Microsoft Defender XDR
General

Investigate data loss prevention alerts with Microsoft Defender XDR

In brief

The documentation now states that a built-in alert tuning rule will take effect in early October 2026. In Microsoft Defender XDR, affected DLP signals will appear as behaviors instead of alerts, so they will not generate alerts or enter the incident queue, but will remain available for advanced hunting.

What Defender admins need to know

Administrators who need to manage these DLP alerts in Defender must disable the built-in tuning rule; otherwise, they will need to use advanced hunting for the signals.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Investigate data loss prevention alerts with Microsoft Defender XDR

[!INCLUDE Microsoft Defender XDR rebranding]

YouWhen the built-in DLP alert tuning rule is disabled, you can manage and respond to Microsoft Purview Data Loss Prevention (DLP) alerts and incidents in the Microsoft Defender portal. Open Incidents & alerts > Incidents on the quick launch of the Microsoft Defender portal. From this page, you can:

  • View all your DLP alerts grouped under incidents in the Microsoft Defender XDR incident queue.
  • View DLP alerts correlated with other DLP alerts, or with alerts from other solutions (Defender for Endpoint, Defender for Office 365, Microsoft Sentinel, and so on), under a single incident.
  • Microsoft 365 E5/A5 Compliance
  • Microsoft 365 E5/A5 Information Protection and Governance

Roles

It's best practice to only grant minimal permissions to alerts in the Microsoft Defender portal. You can create a custom role with these roles and assign it to the users who need to investigate DLP alerts.

  1. View the Alert story for details about policy and the sensitive information types detected in the alert. Select the event in the Related Events section to see the user activity details.

  2. View the matched sensitive content in the Sensitive info types tab and the file content in the Source tab if you have the required permission (See details here

    Roles

    It's best practice to only grant minimal permissions to alerts in the Microsoft Defender portal. You can create a custom role with these roles and assign it to the users who need to investigate DLP alerts.

    1. View the Alert story for details about policy and the sensitive information types detected in the alert. Select the event in the Related Events section to see the user activity details.

    2. View the matched sensitive content in the Sensitive info types tab and the file content in the Source tab if you have the required permission (see required roles and permissions).

    Extend DLP alert investigation with advanced hunting

    Before you begin

    If you're new to Microsoft Defender advanced hunting, you should review Get started with advanced hunting.

    Before you can use advanced hunting you must have access to the CloudAppEvents table that contains Microsoft Purview DLP audit data.

    To take remediation actions on the user,user associated with the alert, select the User card on the top of the alert page to open the user details.

    For Devices DLP alerts, select the device card on the top of the alert page to view details about the device detailsassociated with the alert and take remediation actions on the device.actions.

    Go to the incident summary page and select Manage Incident to add incident tags, assign, or resolve an incident.

    Related articles

    [!INCLUDE Microsoft Defender XDR rebranding]