Microsoft 365 Data Loss Prevention Won’t Find What’s Already in the Downloads Folder
We run a scan that looks for personal information left in places nobody meant to leave it. Client lists, spreadsheets of holdings, scanned identity documents, the occasional file literally called passwords.
We run it on our own machines too, and an IT company’s Downloads folder turns out to be exactly as ordinary as everyone else’s.
I had client lists I downloaded from our CRM that I wanted to manipulate in Excel sitting in there. Old invoices with payment details and candidate resumes for a helpdesk role.
So I’m not going to tell you your staff is careless. I’m going to take four things I hear from partners who’ve done the security work properly and show you why each one is a bit less true than it sounds.
“It’s all in Microsoft 365”
This is the one that’s changed, and it’s changed in your favour.
For years the answer from my side of the industry was: secure Microsoft 365, because that’s where the data is. Firms did it. Yours probably did it well.
Meanwhile the candidate spreadsheet lives in Salesforce, the scanned passports live in Box, the CVs live in Dropbox because somebody set it up properly in 2021 and it works, and there’s a file share in the comms cupboard that predates the migration and that nobody has opened since.
Microsoft’s data loss prevention documentation now lists Box, Dropbox, Google Workspace and Salesforce among the places a policy can be scoped to, alongside on-premises file shares and document libraries. Finally! The tool admits where the data actually is.
The non-Microsoft connections are in preview. And the on-premises repositories, sitting in your own comms cupboard, need a separate scanner deployed before a policy can touch them, which is a project rather than a setting.
There’s a third thing I can’t fully source. The policy creation screen carries a notice that pay-as-you-go billing has to be set up before you can configure policies for non-Microsoft data sources. I’ve seen that notice in the product. I couldn’t find it stated on the documentation page, so treat it as something to confirm in your own tenant before anyone budgets around it.
Beware: Every firm I ask can name the three places its data lives. The trouble is always the fourth one.
“Prevention means somebody’s looking”
Here’s the distinction that took me too long to start making plainly.
Microsoft 365 data loss prevention is a gate. It sits on the way out and watches for personal information trying to leave: attached to an email, pasted into a browser, copied to a USB stick. It’s genuinely good, definitely necessary, and once it’s on, the bleeding mostly stops.
However it says nothing about what’s already inside the building.
Your firm has been trading for many years. Every policy you write starts working the day you switch it on, and every file that arrived before that is untouched by it. The gate doesn’t go looking. It was never built to.
Think about a house you’ve lived in for fifteen years. You’ve put in an alarm, deadbolts and sensor lights, and not one of them tells you what’s in the boxes in the garage. Somebody has to open the boxes.
“Downloads is temporary”
The Downloads folder is the most permanent storage on a laptop (with your recycle bin coming in 2nd). Nobody empties it. There’s no policy attached to it, no retention rule, no owner. It’s the drawer in the kitchen that everything ends up in.
And on a professional services laptop it holds a remarkable record of the firm. Every attachment anyone opened from a client. Every report exported from a system to check a number. Every statement, every identity document, every spreadsheet someone pulled down because opening it in the browser was slower.
Nobody did anything wrong to create that. Downloading the file was the fastest way to answer a client at four in the afternoon, and your firm rewards people who answer clients quickly.
Two things about it surprise people.
- Clearing it isn’t enough. Opening a spreadsheet leaves a temporary copy in an Office cache, one per opening, carrying the same contents as the original. Empty the Downloads folder and those copies are still there, unreferenced and complete. They belong in the same job.
- The Recycle Bin, which in the scans we run is frequently the single largest finding on a machine. Deleted isn’t gone. It’s recoverable, and the folder names usually survive intact, so anyone who recovers it also gets a tidy description of what they’ve found.
Tip: Pick one laptop this week, ideally a partner’s, and sort the Downloads folder by date. Look at the oldest fifty files. You’ll be shocked.
“We migrated, so it’s clean”
Migrations move what people ask for. They leave what nobody mentions.
After an in-place Windows upgrade the machine keeps a complete copy of the previous installation, mailbox included. It’s meant to be removed automatically after ten days. Where that didn’t complete, it’s still sitting there months later, a second version of somebody’s entire working life.
The pattern I’d watch for more than any single file is duplication. On one device we looked at, a single system export existed in well over a hundred copies, each a slightly different vintage, alongside dozens of cache copies of the same thing. Deleting them takes an afternoon. They’d be back within the month, because the thing generating them hadn’t changed.
That’s the difference between a clean-up and a proper look at how data gets created, kept and disposed of. One is a job. The other is the reason the job keeps coming back.
The same logic applies to people. A laptop that came back when someone left, sat in a cupboard for a year and then got reissued carries the previous person’s entire Downloads folder unless somebody deliberately dealt with it, which is why what you do when an employee leaves matters well beyond switching off their logins.
Why is this important?
The Office of the Australian Information Commissioner received 1,205 data breach notifications in the 2025 calendar year, an 8% increase on 2024. Malicious or criminal attack accounted for 716 of them.
The part that should worry you is what a notification actually requires. When you notify, you have to describe the kinds of personal information involved and who’s affected. Not approximately. Specifically enough that the people you’re telling can decide what to do about it.
A firm that knows where its data lives answers that in a day, and notifies the people who were actually affected.
A firm that doesn’t know notifies everyone, because it can’t rule anybody out. Same incident, same regulator, and a completely different number of clients who now have a letter from you sitting in their inbox.
That’s the cost of not knowing, and it never appears in anyone’s security budget.
What a scan finds, and what it can’t do
Finding the files is the easy half, and software does it. The hard half is that most of what comes back isn’t yours. Applications ship their own documents and generate enormous noise. A browser installs a dictionary file named passwords.txt that reports the same match count on every machine on earth, at a marketing agency, a surgical college and a funds manager alike. It’s nobody’s credentials.
Which sounds like a footnote until you think about what it does to whoever’s reading the report. You dismiss that file twenty times, you stop reading the path, and the twenty-first is the one a real person saved to their real desktop with their actual logins in it.
The other limit is bigger. A scan tells you what’s there. It can’t tell you what you’re allowed to delete. A seven-year-old client file might be an obligation you’re required to keep, and the person who can make that call works for you.
So what we do is narrower than it sounds, and more useful than it sounds. We can hand you a list of what personal information is sitting where, on which machines, in whose folders, with the software noise already stripped out and the numbers worth quoting separated from the numbers that aren’t. What happens to each line is a decision your firm makes, which is the right way round.
If you’d like to see what’s in the Downloads folders before your next risk committee, let us know and we can give it you in writing. Talk to us about DLP or Compliance Scanning for your business.
About the author
Yener is the founder and Managing Director of Intuitive IT. Prior to running his own business Yener worked for a number of corporate organisations where he gained invaluable experience and skills, as well as an understanding of how IT can complement and improve business outcomes.