Microsoft Purview introduces a new DLP alert classification property—True Positive, False Positive, Benign Positive, or Not Set—syncing with Microsoft Defender. Rolling out from late October to December 2025, it enables individual or bulk classification by admins, enhancing alert management and reporting without requiring activation.
Introduction
To help security teams better manage and report on data loss prevention (DLP) alerts, Microsoft Purview is introducing a new classification property. This feature allows alerts to be categorized directly in the Purview portal as True Positive, False Positive, or Benign Positive. Classifications can be applied individually or in bulk, and they sync bi-directionally with Microsoft Defender.
This message is associated with Microsoft 365 Roadmap ID 511795.
When this will happen:
Public Preview: Rollout will begin in late October 2025 and is expected to complete by early November 2025.
General Availability (Worldwide): Rollout will begin in late November 2025 and is expected to complete by early December 2025.
How this affects your organization:
What you can do to prepare:
For visual guidance, refer to the confirmation email attachments for high-resolution PNGs.
How to use the feature:
Does the change store new customer data? | Yes, it stores a new classification property in alert data. |
Does the change alter how admins can monitor, report on, or demonstrate compliance activities? | Yes, admins can now use the classification property on alerts to generate reports. |