Back to Blog
    Competitive Intelligence

    ChatGPT DLP Without Microsoft Purview E5

    Purview prompt protection is real, and it lives behind E5, Edge for Business, and enrolled Windows. Here is the gap, and what a growing UK firm can deploy instead.

    Fendr Security28 August 20267 min read
    Comparison of Microsoft Purview Edge DLP and a Chrome/Edge extension for ChatGPT paste protection

    You are the IT Director or IT Manager at a 50-500 person UK firm, often in wealth or professional services. You have Microsoft 365 Business Premium or E3. You do not have E5. Then someone asks, "Can we just turn on Purview for ChatGPT?"

    The short answer is: Purview prompt protection is real, but it lives behind E5, Edge for Business, and Entra-enrolled Windows. If any of those are missing, the paste still happens.

    Purview is not missing. It is just not the product you bought.


    What Purview actually does for AI

    Microsoft's AI data loss prevention works through two things:

    • Endpoint DLP at the Windows OS level, which watches file transfers, clipboard, USB, and other device-level data movement.
    • Edge for Business browser-level prompt inspection, which can block or warn when sensitive data is pasted into AI tools like ChatGPT or Claude.

    The real-time prompt protection is browser-level and Edge-centric. It works on managed, Entra-enrolled Windows devices. That is its lane, and inside that lane it is effective.

    Outside that lane - Chrome, Safari, Mac, contractor laptops, personal devices, or any PC not enrolled in your Entra ID - the protection does not travel with the user.


    Why this matters for most UK firms

    Most growing firms are not 100% managed Windows. They have:

    • Mixed browsers: Chrome for some workflows, Edge for others
    • Macs in design, marketing, or leadership
    • Contractors and freelancers on their own hardware
    • BYOD policies that do not include full device enrolment

    In that environment, Purview E5 covers the Windows/Edge slice and leaves the rest open. The result is a familiar pattern: IT thinks the problem is solved, while staff paste client data into ChatGPT from Chrome on a Mac or from a personal phone.


    Comparison: what each approach actually covers

    ApproachStops paste in ChromeStops paste on MacStops paste for contractorsNeeds E5Deploy timeAudit log of AI use
    Microsoft Purview E5NoNoNoYesWeeks to monthsYes, within scope
    Fendr browser extensionYesYes, in Chrome/EdgeYes, in Chrome/EdgeNoMinutes via MDMYes
    Firewall / DNS blockNoNoNoNoHoursNo

    A few notes on the table:

    • Purview E5 is good in its lane. If you are already on E5/E7 with fully managed Windows, it is a sensible native option.
    • Fendr is a Chrome and Edge extension. It sees paste, type, and upload inside the browser. It does not need E5 and it works on Mac and contractor devices as long as they run a managed browser. The honest miss: it does not see native desktop apps like Claude desktop or Copilot inside Word.
    • Firewall bans block a domain, not the behaviour. Staff switch to another model, use a phone hotspot, or work from home. The paste continues; you just stop seeing it.

    When Fendr is the right layer

    Fendr is not a replacement for Microsoft's entire security stack. It is the layer that covers the browser gap when you are not on the full E5/E7 path.

    That usually means:

    • You have E3 or Business Premium and no immediate plan to upgrade to E5
    • Your workforce uses Chrome as well as Edge
    • You have Macs, contractors, or BYOD that cannot be Entra-enrolled
    • You need a deploy-today control while a longer Microsoft procurement decision runs in parallel

    If you are considering E7, read our breakdown of Microsoft 365 E7 and AI security. If you want the practical rollout, see how to stop employees pasting into ChatGPT.


    What an IT manager should do this week

    1. Check what you actually bought. Confirm your Microsoft licence level and whether your devices are Entra-enrolled. Many IT teams assume Purview is available when it is not. 2. Map the real environment. Count browsers, Macs, contractors, and remote workers. That is your uncovered surface. 3. Deploy visibility first. A browser extension like Fendr can be pushed via MDM in minutes. Run in monitor mode to see which AI tools are in use and what data is reaching them. 4. Add controls without blocking AI. Block paste of client identifiers, account numbers, and source code into unsanctioned AI. Allow general questions. Redirect users to approved tools. 5. Keep the audit log. Evidence is what turns a policy into a defensible control. Fendr's compliance product produces export-ready AI usage logs for ISO 27001, SOC 2, GDPR, FCA, ICO, and SRA requests.


    The honest bottom line

    Microsoft Purview is not the wrong product. It is simply the wrong product for firms that have not bought the full E5/E7 stack and do not run 100% managed Windows.

    For everyone else, the practical answer is a lightweight browser-level control that works in the browsers staff already use, deploys in minutes, and produces the audit trail regulators and clients expect.

    If that sounds like your environment, run a free AI audit or see a demo.

    Ready to see what your team is actually using?

    Ready to Take Control of AI in Your Organisation?

    Join security-conscious teams who are enabling safe AI adoption without becoming the "department of no."

    Watch Demo