Favorite your Message Center and Roadmap items. Access them anytime via your Profile. Export and share with your team or your LLM.

(Updated) Microsoft Purview | Data Security Triage Agent Summaries for DLP Alerts in Microsoft Defender XDR

Message ID
MC1255406
View in Message Center
Services
Microsoft Defender XDRMicrosoft Purview
Category
Plan for Change
Tags
Major Change New featureAdmin impact
Rollout
April 2026August 2027
Roadmap ID
558860
View in M365 Roadmap
Platform
Web

Summary

Microsoft Purview introduces AI-generated summaries and categorizations for DLP alerts within Microsoft Defender XDR, aiding security analysts in triage. The Data Security Triage Agent can be deployed from Defender XDR, with management in Purview. Rollout starts April 2026 (preview) and August 2027 (GA). Existing policies remain unchanged.

Details

Updated August 17, 2026: We have updated the timeline. Thank you for your patience. 

[Introduction]

We’re introducing Data Security Triage Agent summaries and categorizations for Data Loss Prevention (DLP) alerts directly within the Microsoft Defender XDR portal. This update helps security analysts triage DLP alerts more efficiently by surfacing AI-generated summaries and categorizations created by the Microsoft Purview Data Security Triage Agent.

Screenshot 1: Data Security Triage Agent outputs and summaries now available in DLP alerts in Microsoft Defender XDR

user settings

This message is associated with Roadmap ID 558860.

[When this will happen:]

  • Public Preview: We will begin rolling out early April 2026 and expect to complete by mid-April 2026.
  • General Availability (Worldwide): We will begin rolling out August 2027 (previously August 2026).

[How this affects your organization:]

Who is affected:

  • Security analysts and admins triaging DLP alerts in Microsoft Defender XDR
  • Organizations using Microsoft Purview Data Security Triage Agent

What will happen:

  • DLP alerts in Defender XDR will display AI-generated summaries and categorizations when the Agent is deployed.
  • Screenshot 2: Security Analysts and Admins triaging DLP alerts in Defenders will be able to deploy the Data Security Triage Agent from the Microsoft Defender XDR portal

    user settings

  • If the Agent is not deployed, eligible analysts can deploy it from the DLP alert page in Defender XDR.
  • Agent management (instructions, pause/deactivate, usage monitoring) remains in Microsoft Purview.
  • Existing DLP policies and enforcement are not changed.
  • There is no impact to users.

[What you can do to prepare:]

  • Deploy the Data Security Triage Agent in Microsoft Purview to enable summaries in Defender XDR.
  • Review role assignments to ensure analysts who triage DLP alerts have the appropriate permissions.
  • Update internal security operations documentation to reflect the new triage experience.
  • Familiarize security teams with where Agent deployment can occur (Defender XDR) and where ongoing management is performed (Purview).

Learn more: Before rollout, we will update this post with new documentation.

[Compliance considerations:]

Compliance area Explanation
AI/ML or agent capabilities interacting with customer data This change introduces AI-generated summaries and categorizations for DLP alerts using the Microsoft Purview Data Security Triage Agent, which processes existing DLP alert data to assist analysts during triage.
Admin controls Admins can deploy the Data Security Triage Agent from the Microsoft Defender XDR portal. Ongoing agent management, including custom instructions, pausing or deactivating the agent, and monitoring usage, remains available in the Microsoft Purview portal.
Admin monitoring and compliance reporting The update enhances DLP alert investigations by adding AI-generated context, improving how admins monitor and assess data security incidents without changing underlying DLP policy enforcement or audit logging.

Change History

Show
August 31, 2026 at 10:31 PM Updated
Body Content
Previous
<p>Updated August 17, 2026: We have updated the timeline. Thank you for your patience.&nbsp;</p><p><b>[Introduction]</b></p> <p>We’re introducing <b>Data Security Triage Agent summaries and categorizations for Data Loss Prevention (DLP) alerts </b>directly within the <b>Microsoft Defender XDR portal</b>. This update helps security analysts triage DLP alerts more efficiently by surfacing AI-generated summaries and categorizations created by the <b>Microsoft Purview Data Security Triage Agent</b>.</p><p>Screenshot 1: <i>Data Security Triage Agent outputs and summaries now available in DLP alerts in Microsoft Defender XDR</i></p><p><img src="https://cxcs.microsoft.net/file/ccp/en-us/50c99607-4e2b-4535-99fb-62be7069f3d7" style="width: 400px;" alt="user settings"></p><p>This message is associated with Roadmap ID <a href="https://www.microsoft.com/microsoft-365/roadmap?filters=&amp;searchterms=558860" target="_blank" style="">558860</a>.</p> <p><b>[When this will happen:]</b></p><ul><li>Public Preview: We will begin rolling out <b>early April 2026 </b>and expect to complete by <b>mid-April 2026</b>.</li><li> General Availability (Worldwide): We will begin rolling out <b>August 2027 </b>(previously August 2026)<b>.</b></li></ul><p><b>[How this affects your organization:]</b></p><p><b>Who is affected:</b></p> <ul> <li>Security analysts and admins triaging DLP alerts in Microsoft Defender XDR</li> <li>Organizations using Microsoft Purview Data Security Triage Agent</li> </ul> <p><b>What will happen:</b></p> <ul> <li>DLP alerts in Defender XDR will display <b>AI-generated summaries and categorizations</b> when the Agent is deployed.</li><p>Screenshot 2: <i>Security Analysts and Admins triaging DLP alerts in Defenders will be able to deploy the Data Security Triage Agent from the Microsoft Defender XDR portal</i></p><p><img src="https://cxcs.microsoft.net/file/ccp/en-us/920c32a9-6acc-4c6d-9533-ed198096d581" style="width: 400px;" alt="user settings"></p> <li>If the Agent is not deployed, eligible analysts can <b>deploy it from the DLP alert page</b> in Defender XDR.</li> <li>Agent management (instructions, pause/deactivate, usage monitoring) remains in Microsoft Purview.</li> <li>Existing DLP policies and enforcement are <b>not changed</b>.</li> <li>There is no impact to users.</li> </ul> <p><b>[What you can do to prepare:]</b></p> <ul> <li>Deploy the <b>Data Security Triage Agent</b> in <b>Microsoft Purview </b>to enable summaries in Defender XDR.</li><li>Review role assignments to ensure analysts who triage DLP alerts have the appropriate permissions.</li><li>Update internal security operations documentation to reflect the new triage experience.</li><li>Familiarize security teams with where Agent deployment can occur (Defender XDR) and where ongoing management is performed (Purview).</li> </ul> <p><b>Learn more: </b>Before rollout, we will update this post with new documentation.</p><p><b>[Compliance considerations:]</b></p> <table border="1" cellpadding="6" cellspacing="0"> <tbody><tr> <th>Compliance area</th> <th>Explanation</th> </tr> <tr> <td>AI/ML or agent capabilities interacting with customer data</td> <td>This change introduces AI-generated summaries and categorizations for DLP alerts using the Microsoft Purview Data Security Triage Agent, which processes existing DLP alert data to assist analysts during triage.</td> </tr> <tr> <td>Admin controls</td> <td>Admins can deploy the Data Security Triage Agent from the Microsoft Defender XDR portal. Ongoing agent management, including custom instructions, pausing or deactivating the agent, and monitoring usage, remains available in the Microsoft Purview portal.</td> </tr> <tr> <td>Admin monitoring and compliance reporting</td> <td>The update enhances DLP alert investigations by adding AI-generated context, improving how admins monitor and assess data security incidents without changing underlying DLP policy enforcement or audit logging.</td> </tr> </tbody></table>
New
<p>Updated August 17, 2026: We have updated the timeline. Thank you for your patience.&nbsp;</p><p><b>[Introduction]</b></p> <p>We’re introducing <b>Data Security Triage Agent summaries and categorizations for Data Loss Prevention (DLP) alerts </b>directly within the <b>Microsoft Defender XDR portal</b>. This update helps security analysts triage DLP alerts more efficiently by surfacing AI-generated summaries and categorizations created by the <b>Microsoft Purview Data Security Triage Agent</b>.</p><p>Screenshot 1: <i>Data Security Triage Agent outputs and summaries now available in DLP alerts in Microsoft Defender XDR</i></p><p><img src="https://support.microsoft.com/en-us/customercomms/media/messagecenter/2026/03/20236-2.png" style="width: 400px;" alt="user settings"></p><p>This message is associated with Roadmap ID <a href="https://www.microsoft.com/microsoft-365/roadmap?filters=&amp;searchterms=558860" target="_blank" style="">558860</a>.</p> <p><b>[When this will happen:]</b></p><ul><li>Public Preview: We will begin rolling out <b>early April 2026 </b>and expect to complete by <b>mid-April 2026</b>.</li><li> General Availability (Worldwide): We will begin rolling out <b>August 2027 </b>(previously August 2026)<b>.</b></li></ul><p><b>[How this affects your organization:]</b></p><p><b>Who is affected:</b></p> <ul> <li>Security analysts and admins triaging DLP alerts in Microsoft Defender XDR</li> <li>Organizations using Microsoft Purview Data Security Triage Agent</li> </ul> <p><b>What will happen:</b></p> <ul> <li>DLP alerts in Defender XDR will display <b>AI-generated summaries and categorizations</b> when the Agent is deployed.</li><p>Screenshot 2: <i>Security Analysts and Admins triaging DLP alerts in Defenders will be able to deploy the Data Security Triage Agent from the Microsoft Defender XDR portal</i></p><p><img src="https://support.microsoft.com/en-us/customercomms/media/messagecenter/2026/03/20236.png" style="width: 400px;" alt="user settings"></p> <li>If the Agent is not deployed, eligible analysts can <b>deploy it from the DLP alert page</b> in Defender XDR.</li> <li>Agent management (instructions, pause/deactivate, usage monitoring) remains in Microsoft Purview.</li> <li>Existing DLP policies and enforcement are <b>not changed</b>.</li> <li>There is no impact to users.</li> </ul> <p><b>[What you can do to prepare:]</b></p> <ul> <li>Deploy the <b>Data Security Triage Agent</b> in <b>Microsoft Purview </b>to enable summaries in Defender XDR.</li><li>Review role assignments to ensure analysts who triage DLP alerts have the appropriate permissions.</li><li>Update internal security operations documentation to reflect the new triage experience.</li><li>Familiarize security teams with where Agent deployment can occur (Defender XDR) and where ongoing management is performed (Purview).</li> </ul> <p><b>Learn more: </b>Before rollout, we will update this post with new documentation.</p><p><b>[Compliance considerations:]</b></p> <table border="1" cellpadding="6" cellspacing="0"> <tbody><tr> <th>Compliance area</th> <th>Explanation</th> </tr> <tr> <td>AI/ML or agent capabilities interacting with customer data</td> <td>This change introduces AI-generated summaries and categorizations for DLP alerts using the Microsoft Purview Data Security Triage Agent, which processes existing DLP alert data to assist analysts during triage.</td> </tr> <tr> <td>Admin controls</td> <td>Admins can deploy the Data Security Triage Agent from the Microsoft Defender XDR portal. Ongoing agent management, including custom instructions, pausing or deactivating the agent, and monitoring usage, remains available in the Microsoft Purview portal.</td> </tr> <tr> <td>Admin monitoring and compliance reporting</td> <td>The update enhances DLP alert investigations by adding AI-generated context, improving how admins monitor and assess data security incidents without changing underlying DLP policy enforcement or audit logging.</td> </tr> </tbody></table>
August 18, 2026 at 12:31 AM Updated
Title
Previous
Microsoft Purview | Data Security Triage Agent Summaries for DLP Alerts in Microsoft Defender XDR
New
(Updated) Microsoft Purview | Data Security Triage Agent Summaries for DLP Alerts in Microsoft Defender XDR
Summary
Previous
Microsoft Defender XDR will integrate AI-generated summaries and categorizations for DLP alerts via the Microsoft Purview Data Security Triage Agent, improving alert triage. Deployment starts April 2026 (preview) and August 2026 (general). Agent management remains in Purview; DLP policies and user impact remain unchanged.
New
Microsoft Purview introduces AI-generated summaries and categorizations for DLP alerts within Microsoft Defender XDR, aiding security analysts in triage. The Data Security Triage Agent can be deployed from Defender XDR, with management in Purview. Rollout starts April 2026 (preview) and August 2027 (GA). Existing policies remain unchanged.
Last Updated Date
Previous
2026-03-18T22:30:00.027Z
New
2026-08-17T22:48:15.660Z
Tags
Previous
New feature,Admin impact
New
Updated message,New feature,Admin impact
Body Content
Previous
<p><b>[Introduction]</b></p> <p>We’re introducing <b>Data Security Triage Agent summaries and categorizations for Data Loss Prevention (DLP) alerts </b>directly within the <b>Microsoft Defender XDR portal</b>. This update helps security analysts triage DLP alerts more efficiently by surfacing AI-generated summaries and categorizations created by the <b>Microsoft Purview Data Security Triage Agent</b>.</p><p>Screenshot 1: <i>Data Security Triage Agent outputs and summaries now available in DLP alerts in Microsoft Defender XDR</i></p><p><img src="https://cxcs.microsoft.net/file/ccp/en-us/50c99607-4e2b-4535-99fb-62be7069f3d7" style="width: 400px;" alt="user settings"></p><p>This message is associated with Roadmap ID <a href="https://www.microsoft.com/microsoft-365/roadmap?filters=&amp;searchterms=558860" target="_blank" style="">558860</a>.</p> <p><b>[When this will happen:]</b></p><ul><li>Public Preview: We will begin rolling out <b>early April 2026 </b>and expect to complete by <b>mid-April 2026</b>.</li><li> General Availability (Worldwide): We will begin rolling out <b>mid-August 2026</b> and expect to complete by <b>late August 2026</b>.</li></ul><p><b>[How this affects your organization:]</b></p><p><b>Who is affected:</b></p> <ul> <li>Security analysts and admins triaging DLP alerts in Microsoft Defender XDR</li> <li>Organizations using Microsoft Purview Data Security Triage Agent</li> </ul> <p><b>What will happen:</b></p> <ul> <li>DLP alerts in Defender XDR will display <b>AI-generated summaries and categorizations</b> when the Agent is deployed.</li><p>Screenshot 2: <i>Security Analysts and Admins triaging DLP alerts in Defenders will be able to deploy the Data Security Triage Agent from the Microsoft Defender XDR portal</i></p><p><img src="https://cxcs.microsoft.net/file/ccp/en-us/920c32a9-6acc-4c6d-9533-ed198096d581" style="width: 400px;" alt="user settings"></p> <li>If the Agent is not deployed, eligible analysts can <b>deploy it from the DLP alert page</b> in Defender XDR.</li> <li>Agent management (instructions, pause/deactivate, usage monitoring) remains in Microsoft Purview.</li> <li>Existing DLP policies and enforcement are <b>not changed</b>.</li> <li>There is no impact to users.</li> </ul> <p><b>[What you can do to prepare:]</b></p> <ul> <li>Deploy the <b>Data Security Triage Agent</b> in <b>Microsoft Purview </b>to enable summaries in Defender XDR.</li><li>Review role assignments to ensure analysts who triage DLP alerts have the appropriate permissions.</li><li>Update internal security operations documentation to reflect the new triage experience.</li><li>Familiarize security teams with where Agent deployment can occur (Defender XDR) and where ongoing management is performed (Purview).</li> </ul> <p><b>Learn more: </b>Before rollout, we will update this post with new documentation.</p><p><b>[Compliance considerations:]</b></p> <table border="1" cellpadding="6" cellspacing="0"> <tbody><tr> <th>Compliance area</th> <th>Explanation</th> </tr> <tr> <td>AI/ML or agent capabilities interacting with customer data</td> <td>This change introduces AI-generated summaries and categorizations for DLP alerts using the Microsoft Purview Data Security Triage Agent, which processes existing DLP alert data to assist analysts during triage.</td> </tr> <tr> <td>Admin controls</td> <td>Admins can deploy the Data Security Triage Agent from the Microsoft Defender XDR portal. Ongoing agent management, including custom instructions, pausing or deactivating the agent, and monitoring usage, remains available in the Microsoft Purview portal.</td> </tr> <tr> <td>Admin monitoring and compliance reporting</td> <td>The update enhances DLP alert investigations by adding AI-generated context, improving how admins monitor and assess data security incidents without changing underlying DLP policy enforcement or audit logging.</td> </tr> </tbody></table>
New
<p>Updated August 17, 2026: We have updated the timeline. Thank you for your patience.&nbsp;</p><p><b>[Introduction]</b></p> <p>We’re introducing <b>Data Security Triage Agent summaries and categorizations for Data Loss Prevention (DLP) alerts </b>directly within the <b>Microsoft Defender XDR portal</b>. This update helps security analysts triage DLP alerts more efficiently by surfacing AI-generated summaries and categorizations created by the <b>Microsoft Purview Data Security Triage Agent</b>.</p><p>Screenshot 1: <i>Data Security Triage Agent outputs and summaries now available in DLP alerts in Microsoft Defender XDR</i></p><p><img src="https://cxcs.microsoft.net/file/ccp/en-us/50c99607-4e2b-4535-99fb-62be7069f3d7" style="width: 400px;" alt="user settings"></p><p>This message is associated with Roadmap ID <a href="https://www.microsoft.com/microsoft-365/roadmap?filters=&amp;searchterms=558860" target="_blank" style="">558860</a>.</p> <p><b>[When this will happen:]</b></p><ul><li>Public Preview: We will begin rolling out <b>early April 2026 </b>and expect to complete by <b>mid-April 2026</b>.</li><li> General Availability (Worldwide): We will begin rolling out <b>August 2027 </b>(previously August 2026)<b>.</b></li></ul><p><b>[How this affects your organization:]</b></p><p><b>Who is affected:</b></p> <ul> <li>Security analysts and admins triaging DLP alerts in Microsoft Defender XDR</li> <li>Organizations using Microsoft Purview Data Security Triage Agent</li> </ul> <p><b>What will happen:</b></p> <ul> <li>DLP alerts in Defender XDR will display <b>AI-generated summaries and categorizations</b> when the Agent is deployed.</li><p>Screenshot 2: <i>Security Analysts and Admins triaging DLP alerts in Defenders will be able to deploy the Data Security Triage Agent from the Microsoft Defender XDR portal</i></p><p><img src="https://cxcs.microsoft.net/file/ccp/en-us/920c32a9-6acc-4c6d-9533-ed198096d581" style="width: 400px;" alt="user settings"></p> <li>If the Agent is not deployed, eligible analysts can <b>deploy it from the DLP alert page</b> in Defender XDR.</li> <li>Agent management (instructions, pause/deactivate, usage monitoring) remains in Microsoft Purview.</li> <li>Existing DLP policies and enforcement are <b>not changed</b>.</li> <li>There is no impact to users.</li> </ul> <p><b>[What you can do to prepare:]</b></p> <ul> <li>Deploy the <b>Data Security Triage Agent</b> in <b>Microsoft Purview </b>to enable summaries in Defender XDR.</li><li>Review role assignments to ensure analysts who triage DLP alerts have the appropriate permissions.</li><li>Update internal security operations documentation to reflect the new triage experience.</li><li>Familiarize security teams with where Agent deployment can occur (Defender XDR) and where ongoing management is performed (Purview).</li> </ul> <p><b>Learn more: </b>Before rollout, we will update this post with new documentation.</p><p><b>[Compliance considerations:]</b></p> <table border="1" cellpadding="6" cellspacing="0"> <tbody><tr> <th>Compliance area</th> <th>Explanation</th> </tr> <tr> <td>AI/ML or agent capabilities interacting with customer data</td> <td>This change introduces AI-generated summaries and categorizations for DLP alerts using the Microsoft Purview Data Security Triage Agent, which processes existing DLP alert data to assist analysts during triage.</td> </tr> <tr> <td>Admin controls</td> <td>Admins can deploy the Data Security Triage Agent from the Microsoft Defender XDR portal. Ongoing agent management, including custom instructions, pausing or deactivating the agent, and monitoring usage, remains available in the Microsoft Purview portal.</td> </tr> <tr> <td>Admin monitoring and compliance reporting</td> <td>The update enhances DLP alert investigations by adding AI-generated context, improving how admins monitor and assess data security incidents without changing underlying DLP policy enforcement or audit logging.</td> </tr> </tbody></table>

Never Miss a Microsoft 365 Update

Join thousands of IT professionals who rely on DeltaPulse for real-time Microsoft 365 change intelligence, automated notifications, and community insights.