. For details, see the licensing section of [What is Global Secure Access](overview-what-is-global-secure-access.md). If needed, you can [purchase licenses or get trial licenses](https://aka.ms/azureadlicense).
- A valid Microsoft Entra Internet Access license.
- - A valid Microsoft Purview license, required for **Scan with Purview** inspection.
- - You must set up [pay-as-you-go billing](/purview/purview-billing-models#pay-as-you-go-billing-model) to use **Scan with Purview**.
+ - A valid Microsoft Purview license, required for **Scan with Purview** inspection.
+ - Network data security requires Microsoft Purview pay-as-you-go billing to be configured before you create Purview collection or DLP policies. For more information, see [Learn about Microsoft Purview billing models](/purview/purview-billing-models).
- You can use basic content policy without a Purview license.
-- A user with the [Global Secure Access Administrator](../identity/role-based-access-control/permissions-reference.md#global-secure-access-administrator) role in Microsoft Entra ID to configure Global Secure Access settings.
-- A [Conditional Access Administrator](../identity/role-based-access-control/permissions-reference.md#conditional-access-administrator) role to configure Conditional Access policies.
-- The Global Secure Access client requires a device (or virtual machine) that is either Microsoft Entra ID joined or Microsoft Entra ID Hybrid joined.
+- A user with the [Global Secure Access Administrator](../identity/role-based-access-control/permissions-reference.md#global-secure-access-administrator) role in Microsoft Entra ID to configure Global Secure Access settings.
+- A [Conditional Access Administrator](../identity/role-based-access-control/permissions-reference.md#conditional-access-administrator) role to configure Conditional Access policies.
+- The Global Secure Access client requires a device (or virtual machine) that is either Microsoft Entra ID joined or Microsoft Entra ID Hybrid joined.
- To use **web categories** as a content policy destination, you must also configure a [web content filtering policy](how-to-configure-web-content-filtering.md).
- User Datagram Protocol (UDP) traffic (that is, QUIC) isn't supported. Most websites support fallback to Transmission Control Protocol (TCP) when QUIC can't be established. For an improved user experience, you can deploy a Windows Firewall rule that blocks outbound UDP 443:
@@ -63,16 +63,16 @@ To use the content policy feature, you need the following prerequisites:
## Initial configuration
To configure content policies, complete the following initial setup steps:
-1. [Enable the Internet Access traffic forwarding profile](how-to-manage-internet-access-profile.md#enable-the-internet-access-traffic-forwarding-profile) and ensure correct user assignments.
+1. [Enable the Internet Access traffic forwarding profile](how-to-manage-internet-access-profile.md#enable-the-internet-access-traffic-forwarding-profile) and ensure correct user assignments.
1. [Configure the Transport Layer Security (TLS) inspection](how-to-transport-layer-security.md) policy.
1. Install and configure the Global Secure Access client:
1. Install the Global Secure Access client on Windows or macOS.
> [!IMPORTANT]
> Before you continue, test and ensure your client's internet traffic is routed through Global Secure Access. To verify the client configuration, see the steps in the following section.
1. Select the **Global Secure Access** icon and select the Troubleshooting tab.
- 1. Under **Advanced Diagnostics**, select **Run tool**.
- 1. In the Global Secure Access Advanced Diagnostics window, select the **Forwarding Profile** tab.
- 1. Verify that **Internet Access** rules are present in the **Rules** section. This configuration might take up to 15 minutes to apply to clients after enabling the Internet Access traffic profile in the Microsoft Entra admin center.
+ 1. Under **Advanced Diagnostics**, select **Run tool**.
+ 1. In the Global Secure Access Advanced Diagnostics window, select the **Forwarding Profile** tab.
+ 1. Verify that **Internet Access** rules are present in the **Rules** section. This configuration might take up to 15 minutes to apply to clients after enabling the Internet Access traffic profile in the Microsoft Entra admin center.
:::image type="content" source="media/how-to-network-content-filtering/internet-access-rules.png" alt-text="Screenshot of the Global Secure Access Advanced Diagnostics window on the Forwarding Profile tab, showing Internet Access rules in the Rules section." lightbox="media/how-to-network-content-filtering/internet-access-rules.png":::
1. Confirm access to web applications you plan for content policies.
@@ -102,9 +102,11 @@ To configure a content policy in Global Secure Access, complete the following st
- To use data policies configured in Microsoft Purview, select **Scan with Purview** (preview).
:::image type="content" source="media/how-to-network-content-filtering/scan-with-purview.png" alt-text="Screenshot of the content rule screen with the Action menu expanded and the Scan with Purview option selected." lightbox="media/how-to-network-content-filtering/scan-with-purview.png":::
1. For **Matching conditions**, select the appropriate **Activities** and **Content types**.
+ - For basic content policy, select the file content types to allow or block.
+ - For **Scan with Purview**, select the file content types and text content types that you want Microsoft Purview to inspect. File content type selection is optional for text-only scenarios.
:::image type="content" source="media/how-to-network-content-filtering/content-rule-content-types.png" alt-text="Screenshot of the Add Content Rule page showing the Matching conditions section with Activities set to Upload, and the Content types dropdown expanded with PDF selected." lightbox="media/how-to-network-content-filtering/content-rule-content-types.png":::
1. Select **+ Add destination** and configure the destinations.
- - For application-specific control, you can add the exact upload URLs and related FQDNs that the app uses. Use browser developer tools or network traffic analysis to identify the endpoints used during file upload.
+ - For application-specific control, you can add the exact URLs and related FQDNs that the app uses. Use browser developer tools or network traffic analysis to identify the endpoints used during file upload, text submission, or other protected traffic.
- You can also select web categories as a destination. If you select web categories, you must also configure a [web content filtering policy](how-to-configure-web-content-filtering.md).
1. Select **Next**.
1. On the **Review** tab, review your settings.
@@ -112,7 +114,7 @@ To configure a content policy in Global Secure Access, complete the following st
1. Select **Create** to create the policy.
> [!IMPORTANT]
-> If you choose the **Scan with Purview** action in a content policy rule, you must also configure a corresponding DLP policy in Microsoft Purview that targets inline web traffic. Without a matching Purview DLP policy, the content policy can't inspect file content or enforce allow or deny decisions. See [Configure a Purview DLP policy for network data security](#configure-a-purview-dlp-policy-for-network-data-security) for step-by-step guidance and [Example: Block sensitive PDF uploads to ChatGPT](#example-block-sensitive-pdf-uploads-to-chatgpt) for a concrete scenario.
+> If you choose the **Scan with Purview** action in a content policy rule, you must also configure a corresponding DLP policy in Microsoft Purview that targets inline web traffic. Without a matching Purview DLP policy, the content policy can't inspect selected file or text content or enforce audit or block decisions. See [Configure a Purview DLP policy for network data security](#configure-a-purview-dlp-policy-for-network-data-security) for step-by-step guidance and [Example: Block sensitive text sent through Gmail](#example-block-sensitive-text-sent-through-gmail) for a concrete scenario.
### Link the content policy to a security profile
@@ -120,10 +122,10 @@ To configure a content policy in Global Secure Access, complete the following st
1. Select the security profile you want to modify.
1. Switch to the **Link policies** view.
1. Configure the link content policy:
- 1. Select **+ Link a policy** > **Existing Content policy**.
- 1. From the **Policy name** menu, select the content policy you created.
- 1. Keep the default values for **Position** and **State**.
- 1. Select **Add**.
+ 1. Select **+ Link a policy** > **Existing Content policy**.
+ 1. From the **Policy name** menu, select the content policy you created.
+ 1. Keep the default values for **Position** and **State**.
+ 1. Select **Add**.
1. Close the security profile.
### Configure a Conditional Access policy
@@ -140,26 +142,24 @@ To enforce the Global Secure Access security profile, create a Conditional Acces
1. Under **Session**, select **Use Global Secure Access Security Profile** and select the security profile you created.
1. To create the policy, select **Create**.
-For more information, see [Create and link a Conditional Access policy](how-to-configure-web-content-filtering.md#create-and-link-conditional-access-policy).
+For more information, see [Create and link a Conditional Access policy](how-to-configure-web-content-filtering.md#create-and-link-conditional-access-policy).
The content policy is successfully configured.
## Configure a Purview DLP policy for network data security
-If you selected the **Scan with Purview** action in your content policy, you must configure a corresponding data loss prevention (DLP) policy in Microsoft Purview. The DLP policy defines how Purview classifies and acts on files that Global Secure Access routes for inspection.
+If you selected the **Scan with Purview** action in your content policy, you must configure a corresponding data loss prevention (DLP) policy in Microsoft Purview. The DLP policy defines how Purview classifies and acts on file and text content that Global Secure Access routes for inspection.
> [!IMPORTANT]
-> The **Scan with Purview** integration for Global Secure Access is currently in PREVIEW.
+> The **Scan with Purview** integration for Global Secure Access is currently in preview.
> This information relates to a prerelease product that might be substantially modified before release. Microsoft makes no warranties, expressed or implied, with respect to the information provided here.
### Prerequisites for Purview integration
-- Microsoft Purview pay-as-you-go billing configured for your tenant. For network data security DLP scenarios, the pay-as-you-go subscription is all you need. If you use other DLP functionality, per-seat licensing is required. For more information, see [Learn about Microsoft Purview billing models](/purview/purview-billing-models).
+- Microsoft Purview pay-as-you-go billing configured for your tenant. You must configure pay-as-you-go billing before you set up Microsoft Purview collection or DLP policies for network data security. For more information, see [Learn about Microsoft Purview billing models](/purview/purview-billing-models).
> [!NOTE]
-> If you don't see **Data loss prevention** under **Settings**, your account might not have the required permissions or your tenant might not have the required licensing. You need a role such as **DLP Compliance Management** or **Information Protection Admin**, and a Microsoft 365 E5/A5 subscription or a Microsoft Purview DLP add-on. For more information, see [Permissions in the Microsoft Purview portal](/purview/purview-permissions).
-
-For detailed steps on SASE provider integration, see [Use Network Data Security to help prevent sharing sensitive information with unmanaged AI -- SASE provider integration](/purview/dlp-create-policy-ai-network-data-security#sase-provider-integration).
+> If you don't see **Data loss prevention** in Microsoft Purview, your account might not have the required permissions or your tenant might not have the required licensing. You need a role such as **DLP Compliance Management** or **Information Protection Admin**, and a Microsoft 365 E5/A5 subscription or a Microsoft Purview DLP add-on. For more information, see [Permissions in the Microsoft Purview portal](/purview/purview-permissions).
### Create a DLP policy for network data security
@@ -174,14 +174,18 @@ For detailed steps on SASE provider integration, see [Use Network Data Security
1. On the **Adaptive app scopes** tab, choose the app categories you want to protect against (for example, **All unmanaged AI apps**).
1. Select **Add**.
1. Select **Next**.
-1. On the **Choose where to enforce the policy** page, ensure **Network** is enabled, then select **Next**. You can only select **Network** when pay-as-you-go billing is set up. For more information, see [Learn about Microsoft Purview billing models](/purview/purview-billing-models).
+1. On the **Choose where to enforce the policy** page, ensure **Network and non-Microsoft secure browsers** is enabled, then select **Next**. You can only select network enforcement when pay-as-you-go billing is set up. For more information, see [Learn about Microsoft Purview billing models](/purview/purview-billing-models).
1. Select **Create or customize advanced DLP rules** and select **Next**.
1. Select **+ Create rule** and configure the rule:
1. Enter a **Name** and optional description.
1. Under **Conditions**, select **+ Add condition** > **Content contains**.
1. Add the **sensitive information types** or **sensitivity labels** that match your organization's data protection requirements.
1. Under **Actions**, select **+ Add an action** > **Restrict browser and network activities**.
- 1. Select **File uploaded to or shared with cloud or AI apps** and set the action to **Audit** or **Block** as appropriate.
+ 1. Select the actions that match your content policy scenario and set each action to **Audit** or **Block** as appropriate:
+ - **Text sent to or shared with cloud or AI apps**
+ - **Text received from cloud or AI apps**
+ - **File uploaded to or shared with cloud or AI apps**
+ - **File downloaded from cloud or AI apps**
1. Configure **Incident reports** and alert settings as needed.
1. Select **Save**.
1. Review the rule, ensure its status is **On**, and select **Next**.
@@ -189,12 +193,48 @@ For detailed steps on SASE provider integration, see [Use Network Data Security
1. Select **Next**, review the policy, and select **Submit**.
> [!NOTE]
-> Global Secure Access supports file activities only. Text-based activities in the DLP policy apply to other integrated SASE solutions but not to Global Secure Access.
+> The actions you select in the Purview DLP rule should match the content types and activities you selected in the Global Secure Access content policy. For text inspection scenarios, include the applicable text actions in the Purview DLP rule.
For a detailed walkthrough with example configurations, see [Use Network Data Security to help prevent sharing sensitive information with unmanaged AI](/purview/dlp-create-policy-ai-network-data-security).
## Test the content policy
-Test the configuration by attempting to upload or download files that match the content policy conditions. Verify that the policy settings block or allow the actions.
+Test the configuration by attempting to upload or download files, or send text content, that matches the content policy conditions. Verify that the policy settings audit or block the actions.
+
+### Example: Block sensitive text sent through Gmail
+
+This example walks through an end-to-end test scenario that blocks text containing sensitive data, such as credit card numbers or Social Security numbers, from being sent in a Gmail message body.
+
+#### Step 1: Configure the content policy destination
+
+When you create or edit your content policy rule, configure the following settings:
+
+- **Action**: Select **Scan with Purview** (preview).
+- **Activities**: Select **Upload**.
+- **Text content types**: Select the text content types that you want Microsoft Purview to inspect.
+- **Destination**: Add `mail.google.com` as an FQDN.
+
+For text-only scenarios, you don't need to select a file content type.
+
+#### Step 2: Configure a Purview DLP policy
+
+If you select **Scan with Purview** as the content policy action, you must also configure a corresponding Microsoft Purview DLP policy to inspect the text content and make the audit or block decision.
+
+1. In the [Microsoft Purview portal](https://purview.microsoft.com), create an **Inline web traffic** DLP policy.
+1. On the **Choose where to enforce the policy** page, ensure **Network and non-Microsoft secure browsers** is enabled.
+1. Configure the DLP rule to detect the sensitive information types you want to block, such as credit card numbers or Social Security numbers.
+1. Under **Actions**, select **Restrict browser and network activities**.
+1. Select **Text sent to or shared with cloud or AI apps** and set the action to **Block**.
+1. Configure incident reports and alert settings as needed.
+1. Save and apply the policy.
+
+#### Step 3: Validate the policy
+
+1. On a managed device with the Global Secure Access client installed, open a browser and go to [Gmail](https://mail.google.com).
+1. Create a message that contains sensitive data, such as sample credit card numbers or Social Security numbers.
+1. Attempt to send the message.
+1. Verify that the message is blocked.
+1. To confirm the block, check the traffic logs in the Microsoft Entra admin center under **Global Secure Access** > **Monitor** > **Traffic logs**.
+1. Review the corresponding alert or activity details in Microsoft Purview.
### Example: Block sensitive PDF uploads to ChatGPT
@@ -208,16 +248,16 @@ When you create or edit your content policy rule, don't add only `chatgpt.com`.
- `https://chatgpt.com/backend-api/files/process_upload_stream` (add as URL)
- `*.oaiusercontent.com` (add as FQDN)
-For **Content types**, select **PDF** (and other file types you want to inspect).
+For **Content types**, select **PDF** and other file types you want to inspect.
> [!TIP]
> Web applications often use multiple URLs and FQDNs under the hood. Use browser developer tools or network traffic analysis to identify the correct upload endpoints for your target destination. For ChatGPT, the URLs listed here are the endpoints used for file upload operations.
#### Step 2: Configure a Purview DLP policy (for Scan with Purview action)
-If you select **Scan with Purview** as the content policy action, you must also configure a corresponding Microsoft Purview DLP policy to inspect the file content and make the allow or deny decision.
+If you select **Scan with Purview** as the content policy action, you must also configure a corresponding Microsoft Purview DLP policy to inspect the file content and make the audit or block decision.
-1. In the [Microsoft Purview portal](https://purview.microsoft.com).
+1. Sign in to the [Microsoft Purview portal](https://purview.microsoft.com).
1. Follow the steps in [Use Network Data Security to help prevent sharing sensitive information with unmanaged AI](/purview/dlp-create-policy-ai-network-data-security#steps-to-create-policy) to create a new DLP policy.
1. In the **Cloud apps** step, search for and add **ChatGPT**.
1. Configure the DLP rule to detect the sensitive information types you want to block (for example, credit card numbers or Social Security numbers).
@@ -226,8 +266,8 @@ If you select **Scan with Purview** as the content policy action, you must also
For more information about Purview DLP policies for network traffic, see [Learn about Microsoft Purview Network Data Security](/purview/dlp-network-data-security-learn).
-> [!Note]
-> Network DLP with Global Secure Access integration is currently in preview. Global Secure Access forwards matching upload traffic to Microsoft Purview for content inspection. Purview evaluates the content against your DLP policy and returns an allow or deny decision. Global Secure Access then enforces the result.
+> [!NOTE]
+> Network DLP with Global Secure Access integration is currently in preview. Global Secure Access forwards matching upload traffic to Microsoft Purview for content inspection. Purview evaluates the content against your DLP policy and returns a decision based on your DLP rule action. Global Secure Access then enforces the result.
#### Step 3: Validate the policy
@@ -240,11 +280,12 @@ For more information about Purview DLP policies for network traffic, see [Learn
## Known limitations
-- Network content filtering doesn't support text. It only supports files.
+- Basic content policy doesn't inspect text. Text content type inspection requires **Scan with Purview** and a matching Purview DLP policy.
+- Network content filtering doesn't support User Datagram Protocol (UDP) traffic, including QUIC.
- Compressed content is detected in ZIP format. The content isn't decompressed.
- True file type detection might not be 100% accurate.
-- Destination applications that use WebSocket, such as Copilot, aren't supported.
-- Top level and second level domains don't support wildcards (like `*`, `*.com`, `*contoso.com`) while configuring FQDNs.
+- Top-level and second-level domains don't support wildcards (like `*`, `*.com`, `*contoso.com`) while configuring FQDNs.
+- Microsoft Purview network data security policies don't apply to B2B guest users.
## Monitoring and logging
@@ -272,5 +313,5 @@ If you use **Scan with Purview**, review the corresponding investigation data in
- [Get started with the data loss prevention Alerts dashboard](/purview/dlp-alerts-dashboard-get-started)
- [Get started with activity explorer](/purview/data-classification-activity-explorer)
- [How to configure Global Secure Access web content filtering](how-to-configure-web-content-filtering.md)
-- [Enable the Internet Access traffic forwarding profile](how-to-manage-internet-access-profile.md)
+- [Enable the Internet Access traffic forwarding profile](how-to-manage-internet-access-profile.md)
- [Configure Transport Layer Security inspection](how-to-transport-layer-security.md)