I am using Microsoft Endpoint Data Loss Prevention (DLP) policies to monitor and control file transfers to removable media and cloud locations. The policy detects and prompts users for justification when files are copied to these destinations.
On a Windows 11 endpoint (managed by Intune, not a hybrid-joined machine), we are encountering an issue with a specific user, where:
- The specific user is unable to copy multiple files to removable media. Single files gets copied.
- On the first attempt, the Microsoft Malware Protection Command Line Utility (mpcmdrun.exe) prompts the user for justification as expected.
- However, subsequent paste attempts repeatedly show the same justification prompt, and no files are actually copied to the removable media.
Additional details:
- This behavior affects only this user; other users under the same DLP policy scope are unaffected.
- We have already tried resetting the endpoint multiple times, which temporarily resolves the issue, but the problem recurs after some time.
Questions:
- Has anyone encountered this issue with Microsoft DLP policies before?
- Are there specific troubleshooting steps or logs I should examine to diagnose why the justification prompt is stuck in a loop for this user?
- Could this be related to the user profile, Intune device configuration, or some local DLP policy caching?
Any insights or suggestions would be greatly appreciated!
Environment Details:
- OS: Windows 11 Enterprise
- Device Management: Intune (not hybrid-joined)
- DLP Policy Type: Microsoft Endpoint Data Loss Prevention (Device)
- Tool Involved: mpcmdrun.exe (Justification Prompt)
- Behavior Consistency: User-specific