Favorite your Message Center and Roadmap items. Access them anytime via your Profile. Export and share with your team or your LLM.

Microsoft Defender XDR: DLP alerts will be set as behaviors by default

Message ID
MC1465771
View in Message Center
Services
Microsoft Defender XDRMicrosoft Purview
Category
Plan for Change
Tags
Major Change New featureAdmin impact
Rollout
September 2026October 2026

Summary

Microsoft Defender XDR will set Microsoft Purview DLP alerts as behaviors by default starting October 12, 2026, reducing alert volume while keeping DLP data accessible in Advanced Hunting and Purview. Administrators can disable this rule to retain DLP alerts in the Defender XDR incident queue.

Details

[What and why:]

Microsoft Defender XDR is introducing a new built-in alert tuning rule that sets Microsoft Purview Data Loss Prevention (DLP) alerts as behaviors. This change is designed to reduce alert volume in Microsoft Defender XDR while preserving DLP investigation data in Advanced Hunting and the Microsoft Purview portal.

Administrators can disable the rule if they prefer DLP events to continue generating standard alerts and appearing in the incident queues in Microsoft Defender XDR portal.

[Rollout Schedule:]

  • The alert tuning rule is available for review today in Microsoft Defender XDR.
  • The rule will be enabled by default beginning October 12, 2026.

[Impact on Your Organization:]

Who is affected:

  • Security administrators and analysts who use Microsoft Defender XDR and Microsoft Purview DLP.

Services affected:

  • Microsoft Defender XDR, Microsoft Purview Data Loss Prevention (DLP), Advanced Hunting.

After the change takes effect:

  • DLP alerts will no longer appear in the Microsoft Defender XDR incident queue by default.
  • DLP signals will remain available for investigation through the BehaviorInfo and BehaviorEntities tables in Advanced Hunting.
  • DLP alerts will continue to be available in the Microsoft Purview portal.
  • This change is controlled by the built-in alert tuning rule: Set-As-Behavior - Data Loss Prevention (DLP) Alerts.

[Action Required / Recommendations:]

No action is required if you want to use the new default experience.

If your organization relies on DLP alerts appearing in the Microsoft Defender XDR incident queue, disable the rule before October 12, 2026, to keep the current experience. The rule can also be disabled at any time after it takes effect.

To continue receiving DLP alerts in the Microsoft Defender XDR incident queue:

  1. Go to Settings > Microsoft Defender XDR > Alert tuning.
  2. Locate the rule Set-As-Behavior - Data Loss Prevention (DLP) Alerts.
  3. Disable the rule.

Additional Considerations

Organizations that use Microsoft Defender XDR incidents and alerts as part of their Security Operations Center (SOC) processes should evaluate any downstream integrations, automation, reporting, monitoring, and alert triage workflows that depend on DLP alerts being present in the Defender XDR incident queue.

If your organization accesses DLP alerts programmatically through Graph Alerts V2, note that once the rule takes effect, the data will instead be available through the Microsoft Graph security runHuntingQuery API.

Change History

Show
No change history available

Never Miss a Microsoft 365 Update

Join thousands of IT professionals who rely on DeltaPulse for real-time Microsoft 365 change intelligence, automated notifications, and community insights.