Loading...

Microsoft Defender XDR: DLP alerts will be set as behaviors by default

Microsoft Defender XDR: DLP alerts will be set as behaviors by default

Microsoft Defender XDR will set Microsoft Purview DLP alerts as behaviors by default starting October 12, 2026, reducing alert volume while keeping DLP data accessible in Advanced Hunting and Purview. Administrators can disable this rule to retain DLP alerts in the Defender XDR incident queue. What and why: Microsoft Defender XDR is introducing a new built-in alert tuning rule that sets Microsoft Purview Data Loss Prevention (DLP) alerts as behaviors. This change is designed to reduce alert volume in Microsoft Defender XDR while preserving DLP investigation data in Advanced Hunting and the Microsoft Purview portal. Administrators can disable the rule if they prefer DLP events to continue generating standard alerts and appearing in the incident queues in Microsoft Defender XDR portal. Rollout Schedule: The alert tuning rule is available for review today in Microsoft Defender XDR. The rule will be enabled by default beginning October 12, 2026. Impact on Your Organization: Who is affected: Security administrators and analysts who use Microsoft Defender XDR and Microsoft Purview DLP. Services affected: Microsoft Defender XDR, Microsoft Purview Data Loss Prevention (DLP), Advanced Hunting. After the change takes effect: DLP alerts will no longer appear in the Microsoft Defender XDR incident queue by default. DLP signals will remain available for investigation through the BehaviorInfo and BehaviorEntities tables in Advanced Hunting. DLP alerts will continue to be available in the Microsoft Purview portal. This change is controlled by the built-in alert tuning rule: Set-As-Behavior – Data Loss Prevention (DLP) Alerts. Action Required / Recommendations: No action is required if you want to use the new default experience. If your organization relies on DLP alerts appearing in the Microsoft Defender XDR incident queue, disable the rule before October 12, 2026, to keep the current experience. The rule can also be disabled at any time after it takes effect. To continue receiving DLP alerts in the Microsoft Defender XDR incident queue: Go to Settings > Microsoft Defender XDR > Alert tuning. Locate the rule Set-As-Behavior – Data Loss Prevention (DLP) Alerts. Disable the rule. Additional Considerations Organizations that use Microsoft Defender XDR incidents and alerts as part of […]

The post Microsoft Defender XDR: DLP alerts will be set as behaviors by default appeared first on M365 Admin.

Published on:

Learn more
Need help with this product?

We can help you with Microsoft Defender XDR: DLP alerts will be set as behaviors by default

If you want help implementing, troubleshooting, or improving this product, contact us and we’ll point you in the right direction.

M365 Admin
M365 Admin

by João Ferreira

Share post:

Related posts

Microsoft 365: Entra ID Backup & Recovery

Enable extended 30-day backup and recovery for a tenant’s Entra objects via the Microsoft 365 Backup native app or M365 Backup Storage p...

15 hours ago

Microsoft Viva: Viva Insights and Copilot Analytics in GCC-High

Microsoft Viva Insights and Copilot Analytics are coming to Microsoft 365 Government Community Cloud High (GCC High), providing eligible organ...

15 hours ago

Microsoft Copilot Studio: Streamlining experiences from Copilot Studio Agents in Microsoft 365 Copilot

This update is meant to bridge the experience of using Copilot Studio agents in M365 Copilot with the Copilot Chat experience. With these upda...

15 hours ago

Microsoft Copilot Studio: Enabling makers to require human approval for tool calls

Copilot Studio now let’s makers require human approval before an agent runs specific tools. With a per-tool, per-agent toggle, any gated tool ...

15 hours ago

Updates available for Microsoft 365 Apps for Current Channel

We’ve released updates to the following update channel for Microsoft 365 Apps: Current Channel When this will happen: We’ll be gra...

15 hours ago

General Availability of Power BI developer mode

Power BI developer mode and the PBIP file format are generally available, making PBIR the default report format in Power BI Desktop and servic...

15 hours ago

Microsoft Teams: Users can temporarily pause all notifications

Microsoft Teams will let users temporarily pause notifications for a chosen time to reduce interruptions and improve focus. This feature, avai...

15 hours ago

Teams web client users will be redirected to teams.cloud.microsoft

Teams web users will be redirected from teams.microsoft.com to teams.cloud.microsoft by September 2026. This domain change won’t affect ...

15 hours ago

Outlook for iOS and Android: Automatically apply email sensitivity labels from labeled attachments

Outlook for iOS and Android will automatically apply or recommend email sensitivity labels based on attached files with Microsoft Purview labe...

15 hours ago

Outlook for Mac: Sensitivity label recommendations and auto-labeling from attachments

Outlook for Mac will auto-apply or recommend Microsoft Purview sensitivity labels on emails based on attached files’ labels, enhancing c...

15 hours ago

Newsletter

Get the latest Dynamics 365 and Power Platform content in your inbox

A curated digest of community blogs, product news, videos, and podcasts — delivered without the noise.

Weekly updates Unsubscribe anytime Fresh community picks
We use your email only for the newsletter and you can unsubscribe at any time.
By subscribing, you agree to the privacy policy.