Microsoft Defender XDR: DLP alerts will be set as behaviors by default
Microsoft Defender XDR will set Microsoft Purview DLP alerts as behaviors by default starting October 12, 2026, reducing alert volume while keeping DLP data accessible in Advanced Hunting and Purview. Administrators can disable this rule to retain DLP alerts in the Defender XDR incident queue. What and why: Microsoft Defender XDR is introducing a new built-in alert tuning rule that sets Microsoft Purview Data Loss Prevention (DLP) alerts as behaviors. This change is designed to reduce alert volume in Microsoft Defender XDR while preserving DLP investigation data in Advanced Hunting and the Microsoft Purview portal. Administrators can disable the rule if they prefer DLP events to continue generating standard alerts and appearing in the incident queues in Microsoft Defender XDR portal. Rollout Schedule: The alert tuning rule is available for review today in Microsoft Defender XDR. The rule will be enabled by default beginning October 12, 2026. Impact on Your Organization: Who is affected: Security administrators and analysts who use Microsoft Defender XDR and Microsoft Purview DLP. Services affected: Microsoft Defender XDR, Microsoft Purview Data Loss Prevention (DLP), Advanced Hunting. After the change takes effect: DLP alerts will no longer appear in the Microsoft Defender XDR incident queue by default. DLP signals will remain available for investigation through the BehaviorInfo and BehaviorEntities tables in Advanced Hunting. DLP alerts will continue to be available in the Microsoft Purview portal. This change is controlled by the built-in alert tuning rule: Set-As-Behavior – Data Loss Prevention (DLP) Alerts. Action Required / Recommendations: No action is required if you want to use the new default experience. If your organization relies on DLP alerts appearing in the Microsoft Defender XDR incident queue, disable the rule before October 12, 2026, to keep the current experience. The rule can also be disabled at any time after it takes effect. To continue receiving DLP alerts in the Microsoft Defender XDR incident queue: Go to Settings > Microsoft Defender XDR > Alert tuning. Locate the rule Set-As-Behavior – Data Loss Prevention (DLP) Alerts. Disable the rule. Additional Considerations Organizations that use Microsoft Defender XDR incidents and alerts as part of […]
The post Microsoft Defender XDR: DLP alerts will be set as behaviors by default appeared first on M365 Admin.
Published on:
Learn moreWe can help you with Microsoft Defender XDR: DLP alerts will be set as behaviors by default
If you want help implementing, troubleshooting, or improving this product, contact us and we’ll point you in the right direction.
Related posts
Microsoft 365: Entra ID Backup & Recovery
Enable extended 30-day backup and recovery for a tenant’s Entra objects via the Microsoft 365 Backup native app or M365 Backup Storage p...
Microsoft Viva: Viva Insights and Copilot Analytics in GCC-High
Microsoft Viva Insights and Copilot Analytics are coming to Microsoft 365 Government Community Cloud High (GCC High), providing eligible organ...
Microsoft Copilot Studio: Streamlining experiences from Copilot Studio Agents in Microsoft 365 Copilot
This update is meant to bridge the experience of using Copilot Studio agents in M365 Copilot with the Copilot Chat experience. With these upda...
Microsoft Copilot Studio: Enabling makers to require human approval for tool calls
Copilot Studio now let’s makers require human approval before an agent runs specific tools. With a per-tool, per-agent toggle, any gated tool ...
Updates available for Microsoft 365 Apps for Current Channel
We’ve released updates to the following update channel for Microsoft 365 Apps: Current Channel When this will happen: We’ll be gra...
General Availability of Power BI developer mode
Power BI developer mode and the PBIP file format are generally available, making PBIR the default report format in Power BI Desktop and servic...
Microsoft Teams: Users can temporarily pause all notifications
Microsoft Teams will let users temporarily pause notifications for a chosen time to reduce interruptions and improve focus. This feature, avai...
Teams web client users will be redirected to teams.cloud.microsoft
Teams web users will be redirected from teams.microsoft.com to teams.cloud.microsoft by September 2026. This domain change won’t affect ...
Outlook for iOS and Android: Automatically apply email sensitivity labels from labeled attachments
Outlook for iOS and Android will automatically apply or recommend email sensitivity labels based on attached files with Microsoft Purview labe...
Outlook for Mac: Sensitivity label recommendations and auto-labeling from attachments
Outlook for Mac will auto-apply or recommend Microsoft Purview sensitivity labels on emails based on attached files’ labels, enhancing c...