Courseiva

Allow Users to Override DLP Block in Teams with Business Justification

Your organization, Fabrikam Inc., uses Microsoft Purview Data Loss Prevention (DLP) to protect sensitive data in Microsoft Teams. You have a DLP policy that blocks sharing of credit card numbers in Teams messages. Recently, users have reported that they cannot share legitimate credit card numbers for business purposes, even with customers. You need to allow users to override the block for legitimate sharing, but require them to provide a business justification. What should you configure?

Quick Answer

The correct answer is to configure the DLP policy to show a policy tip that allows users to override the block with a business justification, and enable audit logging for overrides. This works because Microsoft Purview DLP policy tips in Teams can present an override option when a message is blocked, prompting the user to enter a justification before the content is sent; the override action is then recorded in the audit log for admin review. On the MS-102 exam, this scenario tests your understanding of balancing security with user productivity—a common trap is choosing to exempt entire users or groups, which bypasses per-message control and loses the audit trail. The key memory tip is “Justify and Log”: the user provides justification, and the admin reviews the log, ensuring every override is both accountable and traceable.

⚠ Common exam trap

MS-102 often tests the confusion between exempting users from a DLP policy (removing all protection) and configuring a policy tip with override (preserving protection while allowing documented exceptions) — candidates pick the exemption path thinking it is more granular when it is actually broader.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure the DLP policy to show a policy tip that allows users to override the block with a business justification, and enable audit logging for overrides.

DLP policy tips in Microsoft Teams can be configured to allow users to override a block, and the override can require a business justification that is captured in the audit log. This preserves the protective control while providing a documented exception path for legitimate business scenarios like sharing a customer's own credit card number. Enabling audit logging ensures the override and justification are recorded for compliance review.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create a second DLP policy with a lower priority that allows credit card sharing, and assign it to a security group containing authorized users.

    Why it's wrong here

    A lower-priority allow policy cannot override a higher-priority block, since DLP evaluates rules by priority and the blocking rule still matches first. It is tempting because scoping policies to a security group is a genuine way to limit enforcement, but the correct mechanism is an override action with justification inside the existing rule.

  • ✗

    Add the users to an exempt group in the DLP policy so they are not blocked.

    Why it's wrong here

    Exempting users removes them from policy evaluation entirely, so credit card sharing is unrestricted and no justification is recorded. Exempt groups suit populations that must never be governed by a policy, such as service accounts, rather than users needing case-by-case override with reason.

  • ✓

    Configure the DLP policy to show a policy tip that allows users to override the block with a business justification, and enable audit logging for overrides.

    Why this is correct

    Enabling the override with justification in the policy tip satisfies the requirement to permit legitimate sharing while capturing a reason. The policy tip appears in Teams, letting users proceed after entering a business justification, and audit logging records each override for later review and compliance reporting.

  • ✗

    Configure the DLP policy to allow overrides without justification, and monitor usage.

    Why it's wrong here

    Allowing overrides without justification removes the audit trail the requirement demands, so no business reason is captured when a user bypasses the block. Override-without-justification suits low-risk policies where friction must be minimised and no accountability record is needed.

About these practice questions

Courseiva writes every MS-102 question from scratch — 712 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

2 more ways this is tested on MS-102

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Your organization uses Microsoft Purview Data Loss Prevention (DLP) to protect sensitive data. Users report that they are unable to share files containing credit card numbers via email. You need to allow sharing with specific business partners while maintaining protection for all other recipients. What should you configure?

medium
  • ✓ A.Configure the DLP policy to allow users to override the action with a business justification.
  • B.Create a separate DLP policy with lower priority that allows sharing with the partners.
  • C.Assign a custom sensitivity label to emails sent to the partners.
  • D.Configure a file policy in Microsoft Purview Information Protection to exempt the partners.

Why A: Microsoft Purview DLP policies can be configured to allow users to override a blocking action by providing a business justification. This is useful for scenarios where legitimate sharing with business partners is needed while still blocking sharing with unauthorized recipients. The override action can be audited for compliance. Option B is incorrect because DLP policies are evaluated in priority order; a lower priority policy cannot override a higher priority policy's action. Option C is incorrect because sensitivity labels classify and protect data but do not override DLP policy actions. Option D is incorrect because file policies in Microsoft Purview Information Protection are not used for email content inspection; DLP policies are used for that purpose.

Variation 2. Your organization uses Microsoft Purview Data Loss Prevention (DLP) to protect sensitive data. You have a DLP policy that blocks sharing of documents containing personally identifiable information (PII) with external users. However, the HR department needs to share PII with a third-party benefits administrator for open enrollment. They request an exception that allows sharing only with the specific external domain 'benefits.contoso.com'. You need to implement the exception without weakening the overall policy. The solution must be centrally managed and auditable. What should you do?

medium
  • A.Create a separate DLP policy with a lower priority that allows sharing with the external domain.
  • B.Remove the HR department from the scope of the DLP policy.
  • C.Modify the sensitivity label used by HR to remove the encryption requirement.
  • ✓ D.Configure the existing DLP policy to allow override for the specific external domain by using an allow list.

Why D: You can configure an override in the existing DLP policy to allow sharing with the specific external domain 'benefits.contoso.com' by adding that domain to an allow list. This creates a centrally managed, auditable exception without weakening the overall policy. Option A is incorrect because creating a separate DLP policy with lower priority does not create an exception; all policies apply and may still block the sharing. Option B is incorrect because removing the HR department from the scope would disable all DLP protection for HR data, not just for the specific scenario. Option C is incorrect because modifying the sensitivity label affects encryption and classification, not DLP policy actions directly.

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.