
You are the IT Director or IT Manager at a 50-500 person UK firm, often in wealth or professional services. You have Microsoft 365 Business Premium or E3. You do not have E5. Then someone asks, "Can we just turn on Purview for ChatGPT?"
The short answer is: Purview prompt protection is real, but it lives behind E5, Edge for Business, and Entra-enrolled Windows. If any of those are missing, the paste still happens.
Purview is not missing. It is just not the product you bought.
What Purview actually does for AI
Microsoft's AI data loss prevention works through two things:
- Endpoint DLP at the Windows OS level, which watches file transfers, clipboard, USB, and other device-level data movement.
- Edge for Business browser-level prompt inspection, which can block or warn when sensitive data is pasted into AI tools like ChatGPT or Claude.
The real-time prompt protection is browser-level and Edge-centric. It works on managed, Entra-enrolled Windows devices. That is its lane, and inside that lane it is effective.
Outside that lane - Chrome, Safari, Mac, contractor laptops, personal devices, or any PC not enrolled in your Entra ID - the protection does not travel with the user.
Why this matters for most UK firms
Most growing firms are not 100% managed Windows. They have:
- Mixed browsers: Chrome for some workflows, Edge for others
- Macs in design, marketing, or leadership
- Contractors and freelancers on their own hardware
- BYOD policies that do not include full device enrolment
In that environment, Purview E5 covers the Windows/Edge slice and leaves the rest open. The result is a familiar pattern: IT thinks the problem is solved, while staff paste client data into ChatGPT from Chrome on a Mac or from a personal phone.
Comparison: what each approach actually covers
| Approach | Stops paste in Chrome | Stops paste on Mac | Stops paste for contractors | Needs E5 | Deploy time | Audit log of AI use |
|---|---|---|---|---|---|---|
| Microsoft Purview E5 | No | No | No | Yes | Weeks to months | Yes, within scope |
| Fendr browser extension | Yes | Yes, in Chrome/Edge | Yes, in Chrome/Edge | No | Minutes via MDM | Yes |
| Firewall / DNS block | No | No | No | No | Hours | No |
A few notes on the table:
- Purview E5 is good in its lane. If you are already on E5/E7 with fully managed Windows, it is a sensible native option.
- Fendr is a Chrome and Edge extension. It sees paste, type, and upload inside the browser. It does not need E5 and it works on Mac and contractor devices as long as they run a managed browser. The honest miss: it does not see native desktop apps like Claude desktop or Copilot inside Word.
- Firewall bans block a domain, not the behaviour. Staff switch to another model, use a phone hotspot, or work from home. The paste continues; you just stop seeing it.
When Fendr is the right layer
Fendr is not a replacement for Microsoft's entire security stack. It is the layer that covers the browser gap when you are not on the full E5/E7 path.
That usually means:
- You have E3 or Business Premium and no immediate plan to upgrade to E5
- Your workforce uses Chrome as well as Edge
- You have Macs, contractors, or BYOD that cannot be Entra-enrolled
- You need a deploy-today control while a longer Microsoft procurement decision runs in parallel
If you are considering E7, read our breakdown of Microsoft 365 E7 and AI security. If you want the practical rollout, see how to stop employees pasting into ChatGPT.
What an IT manager should do this week
1. Check what you actually bought. Confirm your Microsoft licence level and whether your devices are Entra-enrolled. Many IT teams assume Purview is available when it is not. 2. Map the real environment. Count browsers, Macs, contractors, and remote workers. That is your uncovered surface. 3. Deploy visibility first. A browser extension like Fendr can be pushed via MDM in minutes. Run in monitor mode to see which AI tools are in use and what data is reaching them. 4. Add controls without blocking AI. Block paste of client identifiers, account numbers, and source code into unsanctioned AI. Allow general questions. Redirect users to approved tools. 5. Keep the audit log. Evidence is what turns a policy into a defensible control. Fendr's compliance product produces export-ready AI usage logs for ISO 27001, SOC 2, GDPR, FCA, ICO, and SRA requests.
The honest bottom line
Microsoft Purview is not the wrong product. It is simply the wrong product for firms that have not bought the full E5/E7 stack and do not run 100% managed Windows.
For everyone else, the practical answer is a lightweight browser-level control that works in the browsers staff already use, deploys in minutes, and produces the audit trail regulators and clients expect.
If that sounds like your environment, run a free AI audit or see a demo.
Ready to see what your team is actually using?