Loading...

Microsoft Purview compliance portal: Data Loss Prevention: User based alert aggregation

Microsoft Purview compliance portal: Data Loss Prevention: User based alert aggregation

Microsoft Purview DLP introduces opt-in User-Based Alert Aggregation, consolidating alerts by user within a set time window to improve security triage. Rolling out from September to November 2025, admins can enable it in the compliance portal to group rule match events per user, enhancing investigation efficiency. Introduction We’re introducing User-Based Alert Aggregation in Microsoft Purview Data Loss Prevention (DLP) to help security teams triage alerts more efficiently. This feature consolidates DLP rule match events by user identity within a defined time window, enabling faster investigation and remediation of potential insider threats. This message is associated with Roadmap ID 501786. When this will happen: Public Preview: We will begin rolling out late September 2025 and expect to complete by early October 2025. General Availability (Worldwide): We will begin rolling out late October 2025 and expect to complete by early November 2025. How this affects your organization: Who is affected: Admins managing DLP policies in Microsoft Purview compliance portal. What will happen: This feature is opt-in and can be enabled via the Microsoft Purview compliance portal. Navigate to Settings > Data Loss Prevention > User-Based Alert Aggregation. Toggle on User-Based Aggregation and select an aggregation time window (minimum 15 minutes). View image in new tab What you can do to prepare: DLP rule match events for the same user and rule within the selected window will be grouped into a single alert. Alerts will be created per user and per rule. For example, if User A and User B violate the same rule within 15 minutes, two separate alerts will be generated. Alert volume may increase due to per-user aggregation. Events will continue to be added to an alert even if it is marked resolved or closed, as long as the aggregation window is active. No preparation is required unless you choose to enable the feature. To opt in: Go to Microsoft Purview compliance portal. Navigate to Settings > Data Loss Prevention > User-Based Alert Aggregation. Toggle on the feature and select your preferred aggregation time window. Review internal documentation and communicate the change to your security operations team. Compliance considerations: No […]

The post Microsoft Purview compliance portal: Data Loss Prevention: User based alert aggregation appeared first on M365 Admin.

Published on:

Learn more
Need help with this product?

We can help you with Microsoft Purview compliance portal: Data Loss Prevention: User based alert aggregation

If you want help implementing, troubleshooting, or improving this product, contact us and we’ll point you in the right direction.

M365 Admin
M365 Admin

by João Ferreira

Share post:

Related posts

Microsoft 365: Entra ID Backup & Recovery

Enable extended 30-day backup and recovery for a tenant’s Entra objects via the Microsoft 365 Backup native app or M365 Backup Storage p...

17 hours ago

Microsoft Viva: Viva Insights and Copilot Analytics in GCC-High

Microsoft Viva Insights and Copilot Analytics are coming to Microsoft 365 Government Community Cloud High (GCC High), providing eligible organ...

17 hours ago

Microsoft Copilot Studio: Streamlining experiences from Copilot Studio Agents in Microsoft 365 Copilot

This update is meant to bridge the experience of using Copilot Studio agents in M365 Copilot with the Copilot Chat experience. With these upda...

17 hours ago

Microsoft Copilot Studio: Enabling makers to require human approval for tool calls

Copilot Studio now let’s makers require human approval before an agent runs specific tools. With a per-tool, per-agent toggle, any gated tool ...

17 hours ago

Updates available for Microsoft 365 Apps for Current Channel

We’ve released updates to the following update channel for Microsoft 365 Apps: Current Channel When this will happen: We’ll be gra...

17 hours ago

General Availability of Power BI developer mode

Power BI developer mode and the PBIP file format are generally available, making PBIR the default report format in Power BI Desktop and servic...

17 hours ago

Microsoft Teams: Users can temporarily pause all notifications

Microsoft Teams will let users temporarily pause notifications for a chosen time to reduce interruptions and improve focus. This feature, avai...

17 hours ago

Teams web client users will be redirected to teams.cloud.microsoft

Teams web users will be redirected from teams.microsoft.com to teams.cloud.microsoft by September 2026. This domain change won’t affect ...

17 hours ago

Outlook for iOS and Android: Automatically apply email sensitivity labels from labeled attachments

Outlook for iOS and Android will automatically apply or recommend email sensitivity labels based on attached files with Microsoft Purview labe...

17 hours ago

Outlook for Mac: Sensitivity label recommendations and auto-labeling from attachments

Outlook for Mac will auto-apply or recommend Microsoft Purview sensitivity labels on emails based on attached files’ labels, enhancing c...

17 hours ago

Newsletter

Get the latest Dynamics 365 and Power Platform content in your inbox

A curated digest of community blogs, product news, videos, and podcasts — delivered without the noise.

Weekly updates Unsubscribe anytime Fresh community picks
We use your email only for the newsletter and you can unsubscribe at any time.
By subscribing, you agree to the privacy policy.