Microsoft Purview: Data Loss Prevention – Enhancements to Data Security Triage Agent
Adding below enhancements to Data Security Triage Agent in MS Purview – Metadata supported Custom Instructions (DLP only) : Earlier the agent only supported custom instructions which are related to content (E.g. Focus on alerts related to financial information). Now we also support instructions related to metadata. (E.g. Focus on alerts related to financial information for user Adam in last 20 days) – Consolidated Agent settings : Earlier we had seperate controls for deployment configuration and triggers. We are now merging them into a single view as the settings can be altered anytime and it becomes easier for admins and analysts to change them from single view. – Support for alerts with Non content contains condition (DLP only) : Till now we were showing alerts generated from non-content contains conditions as unsupported. (E.g. Condition = RecipientDomainIs matches and triggers alert, alert is unsupported). Now we are bringing the alerts into triage capability and determining categorization for them also – Agent Identity : Now the Triage agent can be deployed with Agent’s own identity generated in Microsoft Entra. There won’t be a need to have the agent run using the user’s identity who was setting up the agent. This provides cleaner audit capabilities. Product Release phase Preview Release date April CY2026Preview date: February CY2026 Platform Web Cloud Instance Worldwide (Standard Multi-Tenant) Created 2026-02-20 00:00:24Z Roadmap ID 557552 Roadmap Link https://www.microsoft.com/microsoft-365/roadmap?id=557552
The post Microsoft Purview: Data Loss Prevention – Enhancements to Data Security Triage Agent appeared first on M365 Admin.
Published on:
Learn moreWe can help you with Microsoft Purview: Data Loss Prevention – Enhancements to Data Security Triage Agent
If you want help implementing, troubleshooting, or improving this product, contact us and we’ll point you in the right direction.