Microsoft Defender XDR: DLP alerts will be set as behaviors by default
Microsoft Defender XDR will set Microsoft Purview DLP alerts as behaviors by default starting October 12, 2026, reducing alert volume while keeping DLP data accessible in Advanced Hunting and Purview. Administrators can disable this rule to retain DLP alerts in the Defender XDR incident queue. What and why: Microsoft Defender XDR is introducing a new built-in alert tuning rule that sets Microsoft Purview Data Loss Prevention (DLP) alerts as behaviors. This change is designed to reduce alert volume in Microsoft Defender XDR while preserving DLP investigation data in Advanced Hunting and the Microsoft Purview portal. Administrators can disable the rule if they prefer DLP events to continue generating standard alerts and appearing in the incident queues in Microsoft Defender XDR portal. Rollout Schedule: The alert tuning rule is available for review today in Microsoft Defender XDR. The rule will be enabled by default beginning October 12, 2026. Impact on Your Organization: Who is affected: Security administrators and analysts who use Microsoft Defender XDR and Microsoft Purview DLP. Services affected: Microsoft Defender XDR, Microsoft Purview Data Loss Prevention (DLP), Advanced Hunting. After the change takes effect: DLP alerts will no longer appear in the Microsoft Defender XDR incident queue by default. DLP signals will remain available for investigation through the BehaviorInfo and BehaviorEntities tables in Advanced Hunting. DLP alerts will continue to be available in the Microsoft Purview portal. This change is controlled by the built-in alert tuning rule: Set-As-Behavior – Data Loss Prevention (DLP) Alerts. Action Required / Recommendations: No action is required if you want to use the new default experience. If your organization relies on DLP alerts appearing in the Microsoft Defender XDR incident queue, disable the rule before October 12, 2026, to keep the current experience. The rule can also be disabled at any time after it takes effect. To continue receiving DLP alerts in the Microsoft Defender XDR incident queue: Go to Settings > Microsoft Defender XDR > Alert tuning. Locate the rule Set-As-Behavior – Data Loss Prevention (DLP) Alerts. Disable the rule. Additional Considerations Organizations that use Microsoft Defender XDR incidents and alerts as part of […]
The post Microsoft Defender XDR: DLP alerts will be set as behaviors by default appeared first on M365 Admin.
Published on:
Learn moreWe can help you with Microsoft Defender XDR: DLP alerts will be set as behaviors by default
If you want help implementing, troubleshooting, or improving this product, contact us and we’ll point you in the right direction.
Related posts
Microsoft Copilot (Microsoft 365): Local inferencing
Local inferencing expands Microsoft Copilot’s sovereign controls by enabling AI inferencing for supported Copilot interactions to occur within...
Dynamics 365 Customer Service: Quality evaluation supports knowledge source in criteria
Criteria questions can now use knowledge sources to help evaluate customer interactions. This allows organizations to ground evaluation criter...
Microsoft Viva: Ability for leaders to publish Power BI reports
Microsoft Viva Insights is extending its report publishing capabilities from analysts to leader personas such as Chief Officers, Managers and ...
Dynamics 365 Customer Service: Detailed quality evaluation score breakdown
Evaluation details now include a scoring breakdown at the overall, section, and question level. Users can see how the final evaluation score w...
Dynamics 365 Customer Service: Support Not Applicable answer option for quality evaluation criteria
Criteria questions now support a Not Applicable answer option. When a question is marked as not applicable, it is excluded from scoring instea...
Dynamics 365 Customer Service: Inactivate quality evaluation records
Quality managers can now inactivate evaluation records that should no longer contribute to scoring or reporting. Inactive evaluations are pres...
Microsoft Teams: Granular Conditional Access for Teams meetings
Granular Conditional Access for Teams meetings gives organizations greater control over access to sensitive meetings. Administrators can apply...
Customized PowerBI reports behavior after major report updates
Microsoft Viva Insights customized Power BI reports will remain tied to their original report versions and won’t auto-update with major report...
Microsoft SharePoint: Changes to the FAQ web part authoring experience
The SharePoint FAQ web part will shift AI-assisted FAQ creation to Copilot in SharePoint, while retaining manual FAQ editing in the web part. ...
Microsoft 365 Copilot: Federated Copilot connectors support create, update, and delete actions
Microsoft 365 Copilot’s federated connectors will support create, update, and delete actions in third-party services starting October 20...