Microsoft 365 Message Center item MC1465771

MC1465771 - Microsoft Defender XDR: DLP alerts will be set as behaviors by default

Microsoft Defender XDR will set Microsoft Purview DLP alerts as behaviors by default starting October 12, 2026, reducing alert volume while keeping DLP data accessible in Advanced Hunting and Purview. Administrators can disable this rule to retain DLP alerts in the Defender XDR incident queue.

Message Center ID
MC1465771
Category
plan For Change
Severity
normal
Services
Microsoft Defender XDR, Microsoft Purview
Tags
New feature, Admin impact
Published
2026-09-01
Last updated
2026-09-01
Expires
2026-12-21

[What and why:] Microsoft Defender XDR is introducing a new built-in alert tuning rule that sets Microsoft Purview Data Loss Prevention (DLP) alerts as behaviors. This change is designed to reduce alert volume in Microsoft Defender XDR while preserving DLP investigation data in Advanced Hunting and the Microsoft Purview portal. Administrators can disable the rule if they prefer DLP events to continue generating standard alerts and appearing in the incident queues in Microsoft Defender XDR portal. [Rollout Schedule:] The alert tuning rule is available for review today in Microsoft Defender XDR. The rule will be enabled by default beginning October 12, 2026. [Impact on Your Organization:] Who is affected: Security administrators and analysts who use Microsoft Defender XDR and Microsoft Purview DLP. Services affected: Microsoft Defender XDR, Microsoft Purview Data Loss Prevention (DLP), Advanced Hunting. After the change takes effect: DLP alerts will no longer appear in the Microsoft Defender XDR incident queue by default. DLP signals will remain available for investigation through the BehaviorInfo and BehaviorEntities tables in Advanced Hunting. DLP alerts will continue to be available in the Microsoft Purview portal. This change is controlled by the built-in alert tuning rule: Set-As-Behavior - Data Loss Prevention (DLP) Alerts. [Action Required / Recommendations:] No action is required if you want to use the new default experience. If your organization relies on DLP alerts appearing in the Microsoft Defender XDR incident queue, disable the rule before October 12, 2026, to keep the current experience. The rule can also be disabled at any time after it takes effect.To continue receiving DLP alerts in the Microsoft Defender XDR incident queue: Go to Settings > Microsoft Defender XDR > Alert tuning. Locate the rule Set-As-Behavior - Data Loss Prevention (DLP) Alerts. Disable the rule.Additional Considerations Organizations that use Microsoft Defender XDR incidents and alerts as part of their Security Operations Center (SOC) processes should evaluate any downstream integrations, automation, reporting, monitoring, and alert triage workflows that depend on DLP alerts being present in the Defender XDR incident queue.If your organization accesses DLP alerts programmatically through Graph Alerts V2, note that once the rule takes effect, the data will instead be available through the Microsoft Graph security runHuntingQuery API.