Extending Microsoft Sensitivity Labels Beyond Microsoft 365
Data protection starts with knowing where sensitive information lives, but maintaining that inventory is a constant burden for security teams. Microsoft Purview Information Protection helps by letting organizations classify data with sensitivity labels like Public, Confidential, or Highly Confidential. The catch: those labels only help while traffic stays inside Microsoft's ecosystem. Once a file leaves—say, a download from OneDrive—teams lose visibility into its movement.
Cloudflare One now closes that gap. Its Data Loss Prevention (DLP) can detect Microsoft Purview Information Protection labels in corporate traffic. After integrating your Microsoft account, Cloudflare One pulls your labels automatically, and you can build rules that govern how labeled data travels to non-Microsoft destinations.
How Microsoft Labels Travel With Data
Sensitivity labels are embedded in a document's metadata, so they persist even after the file leaves Microsoft services. That means the label survives a OneDrive download, an email forward, or an upload to an external site. Cloudflare One's DLP takes advantage of this persistence: its API-driven Cloud Access Security Broker (CASB) scans SaaS applications—including Microsoft 365—for misconfigurations, shadow IT, and other post-login data security issues.
Label Sync and DLP Profiles
CASB integration doesn't stop at scanning for issues. With the new release, CASB can retrieve sensitivity labels from a connected Microsoft account. If labels exist, they are populated automatically into a DLP profile on the Cloudflare side.

DLP profiles are the foundation for DLP scanning. They define the sensitive data you want to monitor—Microsoft-labeled files, credit card numbers, or custom keywords. In this case, labels arrive as entries under a Microsoft Purview Information Protection Sensitivity Labels profile, named after your CASB integration. You can also fold those labels into custom DLP profiles when you need more flexible detection configurations.

Enforcing Movement Rules
Cloudflare One's Gateway Firewall Policies let you pair DLP profiles with traffic rules, giving you control over where labeled files can go once they leave Microsoft. Common scenarios include blocking Highly Confidential files from being downloaded from OneDrive or preventing anything more sensitive than Confidential from being uploaded to unauthorized file-sharing sites.
Deploying the rule is a matter of navigating to Gateway Firewall Policies and building entries with your DLP profiles:

Because Cloudflare One is a SASE platform with Zero Trust security built in, DLP rules apply to traffic flowing across the same infrastructure you already use for Zero Trust Network Access or Secure Web Gateway. Adding label-based data protection doesn't require a separate deployment.
Starting With DLP
To try this integration, request a consultation or reach out to your account manager.



