“An organisation with strong DLP but no data classification is enforcing rules nobody defined. An organisation with data classification but no DLP is defining rules nobody enforces.”
Data protection is not a single control. It is a stack. Data classification determines what must be protected. Data Loss Prevention policies enforce protection at the connector boundary. The Dataverse security model enforces it at the record and field level. Sensitivity labels extend classification to documents and outputs. Each layer depends on the ones beneath it.
What Power Platform Provides
Microsoft Purview sensitivity labels applicable to Dataverse environments. Data Loss Prevention policy tiering by environment type — restrictive for production, moderate for development, permissive only where justified and documented. Column-level security in Dataverse for sensitive fields. Azure Key Vault integration for secrets management. Environment-level data residency configuration for regulated workloads.
The Enterprise Gap
The most common Harden gap is a data classification model and a Data Loss Prevention policy designed independently — where the classification tiers do not map cleanly to the connector groupings. Makers discover the misalignment when a solution built on Confidential data is blocked by a policy calibrated for Internal. Designing both together — and testing the mapping against representative solutions before publishing — closes this gap before it creates friction.
One Action
Map each data classification tier to its permitted connector set in the current Data Loss Prevention policy. Where the mapping is unclear or inconsistent, resolve it. A clear, published mapping means makers understand the governance boundaries before they build — not at review.
Part 28 of 36 | #PowerPlatformAtScale
The full Harden model, including the data protection stack design and DLP tiering guide, are in the book.