Loading Now

Updating Purview DLP Sensitive Service Domain Groups with PowerShell

Microsoft Purview Data Loss Prevention (DLP) allows us to manage Sensitive Service Domain Groups, which help organize websites and network destinations referenced by endpoint DLP rules. You can conveniently control these settings through the Purview portal, while PowerShell can be handy for making changes that need to be repeatable, reviewed, and validated before making them permanent.

This article will guide you through retrieving tenant policy configurations, locating an existing group, adding new URLs only if they don’t already exist, confirming the changes, committing them, and finally, verifying the updated configuration.

 

Important: The SiteGroupsPsws object holds tenant-wide restrictions for endpoints. Always test your script in a non-production tenant first, back up the original configuration, and apply change control processes. Microsoft provides details on Get-PolicyConfig and Set-PolicyConfig for viewing and altering endpoint restrictions, but be aware that the internal structure of individual hashtable entries can change over time.

 

Requirement

Guidance

Permissions

Make sure to use an account with the necessary Microsoft Purview permissions for the changes you intend to make. According to Microsoft, you’ll need permissions in Security & Compliance PowerShell to use Get-PolicyConfig and Set-PolicyConfig.

PowerShell Module

Ensure the ExchangeOnlineManagement module is installed or updated. This module is critical for connecting to Security & Compliance PowerShell.

Connection

Connect to Security & Compliance PowerShell using Connect-IPPSSession prior to executing policy configuration commands.

Existing Group

The specific Sensitive Service Domain Group you are targeting must already exist. This script modifies a group named Claude; it doesn’t create new groups.

Change Controls

First, run the discovery and backup commands, use -WhatIf before committing changes, and keep the exported JSON for rollback if needed.

Install-Module -Name ExchangeOnlineManagement -Scope CurrentUser
Import-Module ExchangeOnlineManagement
Connect-IPPSSession

 

Check that you can retrieve the policy configuration successfully:

Get-PolicyConfig | Format-List

 

 

Next, list the names shown in SiteGroupsPsws to ensure your desired group exists before making any modifications.

(Get-PolicyConfig).SiteGroupsPsws |
    Where-Object { $_.ContainsKey(“Name”) } |
    ForEach-Object { $_.Name }

 

Before altering the in-memory object, export the current SiteGroupsPsws representation.

$BackupPath = “.\SiteGroupsPsws-backup-Dedicated Server.json” -f (Get-Date -Format “yyyyMMdd-HHmmss”)
(Get-PolicyConfig).SiteGroupsPsws |
    ConvertTo-Json -Depth 20 |
    Set-Content -Path $BackupPath -Encoding UTF8

Write-Host “Backup saved at $BackupPath” -ForegroundColor Cyan

 

$GroupName = “Claude”
$NewUrls = @(
    “claude1.com”,
    “chatgpt2.com”,
    “claude3.com”
)

 

Make sure to replace these sample values with the actual production URLs you have approved. Use just the domain or wildcard formats that your DLP design supports.

$PolicyConfig = Get-PolicyConfig
$Groups = $PolicyConfig.SiteGroupsPsws
$TargetGroup = $Groups | Where-Object { $_[“Name”] -eq $GroupName }

if (-not $TargetGroup) {
    $AvailableGroups = $Groups |
        Where-Object { $_.ContainsKey(“Name”) } |
        ForEach-Object { $_.Name }

    throw “Sensitive Service Domain Group ‘$GroupName’ not found. Available groups: $($AvailableGroups -join ‘, ‘)”
}

 

 

# Target Sensitive Service Domain Group

$GroupName = “Claude”

 

# URLs to add

$NewUrls = @(

    “claude1.com”,

    “chatgpt2.com”,

    “claude3.com”

)

 

$PolicyConfig = Get-PolicyConfig

$Groups = $PolicyConfig.SiteGroupsPsws

 

$TargetGroup = $Groups | Where-Object { $_[“Name”] -eq $GroupName }

 

$Addresses = $TargetGroup[“Addresses”] | ConvertFrom-Json

 

foreach ($Url in $NewUrls)

{

    if ($Addresses.Url -notcontains $Url)

    {

        $Addresses += [pscustomobject]@{

            Url       = $Url

            MatchType = “UrlMatch”

        }

    }

}

 

$TargetGroup[“Addresses”] = $Addresses | ConvertTo-Json -Compress

 

# Validate

Set-PolicyConfig -SiteGroupsPsws $Groups -WhatIf

 

# Commit the changes

Set-PolicyConfig -SiteGroupsPsws $Groups

 

To verify the changes, retrieve a fresh copy from the service instead of just checking the modified local object.

$VerifiedGroups = (Get-PolicyConfig).SiteGroupsPsws
$VerifiedTarget = $VerifiedGroups | Where-Object { $_[“Name”] -eq $GroupName }
$VerifiedAddresses = @($VerifiedTarget[“Addresses”] | ConvertFrom-Json)

$Verification = foreach ($Url in $NormalizedNewUrls) {
    [pscustomobject]@{
        Group   = $GroupName
        Url     = $Url
        Present = ($VerifiedAddresses.Url -contains $Url)
    }
}

$Verification | Format-Table -AutoSize

if ($Verification.Present -contains $false) {
    throw “Verification failed: some URLs were not found after the update.”
}

Write-Host “Verification successful for all requested URLs.” -ForegroundColor Green

 

 

# Writable PowerShell representation
(Get-PolicyConfig).SiteGroupsPsws | ConvertTo-Json -Depth 20

# Service view
(Get-PolicyConfig).SiteGroups

 

 

 

 

 

This example serves as an illustration only; actual service outputs and formats may differ based on module versions and tenant configurations.

Symptom

Recommended Check

Get-PolicyConfig or Set-PolicyConfig is not recognised

Verify that the ExchangeOnlineManagement module is installed and that you’ve connected the session with Connect-IPPSSession.

Access denied or authorization error

Check that your administrator account has the necessary Purview role-group permissions and reconnect after waiting for role propagation.

Target group not found

Run the discovery command and make sure to use the exact group name returned by SiteGroupsPsws.

Addresses cannot be parsed

Inspect the raw Addresses property before making any changes. If the object structure is unexpected, restore it from the exported JSON.

-WhatIf succeeds, but verification fails

Re-run Get-PolicyConfig, check for any service-side errors, and confirm that no other administrator updates have overwritten the configuration.

PowerShell offers a structured method for updating Microsoft Purview DLP Sensitive Service Domain Groups efficiently. The safest approach includes identifying the exact group name, backing up the current configuration, validating the target object, normalising and de-duplicating inputs, executing Set-PolicyConfig with -WhatIf, committing the changes, and then verifying via a fresh Get-PolicyConfig call. This validation-first strategy enhances repeatability and reduces the chances of unintended alterations to tenant-wide configurations.

 

Share this content:


Discover more from Qureshi

Subscribe to get the latest posts sent to your email.

Discover more from Qureshi

Subscribe now to keep reading and get access to the full archive.

Continue reading