When DLP rules detect policy violations in Exchange Online, they generate audit records that administrators rely on for compliance monitoring, incident investigation, and policy tuning. Previously, these records only showed Sensitive Information Type matches. This feature aims to extend that to sender domain, subject keywords, attachment type, or recipient information. Now they will be visible in alerts and Activity Explorer providing data enrichment to the administrators.
Roadmap › 562051
Microsoft Purview: Data Loss Prevention - Enriched Audit Data for Matched Rules
- General availability
- 2026-06
- Preview
- 2026-05
- Added
- 12 May 2026
- Last modified
- 28 Jul 2026 22:43 UTC
- First archived
- 25 Aug 2026
- Release rings
- General Availability, Preview
- Clouds
- Worldwide (Standard Multi-Tenant)