RM562051 - Microsoft Purview: Data Loss Prevention - Enriched Audit Data for Matched Rules

Microsoft 365 Roadmap

Summary

When DLP rules detect policy violations in Exchange Online, they generate audit records that administrators rely on for compliance monitoring, incident investigation, and policy tuning. Previously, these records only showed Sensitive Information Type matches. This feature aims to extend that to sender domain, subject keywords, attachment type, or recipient information. Now they will be visible in alerts and Activity Explorer providing data enrichment to the administrators.

Last Updated

Jul 28, 2026

Published May 12, 2026

View version history

Status

Launched

Release

General Availability
Preview

Platforms

Web

Service

Microsoft Purview

Tag

Launched
General Availability
Preview
Worldwide (Standard Multi-Tenant)

Cloud

Worldwide (Standard Multi-Tenant)

Description

When DLP rules detect policy violations in Exchange Online, they generate audit records that administrators rely on for compliance monitoring, incident investigation, and policy tuning. Previously, these records only showed Sensitive Information Type matches. This feature aims to extend that to sender domain, subject keywords, attachment type, or recipient information. Now they will be visible in alerts and Activity Explorer providing data enrichment to the administrators.

GA date: June CY2026

Preview date: May CY2026

Version history

2 versions tracked

Updated 1 time since May 12, 2026. Microsoft Message Center only ever shows the current version; this archive preserves the history.

Compare any two versions

From
To
  1. Jul 28, 2026 · 10:43 PMLatest · v2

    Changed: Tags, Status

  2. May 12, 2026 · 11:00 PMOriginal · v1

    Changed: Initial version