MC1474107 - Microsoft Purview: Archive file classification behavior change for Endpoint Data Loss Prevention on Windows endpoints

Message Center

Summary

Microsoft Purview Endpoint DLP on Windows will classify archive files (.zip, .rar) as single atomic objects, reporting only the outer archive in events. This change, rolling out from September to November 2026, improves consistency and performance without requiring user or admin action.

Published

Sep 18, 2026

Service

Microsoft Purview

Tag

Feature update
User impact
Admin impact

Platforms

Web

More information

What and why

We are updating archive file classification behavior for Microsoft Purview Endpoint Data Loss Prevention (DLP) on Windows endpoints to align with classification behavior across Microsoft cloud workloads. This change improves consistency in classification results, reduces event-reporting noise, and enhances performance when processing archive files.

This message is associated with Microsoft 365 Roadmap ID 570965.

Rollout schedule

  • Public Preview: Beginning in late September 2026 and expected to complete in mid-October 2026
  • General Availability (Worldwide): Beginning in late October 2026 and expected to complete in early November 2026

Impact on your organization

Who is affected

  • Organizations using Microsoft Purview Endpoint DLP on Windows endpoints with archive file classification enabled

Platforms and services

  • Microsoft Purview
  • Endpoint Data Loss Prevention (DLP)
  • Windows endpoints

What will happen

  • Archive files such as .zip and .rar files will be classified directly.
  • Classification of archive files will occur as a single, atomic operation.
  • Individual files contained within an archive will no longer generate separate classification events.
  • Only the outer archive file will be reported in Endpoint DLP events.
  • Context-based and sensitivity label-based policy evaluation will continue to apply to content within archive files.
  • Existing DLP policy behavior for evaluating content within archive files is unchanged.
  • No administrator configuration changes are required.
  • No user action is required.

Action required and recommendations

No action is required.

We recommend that administrators:

  • Review internal documentation that describes archive file classification behavior.
  • Update operational and monitoring procedures if they reference individual event generation for files contained within archives.
  • Inform compliance and security teams that Endpoint DLP reporting will show events for the outer archive file instead of individual files within the archive.

Compliance considerations

QuestionAnswer
Does the change alter how existing customer data is processed, stored, or accessed?Archive files will be classified as a single atomic object and reported as the outer archive file rather than generating separate events for files within the archive.
Does the change alter how admins can monitor, report on, or demonstrate compliance activities?Yes. Administrators will see reporting and event-generation changes. Individual files inside archives will no longer generate separate events, and reporting will be associated with the outer archive file.