Updating Purview DLP Sensitive Service Domain Groups with PowerShell
Microsoft Purview Data Loss Prevention (DLP) allows us to manage Sensitive Service Domain Groups, which help organize websites and network destinations referenced by endpoint DLP rules. You can conveniently control these settings through the Purview portal, while PowerShell can be handy for making changes that need to be repeatable, reviewed, and validated before making them permanent.
This article will guide you through retrieving tenant policy configurations, locating an existing group, adding new URLs only if they don’t already exist, confirming the changes, committing them, and finally, verifying the updated configuration.
| Important: The SiteGroupsPsws object holds tenant-wide restrictions for endpoints. Always test your script in a non-production tenant first, back up the original configuration, and apply change control processes. Microsoft provides details on |
Requirement | Guidance |
Permissions | Make sure to use an account with the necessary Microsoft Purview permissions for the changes you intend to make. According to Microsoft, you’ll need permissions in Security & Compliance PowerShell to use |
PowerShell Module | Ensure the ExchangeOnlineManagement module is installed or updated. This module is critical for connecting to Security & Compliance PowerShell. |
Connection | Connect to Security & Compliance PowerShell using |
Existing Group | The specific Sensitive Service Domain Group you are targeting must already exist. This script modifies a group named Claude; it doesn’t create new groups. |
Change Controls | First, run the discovery and backup commands, use |
Install-Module -Name ExchangeOnlineManagement -Scope CurrentUser |
Check that you can retrieve the policy configuration successfully:
Get-PolicyConfig | Format-List |
Next, list the names shown in SiteGroupsPsws to ensure your desired group exists before making any modifications.
(Get-PolicyConfig).SiteGroupsPsws | |
Before altering the in-memory object, export the current SiteGroupsPsws representation.
$BackupPath = “.\SiteGroupsPsws-backup-Dedicated Server.json” -f (Get-Date -Format “yyyyMMdd-HHmmss”) Write-Host “Backup saved at $BackupPath” -ForegroundColor Cyan |
$GroupName = “Claude” |
Make sure to replace these sample values with the actual production URLs you have approved. Use just the domain or wildcard formats that your DLP design supports.
$PolicyConfig = Get-PolicyConfig if (-not $TargetGroup) { throw “Sensitive Service Domain Group ‘$GroupName’ not found. Available groups: $($AvailableGroups -join ‘, ‘)” |
# Target Sensitive Service Domain Group $GroupName = “Claude”
# URLs to add $NewUrls = @( “claude1.com”, “chatgpt2.com”, “claude3.com” )
$PolicyConfig = Get-PolicyConfig $Groups = $PolicyConfig.SiteGroupsPsws
$TargetGroup = $Groups | Where-Object { $_[“Name”] -eq $GroupName }
$Addresses = $TargetGroup[“Addresses”] | ConvertFrom-Json
foreach ($Url in $NewUrls) { if ($Addresses.Url -notcontains $Url) { $Addresses += [pscustomobject]@{ Url = $Url MatchType = “UrlMatch” } } }
$TargetGroup[“Addresses”] = $Addresses | ConvertTo-Json -Compress
# Validate Set-PolicyConfig -SiteGroupsPsws $Groups -WhatIf
# Commit the changes Set-PolicyConfig -SiteGroupsPsws $Groups |
To verify the changes, retrieve a fresh copy from the service instead of just checking the modified local object.
$VerifiedGroups = (Get-PolicyConfig).SiteGroupsPsws $Verification = foreach ($Url in $NormalizedNewUrls) { $Verification | Format-Table -AutoSize if ($Verification.Present -contains $false) { Write-Host “Verification successful for all requested URLs.” -ForegroundColor Green |
# Writable PowerShell representation # Service view |
|
This example serves as an illustration only; actual service outputs and formats may differ based on module versions and tenant configurations.
Symptom | Recommended Check |
Get-PolicyConfig or Set-PolicyConfig is not recognised | Verify that the ExchangeOnlineManagement module is installed and that you’ve connected the session with |
Access denied or authorization error | Check that your administrator account has the necessary Purview role-group permissions and reconnect after waiting for role propagation. |
Target group not found | Run the discovery command and make sure to use the exact group name returned by SiteGroupsPsws. |
Addresses cannot be parsed | Inspect the raw Addresses property before making any changes. If the object structure is unexpected, restore it from the exported JSON. |
-WhatIf succeeds, but verification fails | Re-run |
PowerShell offers a structured method for updating Microsoft Purview DLP Sensitive Service Domain Groups efficiently. The safest approach includes identifying the exact group name, backing up the current configuration, validating the target object, normalising and de-duplicating inputs, executing Set-PolicyConfig with -WhatIf, committing the changes, and then verifying via a fresh Get-PolicyConfig call. This validation-first strategy enhances repeatability and reduces the chances of unintended alterations to tenant-wide configurations.
Share this content:
Discover more from Qureshi
Subscribe to get the latest posts sent to your email.