Microsoft is retiring endpoint-sensitive data alerting in the Microsoft Defender portal by March 23, 2026. Organizations must switch to Microsoft Purview DLP for alerting, enforcement, and investigation of sensitive data activities on endpoints. Existing Defender alert policies will stop generating alerts after this date.
Introduction
We’re retiring the ability to create alert policies and generate DLP alerts for sensitive data activities on endpoints in the Microsoft Defender portal. This change unifies endpoint data loss prevention (DLP) detection and alerting under Microsoft Purview DLP, giving organizations a more consistent experience and access to advanced enforcement and investigation capabilities in Microsoft Defender XDR.
When this will happen
How this affects your organization
Who is affected:
What will happen:

What you can do to prepare
Compliance considerations
No compliance considerations identified. Review as appropriate for your organization.