Message Center
Microsoft Purview DLP for Exchange Online will enrich audit data with detailed matched conditions (e.g., sender, recipient, attachment, subject) when a DLP rule triggers. This enhancement, rolling out late June to July 2026, improves visibility without changing enforcement or requiring configuration.
What and Why:
We are enhancing Microsoft Purview Data Loss Prevention (DLP) audit data for Exchange Online by adding enriched matched condition details whenever a DLP rule is triggered. Previously, audit records primarily surfaced sensitive information type (SIT) matches. With this update, audit records now include all contributing rule conditions, including non-SIT conditions such as sender and recipient attributes, attachment properties, subject keywords, and message metadata.
This change aligns with Microsoft’s enterprise-ready security and compliance commitments. It provides clearer insight into why a DLP rule was triggered without requiring manual cross-referencing of policy configurations and audit logs.
This message is associated with Roadmap ID 562051.
Rollout Schedule:
Impact on Your Organization:
Who is affected:
Platforms/Services:
What will happen:
Supported conditions and example output:
Attachment conditions
| Condition | Example output |
|---|---|
| File extension is | Attachment Extension: txt — Testing.txt |
| Document or attachment is password protected | File.txt — Password Protected |
| Document could not be scanned | File.txt — Other Error |
| Document didn’t complete scanning | File.txt — Other Error |
| Attachment count over | 12 — Document1.pdf; Document2.pdf; Document3.pdf; Document4.pdf; Document5.pdf; ...+7 more |
Sender conditions
| Condition | Example output |
|---|---|
| Shared by users | [email protected] |
| Sender domain is | contoso.com — [email protected] |
| Sender IP address is | 192.168.1.100 — [email protected] |
| Sender AD attribute contains words | Sales Department — [email protected] |
Recipient conditions
| Condition | Example output |
|---|---|
| Recipient domain is | fabrikam.com — [email protected] |
| Shared with user | [email protected] — USERNAME |
| Unique domain count over | 3 — contoso.com; fabrikam.com; adventureworks.net |
| Recipient AD attribute contains words | Seattle — [email protected]; Portland — [email protected] |
Subject and body conditions
| Condition | Example output |
|---|---|
| Subject contains words | Matchedword — Subject: this is Matchedword subject |
Message conditions
| Condition | Example output |
|---|---|
| Message size over | 5242880 — Q1 Financial Report with Attachments |
How matched condition evidence is structured:
If multiple values match a condition, all contributing sources are listed. If more than five attachments match, the first five are shown followed by a count of additional matches (for example, “+7 more”).
Action Required / Recommendations:
No action is required. This feature is enabled automatically for all DLP policies scoped to Exchange Online.
Note: Matched condition details may take up to 60 minutes to appear in Activity Explorer.
Compliance considerations:
| Area | Explanation |
|---|---|
| Audit logging capabilities | Audit records now include additional matched condition metadata for DLP rule evaluations in Exchange Online. |
| Admin monitoring and reporting | Admins gain increased visibility into DLP rule triggers via Activity Explorer, alerts, and audit logs. |
| Processing of existing customer data | Existing email metadata and DLP evaluation results are logged with richer detail; no new data types are introduced. |