Microsoft Purview | Data Loss Prevention – Enriched Audit Data for Matched Rules in Exchange Online
Microsoft Purview DLP for Exchange Online will enrich audit data with detailed matched conditions (e.g., sender, recipient, attachment, subject) when a DLP rule triggers. This enhancement, rolling out late June to July 2026, improves visibility without changing enforcement or requiring configuration. What and Why: We are enhancing Microsoft Purview Data Loss Prevention (DLP) audit data for Exchange Online by adding enriched matched condition details whenever a DLP rule is triggered. Previously, audit records primarily surfaced sensitive information type (SIT) matches. With this update, audit records now include all contributing rule conditions, including non-SIT conditions such as sender and recipient attributes, attachment properties, subject keywords, and message metadata. This change aligns with Microsoft’s enterprise-ready security and compliance commitments. It provides clearer insight into why a DLP rule was triggered without requiring manual cross-referencing of policy configurations and audit logs. This message is associated with Roadmap ID 562051. Rollout Schedule: General Availability (Worldwide): Rollout begins late June 2026 and is expected to complete by late July 2026. Impact on Your Organization: Who is affected: Administrators managing Microsoft Purview DLP policies scoped to Exchange Online Security and compliance teams reviewing DLP alerts, audit logs, or Activity Explorer data Platforms/Services: Microsoft Purview Exchange Online Unified Audit Log Activity Explorer DLP Alerts and user notifications What will happen: When a DLP rule in Exchange Online matches content, audit records will include enriched matched condition data for all contributing conditions. The enriched data includes the condition name, matched value, and the source that produced the match. This information appears in DLP Alerts, Activity Explorer, the Unified Audit Log, and user notifications where applicable. The feature is enabled by default. No configuration changes or policy updates are required. DLP enforcement behavior is unchanged. Supported conditions and example output: Attachment conditions Condition Example output File extension is Attachment Extension: txt — Testing.txt Document or attachment is password protected File.txt — Password Protected Document could not be scanned File.txt — Other Error Document didn’t complete scanning File.txt — Other Error Attachment count over 12 — Document1.pdf; Document2.pdf; Document3.pdf; Document4.pdf; Document5.pdf; …+7 more Sender conditions Condition Example output Shared by […]
The post Microsoft Purview | Data Loss Prevention – Enriched Audit Data for Matched Rules in Exchange Online appeared first on M365 Admin.
Published on:
Learn moreWe can help you with Microsoft Purview | Data Loss Prevention – Enriched Audit Data for Matched Rules in Exchange Online
If you want help implementing, troubleshooting, or improving this product, contact us and we’ll point you in the right direction.
Related posts
Microsoft OneDrive and SharePoint: Generate smart tables of contents for PDFs on the web with Copilot
Microsoft 365 Copilot users can generate AI-created, hierarchical, clickable tables of contents for PDFs in OneDrive and SharePoint on the web...
Microsoft Defender for Office 365: Changes to Unified RBAC permission mapping for Microsoft Entra Security Operator role
Microsoft is updating Microsoft Defender for Office 365’s Unified RBAC mapping for the Microsoft Entra Security Operator role, removing ...
Microsoft 365 Copilot: new guided Copilot onboarding experience
Microsoft 365 Copilot introduces an optional, admin-enabled guided onboarding experience for Frontier participants starting late October 2026....
Microsoft Purview |Unified Classification Management Experience
Microsoft Purview is launching a unified Classification Management experience for admins to manage classifiers consistently. Public Preview st...
Microsoft Purview | Data Loss Prevention: Administrative Units support for DLP policies for Microsoft Copilot
Microsoft Purview extends Microsoft Entra Administrative Units support to Copilot DLP policies, enabling delegated management within units whi...
Action required: Update Teams devices to a minimum app version ahead of the retirement of Exchange Web Services (EWS)
Update Microsoft Teams Rooms on Android, phones, and panels to the minimum app version released in February 2026 before October 2026 to avoid ...
Microsoft Power Platform governance and administration – Secure Dataverse record with column-based filtering
We are announcing the ability for admins to use filtered views to select and manage record-level access securely by defining security based on...
Microsoft Teams: Impersonation Protection for Teams meetings
Impersonation Protection for Teams meetings helps users identify potentially deceptive participants and meeting organizers. When Teams detects...
Microsoft Copilot (Microsoft 365): Use Dataverse Business Skills in Sales Agent
Business Skills are natural language instructions authored and stored in Microsoft Dataverse that teach Sales Agent how work gets done within ...