January 2026
Focus
Focus
Enterprise DLP

January 2026

Table of Contents

January 2026

Review the new features introduced to Enterprise Data Loss Prevention (E-DLP) in January 2026.

Domain Ownership Validation for Email DLP

January 16, 2025
Unvalidated sender domains create a significant security vulnerability that malicious actors can exploit to hijack your identity and perform email spoofing. If your environment allows domain addition without verification, unauthorized users might configure policies rules that compromise your organization's reputation and data security.
Domain Ownership Validation for Email DLP eliminates this risk by requiring a mandatory proof-of-control step for all sender domains when onboarding your email provider. Before you can activate a domain for forwarding or policy configuration, Enterprise DLP now verifies the email domain ownership through DNS TXT record validation. This ensures that only legitimate domain owners can add domains and manage traffic within your tenant. By enforcing strict ownership verification, you effectively prevent unauthorized domain usage, stop spoofing attempts, and maintain the integrity of your email security policies.

Maximum Message Size Setting for Email DLP

January 16, 2025
Standard email security limits often leave organizations vulnerable to threats hidden in large attachments that bypass inspection. Maximum Message Size Settings for Email DLP addresses this gap by extending scanning capabilities to larger data streams up to 150 MB allowing you to configure the actions by Enterprise DLP if a forwarded email message size exceeds the configured threshold.
The Maximum Message Size Settings assesses total email size, including attachments, against your configured threshold. If a message remains within limits, Enterprise DLP inspects the email for sensitive data. For emails that exceed your defined size, Enterprise DLP automatically takes the specified action, such as Monitor, Block, Quarantine, Encrypt, or Forward for Approval. To ensure complete visibility, Enterprise DLP logs all events, including skipped messages and applied actions. Additionally, Enterprise DLP processes archive files (e.g., .zip, .rar) as part of the total message size, maintaining consistent security coverage for nested content.

Regional Storage for Data Dictionaries

January 16, 2025
Regional Storage for Enterprise Data Loss Prevention (E-DLP) Data Dictionaries addresses data residency compliance challenges for organizations subject to strict data sovereignty requirements, particularly financial institutions operating across multiple regions. Regional Storage for Data Dictionaries enables data security administrators to upload data dictionaries directly to Enterprise DLP storage buckets in their chosen region. Administrators can select the appropriate region during upload, ensuring sensitive customer data remains within approved geographical boundaries.
Organizations operating across multiple regions can upload different dictionaries to different regional buckets. For example, administrators can store EU employee data in German storage buckets while keeping US employee data in US storage buckets. This approach helps organizations maintain regulatory compliance while preserving the complete detection capabilities of data dictionaries within their Enterprise DLP deployment.

Archive and Restore Custom Data Patterns

January 16, 2025
Security teams often have to keep up with evolving data security needs across different vectors of data loss. Historically, managing custom Enterprise Data Loss Prevention (E-DLP) data patterns presented significant challenges, as the inability to archive or rename outdated patterns resulted in configuration sprawl, increased administrative overhead, and difficulty in maintaining an optimized data protection strategy. You can now archive and restore Enterprise DLP custom data patterns to ease Enterprise DLP data pattern management. This feature allows you to rename data patterns, archive any data pattern no longer required, and restore previously archived data patterns.
This provides several key benefits for Enterprise DLP configuration management. It reduces console clutter by allowing you to archive unneeded data patterns which remove clutter from your Enterprise DLP data pattern list and allows you to focus on active your data patterns. By extension, you can choose to restore archived data pattern to allow for correction of errors or adaptation to evolving requirements.
Additionally, You gain enhanced adaptability and clarity by updating data pattern names to reflect current organizational needs which helps to improve overall consistency. Renames have an immediate configuration impact, reflecting in data pattern tables, associated data profiles, and across all DLP incidents and snippets. For comprehensive auditing, all rename and archive actions are logged, including the user, the affected pattern, and the timestamp.