Microsoft Purview compliance portal: Data Loss Prevention: User based alert aggregation
Microsoft Purview DLP introduces opt-in User-Based Alert Aggregation, consolidating alerts by user within a set time window to improve security triage. Rolling out from September to November 2025, admins can enable it in the compliance portal to group rule match events per user, enhancing investigation efficiency. Introduction We’re introducing User-Based Alert Aggregation in Microsoft Purview Data Loss Prevention (DLP) to help security teams triage alerts more efficiently. This feature consolidates DLP rule match events by user identity within a defined time window, enabling faster investigation and remediation of potential insider threats. This message is associated with Roadmap ID 501786. When this will happen: Public Preview: We will begin rolling out late September 2025 and expect to complete by early October 2025. General Availability (Worldwide): We will begin rolling out late October 2025 and expect to complete by early November 2025. How this affects your organization: Who is affected: Admins managing DLP policies in Microsoft Purview compliance portal. What will happen: This feature is opt-in and can be enabled via the Microsoft Purview compliance portal. Navigate to Settings > Data Loss Prevention > User-Based Alert Aggregation. Toggle on User-Based Aggregation and select an aggregation time window (minimum 15 minutes). View image in new tab What you can do to prepare: DLP rule match events for the same user and rule within the selected window will be grouped into a single alert. Alerts will be created per user and per rule. For example, if User A and User B violate the same rule within 15 minutes, two separate alerts will be generated. Alert volume may increase due to per-user aggregation. Events will continue to be added to an alert even if it is marked resolved or closed, as long as the aggregation window is active. No preparation is required unless you choose to enable the feature. To opt in: Go to Microsoft Purview compliance portal. Navigate to Settings > Data Loss Prevention > User-Based Alert Aggregation. Toggle on the feature and select your preferred aggregation time window. Review internal documentation and communicate the change to your security operations team. Compliance considerations: No […]
The post Microsoft Purview compliance portal: Data Loss Prevention: User based alert aggregation appeared first on M365 Admin.
Published on:
Learn moreWe can help you with Microsoft Purview compliance portal: Data Loss Prevention: User based alert aggregation
If you want help implementing, troubleshooting, or improving this product, contact us and we’ll point you in the right direction.
Related posts
Microsoft 365: Entra ID Backup & Recovery
Enable extended 30-day backup and recovery for a tenant’s Entra objects via the Microsoft 365 Backup native app or M365 Backup Storage p...
Microsoft Viva: Viva Insights and Copilot Analytics in GCC-High
Microsoft Viva Insights and Copilot Analytics are coming to Microsoft 365 Government Community Cloud High (GCC High), providing eligible organ...
Microsoft Copilot Studio: Streamlining experiences from Copilot Studio Agents in Microsoft 365 Copilot
This update is meant to bridge the experience of using Copilot Studio agents in M365 Copilot with the Copilot Chat experience. With these upda...
Microsoft Copilot Studio: Enabling makers to require human approval for tool calls
Copilot Studio now let’s makers require human approval before an agent runs specific tools. With a per-tool, per-agent toggle, any gated tool ...
Updates available for Microsoft 365 Apps for Current Channel
We’ve released updates to the following update channel for Microsoft 365 Apps: Current Channel When this will happen: We’ll be gra...
General Availability of Power BI developer mode
Power BI developer mode and the PBIP file format are generally available, making PBIR the default report format in Power BI Desktop and servic...
Microsoft Teams: Users can temporarily pause all notifications
Microsoft Teams will let users temporarily pause notifications for a chosen time to reduce interruptions and improve focus. This feature, avai...
Teams web client users will be redirected to teams.cloud.microsoft
Teams web users will be redirected from teams.microsoft.com to teams.cloud.microsoft by September 2026. This domain change won’t affect ...
Outlook for iOS and Android: Automatically apply email sensitivity labels from labeled attachments
Outlook for iOS and Android will automatically apply or recommend email sensitivity labels based on attached files with Microsoft Purview labe...
Outlook for Mac: Sensitivity label recommendations and auto-labeling from attachments
Outlook for Mac will auto-apply or recommend Microsoft Purview sensitivity labels on emails based on attached files’ labels, enhancing c...