Which DLP Policy Location Enables Endpoint Rule Actions?
You have a Microsoft 365 E5 subscription. You create a data loss prevention (DLP) policy named DLP1. You need to ensure that endpoint rule actions are available in the advanced DLP rules for DLP1. To which location should you apply DLP1?
Community Votes
100% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The question tests whether you know that endpoint DLP actions are device-agent driven, and the common trap is selecting OneDrive accounts or On-premises repositories because they sound like data locations that DLP protects.
Endpoint rule actions in Microsoft Purview advanced DLP rules only become available when the DLP policy is applied to the Devices location. This page confirms that option D (Devices) is the correct location for DLP1 so endpoint DLP capabilities can be enforced.
Choosing OneDrive accounts is the most common wrong answer, since DLP policies often target cloud storage; however, file copy, USB, and network-share actions only surface when the policy is scoped to Devices and endpoints are onboarded.
Community Discussion (5 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Endpoint DLP in Microsoft Purview is enforced by the agent installed on Windows and macOS devices, so the endpoint rule actions such as audit, block, override, and warn on copy to USB, network share, or cloud upload appear only when the policy's location is set to Devices. Applying DLP1 to Devices registers that workload in the policy scope and exposes the Endpoint DLP rule actions in the advanced rule editor. Krayzr made exactly this point, noting that endpoint DLP "controlling and monitoring sensitive data on user devices" and linking the Microsoft Learn getting-started article. Tr619899 likewise explained that the policy must be applied to Devices so the policy can "monitor and enforce rules on endpoint devices." Without the Devices location and device onboarding, the endpoint actions are simply not presented in the rule wizard.Why the Other Options Are Wrong
Instances scopes the policy to specific cloud-app instances surfaced through the Defender for Cloud Apps integration, governing files and activities in those services rather than agent-based enforcement on user endpoints. OneDrive accounts covers files stored in OneDrive for work or school in the cloud, so it offers cloud-file conditions and actions, not device actions like blocking copy to a USB drive. On-premises repositories is used with the information protection scanner to discover and classify files on file shares and SharePoint Server, which again has nothing to do with endpoint agent rule actions. Since the scenario explicitly asks for endpoint rule actions in the advanced DLP rules for DLP1, only the Devices location satisfies the requirement.Community Comment Notes
Krayzr's explanation of endpoint DLP and the Microsoft Learn reference were the most useful consensus points, and Tr619899 spelled out the same conclusion that Devices is required for endpoint enforcement. Ody felt "some relevant information is missing in the question or possibly they have changed the interface," a fair caution given how often Purview UI labels shift. Khanbaba43 admitted, "I was going to say 'one Drive accounts'... but again, I say a lotta things!" which nicely illustrates the OneDrive trap this question sets. Murad01 simply doubted that "answer provided by exam topics from ChatGPT 4.0" was reliable, a reminder to verify against Microsoft Learn rather than the source key.Official Reference
Exam Strategy
When a question mentions endpoint rule actions, on-device actions, or USB/network-share blocking, immediately look for the Devices location and remember that onboarding the device is also required. Do not be distracted by other valid DLP locations; each location only exposes the conditions and actions for that workload.
Frequently Asked Questions
Why must DLP1 be applied to Devices instead of OneDrive accounts?
Endpoint rule actions come from the DLP agent on Windows and macOS devices, not from cloud storage. OneDrive accounts only exposes file and sharing conditions for cloud files.
Do On-premises repositories ever enable endpoint rule actions?
No. That location is for the information protection scanner discovering files on file shares, so it never surfaces USB, copy, or network-share endpoint actions.
Related Analysis
Practice All MS-102 Questions
Access 111 questions with complete answers and detailed explanations.
View Full MS-102 Practice Test →