Message Center
Updated July 7, 2026: We have updated the timeline. Thank you for your patience.
What and Why:
Microsoft Purview Endpoint Data Loss Prevention (DLP) is introducing the ability to protect sensitive files even when they reside in commonly excluded Windows folders such as AppData directories and temporary folders. Previously, files stored in these excluded paths were not subjected to Endpoint DLP policy enforcement. With this update, policy checks will apply during key egress actions, including copying, printing, saving to network shares, and uploading to cloud services, helping reduce the risk of sensitive data leaving your organization from these user-writable locations.
This message is associated with Microsoft 365 Roadmap ID 562992.
Rollout Schedule:
General Availability (Worldwide): We will begin rolling out in mid-September 2026 (previously early July 2026July) and expect to complete by end of September 2026 (previously early July 2026July).
How this will affect your organization:
Who is affected: Admins and users in organizations that use Microsoft Purview Endpoint Data Loss Prevention (DLP) on Windows devices
Platforms:
What will happen:
With this update, admins can extend
Endpoint DLP protection to files stored in excluded Windows folders (for
example, %AppData% and temporary directories) during egress activities.
This change improves protection coverage by addressing scenarios where sensitive data in excluded paths may have previously gone unmonitored.
Screenshot: Endpoint DLP settings for excluded Windows folders and file egress activities:
Action Required / Recommendations:
Compliance considerations:
| Compliance consideration | Explanation |
|---|---|
| Admin control | Admins must review excluded Windows folder paths and update Endpoint DLP policies to enable protection for files stored in excluded folders. |
| User impact | Users may experience blocked actions such as copying to removable media, printing, saving to network shares, or uploading to cloud services when interacting with sensitive files stored in protected excluded folders. |
| Policy changes | Organizations may need to extend existing Endpoint DLP policies to include protected excluded folders. |
| User training | Organizations should educate users and support teams about new enforcement behavior and potential blocked actions. |
| Monitoring/Auditing | Audit mode logging will capture user actions involving sensitive files in protected excluded paths for review and analysis. |
| Prerequisite dependency | Devices must run anti-malware client version 4.18.26051 or later before enabling this feature. |
| Security/Compliance impact | This update expands Endpoint DLP protection coverage to previously excluded Windows folder locations, helping reduce the risk of sensitive data exfiltration. |
| Rollout risk assessment | Organizations may want to pilot the feature in audit mode before enabling enforcement to assess operational impact. |
What and Why:
Microsoft Purview Endpoint Data Loss Prevention (DLP) is introducing the ability to protect sensitive files even when they reside in commonly excluded Windows folders such as AppData directories and temporary folders. Previously, files stored in these excluded paths were not subjected to Endpoint DLP policy enforcement. With this update, policy checks will apply during key egress actions, including copying, printing, saving to network shares, and uploading to cloud services, helping reduce the risk of sensitive data leaving your organization from these user-writable locations.
This message is associated with Microsoft 365 Roadmap ID 562992.
Rollout Schedule:
General Availability (Worldwide): We will begin rolling out in early July 2026 and expect to complete by early July 2026.
How this will affect your organization:
Who is affected: Admins and users in organizations that use Microsoft Purview Endpoint Data Loss Prevention (DLP) on Windows devices
Platforms:
What will happen:
With this update, admins can extend
Endpoint DLP protection to files stored in excluded Windows folders (for
example, %AppData% and temporary directories) during egress activities.
This change improves protection coverage by addressing scenarios where sensitive data in excluded paths may have previously gone unmonitored.
Screenshot: Endpoint DLP settings for excluded Windows folders and file egress activities:
Action Required / Recommendations:
Compliance considerations:
| Compliance consideration | Explanation |
|---|---|
| Admin control | Admins must review excluded Windows folder paths and update Endpoint DLP policies to enable protection for files stored in excluded folders. |
| User impact | Users may experience blocked actions such as copying to removable media, printing, saving to network shares, or uploading to cloud services when interacting with sensitive files stored in protected excluded folders. |
| Policy changes | Organizations may need to extend existing Endpoint DLP policies to include protected excluded folders. |
| User training | Organizations should educate users and support teams about new enforcement behavior and potential blocked actions. |
| Monitoring/Auditing | Audit mode logging will capture user actions involving sensitive files in protected excluded paths for review and analysis. |
| Prerequisite dependency | Devices must run anti-malware client version 4.18.26051 or later before enabling this feature. |
| Security/Compliance impact | This update expands Endpoint DLP protection coverage to previously excluded Windows folder locations, helping reduce the risk of sensitive data exfiltration. |
| Rollout risk assessment | Organizations may want to pilot the feature in audit mode before enabling enforcement to assess operational impact. |