
Copying from the Outlook app to WhatsApp takes one second and moves sensitive data outside every DLP boundary. Microsoft has announced that Purview DLP will evaluate clipboard content inside Intune MAM-protected apps — content-aware, not all-or-nothing. What changes, what are the requirements, and how do you prepare?
Mobile devices are the blind spot in many DLP strategies. Organisations define extensive policies for email, SharePoint, and Windows endpoints, but as soon as an employee opens company data on their phone, the options are limited. Copying from the Outlook Mobile app to WhatsApp, from SharePoint Mobile to a personal note-taking app — it takes a single second and moves confidential data outside the managed boundary. In July 2026, Microsoft published a roadmap item that structurally closes this blind spot: Purview DLP evaluation of clipboard actions inside Intune MAM-protected apps.
This is not an incremental improvement to an existing setting. It is a fundamentally different approach to mobile data protection, shifting the question from 'is the user allowed to copy?' to 'what does the content being copied contain?'.
Intune App Protection Policies, known as APP, have long provided control over data movements in managed apps. One of those controls is the clipboard setting. Administrators can configure whether users are allowed to copy from a MAM-managed app to an unmanaged app, whether this is only permitted between managed apps, or whether it is fully blocked.
This works well if you want a sharp binary choice. But in practice, the situation is more nuanced. An employee wants to copy a customer name from Outlook Mobile to their own notes app — a completely legitimate action. Another employee copies an account number or personal detail from a business document to a personal messaging app — a serious data leak. With the current APP clipboard setting, you cannot tell the difference: you block everything or you allow everything. That makes the tool too blunt for any environment where employees regularly and legitimately move text between apps.
The new feature connects the Purview DLP engine to the Intune MAM layer. When a user performs a copy action from a MAM-protected app, Purview DLP evaluates the clipboard content before pasting is permitted. If the copied text contains a sensitive information type defined in your DLP policy, such as a social security number, IBAN, credit card number, or medical code, the action can be blocked or logged based on your policy settings.
This is the same principle as Endpoint DLP on Windows, which has been available for laptops and desktops for several years. The new feature extends that protection to mobile devices, including devices managed via MAM without full MDM enrolment. For organisations with a BYOD policy, that is a significant distinction: you do not need full control over the device to achieve content-aware data protection on the clipboard.
Consider a concrete scenario. An employee opens SharePoint Mobile on their personal phone, which is managed via Intune MAM but not enrolled. They open a customer file, select a paragraph containing personal data, and copy it to the clipboard. Without DLP on the clipboard, they can paste this text into any app, including a personal messaging app or personal cloud storage. With the new feature, Purview DLP evaluates the copied content against sensitive info types. If personal data or other sensitive categories are detected, pasting into unmanaged apps is blocked.
For the employee, the experience is similar to what Endpoint DLP already does on Windows: normal copy actions without sensitive content work as usual. Only copying specifically sensitive information is intercepted. Administrators can choose between silent logging, a visible notification to the user, or direct blocking. Every action can be recorded in Purview Activity Explorer for audit and compliance purposes.
Three profiles where this feature adds the most value. First, organisations with a BYOD policy. When employees use business apps on personal phones, full MDM enrolment is often legally and practically unfeasible. Via Intune MAM you can still apply protection at the app layer. The new clipboard DLP extends that protection to the content layer, without needing to control the device.
Second, organisations in regulated sectors such as financial services, healthcare, and legal. In those environments, personal data and confidential client information are available in apps like Teams Mobile, Outlook Mobile, and SharePoint Mobile. The likelihood of an employee inadvertently leaking sensitive information via the clipboard is real and the resulting damage significant.
Third, organisations already actively using Purview DLP for email and endpoints. The DLP policies with sensitive info types you have already defined will be reused for the mobile clipboard. You do not write separate rules — you extend the scope of existing policies.
The feature requires Microsoft 365 E5 or an equivalent compliance add-on, plus Intune Plan 1. For organisations already on E5, there are no additional licence costs. Organisations on E3 or Business plans will need a Microsoft Purview Compliance add-on or a licence upgrade to use this functionality.
Configuration is done through the Microsoft Purview Compliance Center, in the same DLP policy menu where you also configure Endpoint DLP. Under the locations of a DLP policy, you add the scope 'Intune-protected apps', together with the sensitive information types you want to monitor on mobile devices. Administrators familiar with the Purview DLP interface will immediately recognise the configuration logic.
Preview is scheduled for September 2026, with general availability in November 2026. The period until the preview is the time to review your DLP policies for completeness and determine which sensitive info types on mobile deserve the highest priority.
Three concrete steps for IT teams and compliance officers. First, inventory and validate your existing Purview DLP policies. Which sensitive information types are already defined for email and Windows endpoints? Check that policies are up to date, cover the right categories, and align well with your risk analysis. Those policies will form the basis for clipboard DLP on mobile.
Second, review your Intune MAM configuration. Which apps are managed via App Protection Policies? These are the apps to which clipboard DLP will apply. Use this as an audit moment to also evaluate other APP settings, such as data movements between apps and storage locations. Closing gaps now is more efficient than correcting them later.
Third, design a pilot for the preview phase. Select a group of employees in a BYOD scenario, configure DLP policies for a limited set of sensitive info types, and choose audit mode rather than immediate blocking. This builds insight into the volume of clipboard actions involving sensitive data, providing valuable input for your risk analysis and communication plan towards employees.
Want support setting up Purview DLP for mobile devices, reviewing your Intune MAM policies, or preparing a compliance strategy for BYOD? Contact Zarioh for a no-obligation conversation.
Zarioh Digital Solutions
IT specialists from Utrecht, the Netherlands. We help businesses with Microsoft 365, AI agents, hosting and telephony — and share what we learn in practice. Follow us on LinkedIn

Security

Security

Security