Microsoft Purview limitations: What the E5 upgrade doesn’t fix
Oct 7, 2026
Most teams hit Microsoft Purview limitations after paying to remove them. The E5 upgrade buys endpoint enforcement, auto-labeling, and a year of audit retention, but it still leaves on-premises databases, Linux endpoints, non-Microsoft SaaS, and multi-year evidence outside native enforcement. Map those boundaries before the renewal, because the license tier isn’t where they close.
A March 2025 survey of 100 US security and IT decision-makers by MIND and Enterprise Strategy Group found that 94% run at least two DLP tools, and the average runs more than three.
When Microsoft-heavy mid-market teams ask why they need a second DLP tool, the usual answer is to upgrade to E5 and consolidate. However, the upgrade doesn't deliver that. The Microsoft Purview limitations that push teams toward a second tool, such as on-premises databases, Linux endpoints and non-Microsoft SaaS, sit outside what E5 changes.
Microsoft documents those boundaries across dozens of separate pages, which is why a coverage picture rarely survives contact with a licensing datasheet. Read closely enough, though, and the same shape keeps repeating.
Coverage differs by repository, endpoint class, SaaS app, and how many years of audit evidence the compliance program actually needs.
Why Purview’s limitations matter before the renewal conversation
The renewal conversation answers a narrower question than the one a security or compliance lead is actually asking, and three things follow from that mismatch.
The upgrade answers a licensing question
When a Microsoft-heavy team asks why Purview isn’t stopping something, the reflexive answer is the next license tier up. That answer isn’t wrong, since E5 does add real capability, but it treats “what does E5 include” and “what does the environment need covered” as the same question, and they aren’t. A team can accept the upgrade and pay for a year of it, yet still be exposed on the same on-premises database or the same Linux fleet it was exposed on before signing. That's because those boundaries are drawn by platform and repository, not by seat.
Upgrading isn’t the same as mapping what’s covered
The 94% of organizations running multiple DLP tools aren’t there by accident, and license tier isn’t what’s missing for most. A team that upgrades and stops asking where its regulated data actually sits trades one blind spot for another.
It stops not knowing what E5 includes, and starts assuming E5’s inclusion means enforcement. The second is harder to catch, because nothing in the tenant tells you it’s happened, and it shows up later, usually somewhere worse than a licensing review.
The blind spot surfaces during an investigation
You can map every one of those limitations before a renewal conversation starts. That means naming which repositories carry regulated data, which endpoint classes need coverage, which SaaS apps sit outside the supported list, and how many years of evidence the compliance program actually needs. Map them too late, and you may find out for the first time when an investigation needs a record Purview no longer holds.
Netwrix 1Secure™ reports on the sensitive data Copilot accesses. Request a demo.
What the E5 upgrade was built to fix
Microsoft 365 E3 and E5 are close to two different DLP products. E3 is the narrow one, covering policy creation, monitoring and protection for Exchange Online, SharePoint Online and OneDrive, plus manual sensitivity labeling and scan-and-report discovery. Everything E5 adds beyond that was purpose-built to close one specific limitation at a time, not to extend coverage generally.
Workload coverage beyond Exchange, SharePoint and OneDrive
E3’s DLP reaches Exchange, SharePoint and OneDrive and nowhere else natively. Its Teams coverage inspects only files shared through SharePoint and OneDrive, not the conversation itself. E5 extends enforcement beyond those three workloads in two directions.
Endpoint DLP for Windows and macOS puts policy on the device rather than stopping at the mail and file-sharing layer, and E5 adds chat and channel message inspection in Teams, which E3 doesn’t reach at all.
The labeling bottleneck that manual tagging can’t clear
E3 leaves sensitivity labeling manual, which works until file volume outpaces the people applying labels. E5 was built to remove that ceiling. Automatic sensitivity labeling, including trainable classifiers and Exact Data Match, lets classification run against content instead of waiting on a user to tag it. Auto-labeling isn’t included with E3 or Business Premium, and it’s the only E5 capability aimed squarely at the volume problem manual labeling can’t solve.
DLP rules with no memory across events
A DLP rule evaluates one transfer at a time and has no memory of the last one. Insider Risk Management and Adaptive Protection were built to fix that, correlating behavior across a user’s activity over time instead of scoring each event in isolation. That’s the problem an ad hoc, transfer-by-transfer policy structurally can’t see.
Traffic the endpoint agent can’t see
Two E5 capabilities carry separate costs on top of the license. Network Data Security and inline protection in Edge for Business run on Azure pay-as-you-go meters, billed apart from Microsoft 365 licensing.
Both inspect traffic the endpoint agent can’t see, which is why they sit outside the standard bill. Those meters stopped working for tenants without a linked Azure subscription after June 30, 2025, so the E5 SKU alone doesn’t enable this capability.
Both tiers still assume the regulated data sits in Microsoft’s cloud. On-premises file servers and databases use a different mechanism entirely, and E5 doesn’t cover it.
Microsoft Purview limitations
Even with every E5 capability turned on, the boundaries below sit outside what a license tier moves. They’re drawn by platform, repository or service quota instead, which is why the sales conversation and the coverage conversation keep landing in different places.
On-premises repositories rely on a scheduled crawler
Purview has exactly one mechanism for on-premises file servers, network shares and SharePoint Server: the Information Protection scanner. The scanner doesn’t discover and label content in real time. It crawls specified data stores on a schedule, so a spreadsheet of patient records copied to a departmental share is covered only after the next crawl reaches that folder.
That delay is easier to live with than the deployment itself, heavier than most teams expect and part of why many put it off. Standing it up needs a dedicated Windows Server, a SQL Server instance and an AD service account.
By default, it covers only Office and PDF (Portable Document Format) files; every other type needs PowerShell added first.
Structured data runs into a worse problem. The Data Map can catalog an on-premises SQL Server, but sensitivity labels apply only to asset metadata, never to the actual files and database columns, so nothing here gets enforced.
That's before accounting for how little data it even inspects, since classification samples only the top 128 rows in each column, or the first 1 MB, whichever is lower. No DLP enforcement reaches rows or columns, exactly where healthcare and financial services keep their most regulated records.
Endpoint coverage stops short of Linux and full macOS parity
Endpoint coverage is easy to miss before signing, because it’s drawn by operating system.
Purview has no Linux agent, and Microsoft’s own Q&A answer from February 2025 says, “Microsoft Purview’s Endpoint DLP and MIP [Microsoft Information Protection] do not support Linux devices for classification or DLP monitoring,”.
Engineering teams, research groups and manufacturing systems running Linux workstations are an endpoint population outside native enforcement entirely. The survey behind the Netwrix 2026 Data and Identity Security Report found that 69% of organizations can’t instantly and fully prevent sensitive data from leaving endpoints through external AI tools, personal email, or USB.
Windows is the one platform Purview covers fully. macOS gained ground through 2025 but still trails Windows in two ways. Purview can’t block copy-move over Remote Desktop Protocol (RDP) on a Mac, and can’t enforce just-in-time access while the Mac is offline.
Browser coverage adds a third variable. Edge enforces natively on Windows, but Chrome and Firefox need the Purview extension, and domain lists cover uploads only, never paste actions. Claude sits outside Edge for Business’s unmanaged-app list, covered instead through the preview Network Data Security described above.
Classification quality sets the ceiling on Copilot governance
Purview’s Copilot controls only work on labels already applied to the right items, so Copilot governance is only as good as the classification underneath it.
Built-in sensitive information types ship tuned for breadth, so they over-match out of the box, and since they can’t be edited directly, every tuning pass starts with copying one into a custom type.
Auto-labeling caps at 100,000 files per day per tenant, can’t replace a label a user already applied, and its trainable classifiers support English only.
The same ceiling shows up in how Purview watches Copilot. Microsoft’s own DSPM assessment reports exposure but leaves enforcement to other tools, so Copilot inherits the same blind spots, which show up directly in what it returns. Labeled items still appear in citations with only the content withheld, and DLP can’t scan a file uploaded straight into a prompt.
Even a correct fix takes time to land. A policy change takes up to four hours to reach Copilot, and until then an unlabeled file in a labeled site is still summarized in full, since it doesn’t inherit the site’s label. The same ceiling reaches oversharing remediation, where E5 tenants without SharePoint Advanced Management get no snapshot reports or remedial actions, just 28 days of activity across 10,000 sites.
Audit retention and investigation windows fall short of regulated evidence requirements
HIPAA sets a six-year documentation bar under Title 45 of the Code of Federal Regulations (CFR), section 164.316(b)(2), and Purview doesn’t clear it on the default plan. Purview Audit (Standard) keeps records for 180 days. Audit (Premium), included with E5, extends that to one year.
Longer retention requires the 10-Year Audit Log add-on, priced per user, and Microsoft doesn’t apply retention changes retroactively, so the add-on can’t produce history from before you buy it.
PCI DSS v4.0.1 requirement 10.5.1 requires 12 months of audit history, with three months immediately available. Premium clears that bar. Standard misses it.
Investigation windows run shorter than the retention tiers suggest, which matters because an investigation is exactly when that shortfall gets tested. The DLP alert dashboard and Activity Explorer each hold only 30 days, and the Defender portal holds six months.
On top of that shorter window, the count Purview displays is also an estimate, not a total. One side-by-side comparison put the Purview Audit interface at 172,951 records against the 415,406 the API returned for the same query, a discrepancy worth confirming before either number goes into an audit response.
Non-Microsoft SaaS coverage stops at visibility
Connected apps DLP is still in preview, and Slack isn’t on the supported list yet. Even where a Data Map connector does exist, it classifies without enforcing, which means visibility without protection. The one policy surface built specifically for third-party apps fares no better. Defender for Cloud Apps file policies retire January 6, 2027, landing inside a normal renewal cycle rather than safely beyond one.
Slack’s absence matters more than the supported list suggests, because non-Microsoft collaboration in a mid-market estate concentrates in one tool rather than spread across several. A team that standardized on Slack is entirely outside the supported list.
Building the internal case for complementary tooling
An internal case for a second tool needs the limitations collected in one place, with the licensing math beside them. Microsoft’s documentation supplies neither, and the hard numbers are scattered the same way the prose is:
Documented limit | What it caps | Value |
|---|---|---|
|
Files labeled per tenant per day |
||
|
Data Map classification |
Sample depth per column |
Top 128 rows, or the first 1 MB |
|
Seed samples required |
50 to 500 positive, 150 to 1,500 negative |
|
|
Distance from keyword to match |
300 characters |
|
|
Audit (Standard) |
Record retention |
180 days |
|
Audit (Premium) |
Record retention |
One year; some activities: 180 days |
|
DLP alert dashboard |
Alert history |
30 days |
|
Activity Explorer |
Activity history |
30 days |
|
Copilot policy propagation |
Time for a change to take effect |
Up to 4 hours |
|
Data access governance activity reports |
Sites returned |
10,000 |
The E5 uplift is often worth it on its own merits, but it moves only one line in the table above, audit retention, from 180 days to a year. Every other limit stays exactly where it was, because those limits are drawn by platform, repository or service quota, not by license tier.
Weighing the uplift against the add-on plus targeted tooling gives leadership a coverage-per-dollar comparison instead of a features-per-seat one, the framing the National Association of Corporate Directors (NACD) cyber risk handbook recommends for budget requests tied to quantified risk reduction.
How Netwrix helps where Purview stops
Whatever covers the remainder has three jobs. It has to reach the repositories the scanner can’t, enforce on the endpoint classes the agent doesn’t run on, and tie both back to the identities that hold access.
Netwrix is an identity-centric data security platform for mid-market organizations running Microsoft-heavy hybrid environments, and three of its products map onto those jobs.
Repositories the scanner can’t reach
Netwrix Access Analyzer discovers and classifies data the scanner can’t reach, including on-premises SQL Server and both on-premises and cloud file repositories. It resolves nested AD groups and SharePoint inheritance, so each finding carries who can open the file. It requires architecture and integration planning, so treat it as a roadmap item and budget time accordingly.
Endpoint classes the agent doesn’t run on
Netwrix Endpoint Protector applies the same policy set on Windows, macOS and Linux from one console, with Linux support reaching Red Hat Enterprise Linux (RHEL) 10.x and Ubuntu 26.04 long-term support (LTS).
At Alloy, a fintech identity-risk platform, the job was keeping Social Security numbers (SSNs), tax IDs and client records on the endpoint.
Endpoint Protector delivered that through real-time monitoring of data transfers, USB port blocking and enforced USB encryption, and Alloy’s systems engineer reports no problems since it went in.
The identity layer underneath both
Netwrix 1Secure™ adds Copilot interaction visibility, reporting on Copilot interactions and the sensitive data Copilot accesses. It doesn’t enforce or restrict Copilot behavior.
Attackers log in with valid credentials, which is why a file-level view needs identity context. Netwrix ties a file to who holds effective access across Active Directory and file servers, and Netwrix DSPM extends that discovery across hybrid repositories including on-premises file stores, databases and supported cloud storage.
The survey behind the Netwrix 2026 Data and Identity Security Report found that 73.6% of organizations can’t get a single view of where sensitive data resides and which identities can access it.
Map the boundaries before the next renewal
Before the next renewal conversation, write down four questions. Which repositories sit outside Exchange, SharePoint, OneDrive and Teams? Which endpoint classes run something other than Windows or managed macOS? Which SaaS apps outside Microsoft’s ecosystem carry regulated data, and how many years of audit evidence does the compliance program actually need, measured against what the current tier retains?
Where the answer to any of them isn’t “covered,” a second tool needs to close that boundary directly, rather than through a bigger E5 invoice.
The 94% of organizations already running two or more DLP tools, cited at the top of this piece, aren’t there because they underbought. They’re there because platforms and repositories draw these boundaries, and no license tier redraws them.
Closing the endpoint blind spots covered in this piece starts with visibility across every operating system Purview doesn’t reach.
Request a demo to see how Netwrix Endpoint Protector blocks sensitive data uploads to AI tools across endpoints and browser sessions.
Frequently asked questions about Microsoft Purview limitations
Share on
Learn More
About the author