Microsoft will begin enforcing Data Loss Prevention and auto-labeling policies across Google Workspace, Salesforce, and five other non-Microsoft cloud services from September 2026. The expansion, announced via the Microsoft 365 Roadmap, marks the first time Purview will natively inspect and protect sensitive information sitting inside rival productivity, CRM, and infrastructure platforms.

What Exactly Is Changing?

On July 21, 2026, Microsoft updated Roadmap ID 568075 to confirm that Microsoft Purview will extend its DLP and Information Protection auto-labeling to connected third‑party applications. Until now, Purview’s strongest enforcement lived inside Exchange Online, SharePoint, OneDrive, and Teams. With this release, organizations will be able to define policies that automatically detect financial records, health information, credentials, or any sensitive data type inside Google Workspace, Box, Dropbox, Salesforce, ServiceNow, Amazon Web Services, and Cisco Webex—then trigger actions ranging from alerts to access restrictions.

The feature enters preview in July 2026 and reaches worldwide general availability in September 2026 for the Standard Multi‑Tenant cloud. Microsoft cautions that supported conditions and actions will vary by application, so administrators should not expect identical enforcement everywhere.

Which Services Are Covered?

The initial list spans seven categories of business software:

  • Google Workspace – productivity and document collaboration
  • Box and Dropbox – cloud content repositories
  • Salesforce – customer relationship management
  • ServiceNow – IT service management and workflows
  • Amazon Web Services – public‑cloud infrastructure
  • Cisco Webex – communications and collaboration

This is not just about file storage. Microsoft wants Purview to follow data into CRMs, help desks, chat platforms, and cloud data lakes.

What This Means for Your Data

For years, security teams have stitched together separate controls for each application. A customer list might be locked down in SharePoint but freely shareable after someone uploads it to Box. With this update, a single Purview rule can evaluate that list regardless of where it lands.

The goal is a data‑centric model: attach protection to the information itself, not the container. If a file contains passport numbers or trade secrets, Purview can classify it even if it was created outside Microsoft Office and attached to a Salesforce record or stored in an S3 bucket.

But the fine print matters. Microsoft explicitly warns that conditions and actions will vary by application. A policy that removes public links in Box may only generate an alert in ServiceNow. An auto‑label that encrypts a Word document in OneDrive might only add metadata to a file in Google Workspace. Administrators must build an application‑specific capability matrix before turning on enforcement.

How We Got Here

Microsoft has been inching toward cross‑cloud data governance for years. Defender for Cloud Apps already offered file policies for connected services, but those policies will retire on January 6, 2027. Roadmap ID 568075 is the bridge: the company is moving file‑based protection from Defender for Cloud Apps into Purview’s unified policy console.

This consolidation makes strategic sense. Purview already handles classification, labeling, and DLP for Microsoft 365 and Windows endpoints. Pulling third‑party app controls into the same interface reduces administrative fragmentation—but it also imposes a tight migration deadline. With general availability slated for September 2026, organizations replacing Defender for Cloud Apps file policies will have only about four months to test, map, and migrate before the retirement on January 6, 2027.

What You Should Do Right Now

For IT and Security Administrators

The July 2026 preview is your earliest chance to see real behavior. Do not connect every production repository and flip all policies to “block.” Instead:

  1. Inventory existing policies. Document every active Defender for Cloud Apps file policy, its connected service, conditions, actions, and exceptions.

  2. Build a connector capability matrix. For Google Workspace, Box, Dropbox, Salesforce, ServiceNow, AWS, and Webex, record:
    - Which object types (files, messages, records) can Purview inspect?
    - What is the maximum file size?
    - Does scanning target new content, existing content, or both?
    - Which sensitive info types and classifiers are supported?
    - Can policies apply sensitivity labels, and if so, are they native or metadata‑only?
    - Which remediation actions work: remove public links, quarantine, delete, notify?
    - How quickly after creation or modification does evaluation happen?
    - What permissions does the connector require, and what audit logs does it produce?

  3. Run in simulation first. Deploy policies in audit‑only or simulation mode. Measure volume of matches, false positives, detection latency, and any impact on business workflows. A false positive that blocks a customer case in ServiceNow or removes sharing from an active deal room in Salesforce can damage operations.

  4. Plan the Defender for Cloud Apps transition. Map each legacy file policy to an equivalent Purview configuration. If a vendor‑specific action has no Purview counterpart, document the gap and identify a compensating control.

  5. Establish cross‑functional governance. Connected‑app DLP spans multiple teams. Data owners should approve classification rules; application owners must validate connector access and performance; security teams manage detection and incident response; compliance verifies regulatory coverage. Create a RACI before putting policies into production.

For End Users

Once policies go live, you may encounter new labels, sharing restrictions, or warnings inside applications you never associated with Microsoft. A document in Google Workspace might suddenly carry a “Confidential” tag. A Salesforce record might become read‑only. When that happens, look for policy tips that explain why the action occurred and what you can do—such as removing sensitive information, requesting an exception, or moving the file to an approved location. If the message is unclear, report it to your IT help desk; poorly communicated blocks often lead to unsafe workarounds like screenshotting or copying data to personal accounts.

The Outlook

The success of this expansion hinges on documentation and connector depth. The condition‑and‑action matrix Microsoft publishes will determine whether Purview becomes a genuine cross‑cloud control plane or just a thin API inspector. Customers will also look for PowerShell, Graph API, and infrastructure‑as‑code support, because large enterprises cannot manage dozens of policies manually.

Above all, the four‑month window between September 2026 GA and the Defender for Cloud Apps file‑policy retirement on January 6, 2027, is alarmingly short. Organizations that begin testing during the July 2026 preview will be in the best position. Everyone else should start inventorying their existing third‑party data controls today.