Your endpoint DLP rollout covers Windows 10/11 devices. Users browse in Microsoft Edge, Google Chrome, and Mozilla Firefox. You need endpoint DLP to monitor and block sensitive uploads to restricted cloud-service domains across all three browsers. What must you deploy, and what is the platform constraint?
Correct answer: D. The Microsoft Purview extension for Chrome and the Microsoft Purview extension for Firefox; Edge needs no extension. The extensions are supported on Windows 10/11 devices only.
Edge is instrumented for endpoint DLP natively and needs no add-on. To extend endpoint DLP activity monitoring and protective actions (upload to a restricted service domain, print, copy to clipboard / removable storage / network share) to Chrome and Firefox, you install the Microsoft Purview extension for Chrome and the Microsoft Purview extension for Firefox respectively. Per Learn, these extensions are for Windows 10/11 devices. Where the extension is installed, it bypasses the unallowed-browser and unallowed-app restrictions for that browser, so monitoring works instead of a hard block.
Why the other options are wrong:
- A. Adding Chrome/Firefox to the Unallowed browsers list forces users to Edge; it does not give you monitoring within those browsers. Installing the extension is what enables in-browser monitoring, and it bypasses the unallowed lists where installed.
- B. There is no single universal package. Chrome and Firefox each have their own dedicated Microsoft Purview extension; Edge needs none.
- C. Endpoint DLP does not natively instrument Chrome and Firefox the way it does Edge. Without the Purview extensions, those browsers are treated as unsupported (and can be redirected to Edge or blocked).
Memory hook: Edge is built in. Chrome and Firefox each need their own Purview extension, and only on Windows. The extension is what turns a hard block into actual monitoring.
Microsoft Learn: DLP chrome





