Published Jan 13, 2026
Starting February 2026, Microsoft Purview Activity Explorer will let admins preview flagged email attachments in Exchange Online without downloading them, simplifying investigations. This feature is enabled by default, requires no action, and does not change existing DLP or Information Protection policies.
Updated February 17, 2026: We have updated the timeline. Thank you for your patience.
Introduction
We’re enhancing Activity Explorer in the Microsoft Purview compliance portal to provide better visibility into sensitive data detected in Exchange Online. Today, admins can only view email message bodies when investigating Data Loss Prevention (DLP) or Information Protection events. With this update, admins will be able to preview flagged email attachments directly within Activity Explorer—without downloading the email—simplifying investigations and reducing risk exposure.
This message is associated with Microsoft Roadmap ID 543969.
When this will happen
General Availability (Worldwide) rollout will begin in early February 2026 and complete by end of February 2026 (previously early February).
How this affects your organization
Who is affected: Admins who use Microsoft Purview Activity Explorer to investigate Data Loss Prevention (DLP) or Information Protection events in Exchange Online.
What will happen:

What you can do to prepare
Compliance considerations
No compliance considerations identified. Review as appropriate for your organization.