Skip to Content

MC1465771 Microsoft Defender XDR DLP alerts will be set as behaviors by default

Summary

  • Microsoft Defender XDR will treat Microsoft Purview DLP alerts as behaviors by default using a built-in alert tuning rule.
  • This reduces DLP alert volume in the Defender XDR incident queue while keeping investigation data available in Advanced Hunting and the Purview portal.
  • Security admins and analysts should review whether their SOC processes, automations, and reporting depend on DLP alerts appearing as standard incidents.
  • If your organization wants the current behavior, disable the alert tuning rule before it is enabled by default; otherwise no action is required.

Microsoft Defender XDR will set Microsoft Purview DLP alerts as behaviors by default starting October 12, 2026, reducing alert volume while keeping DLP data accessible in Advanced Hunting and Purview. Administrators can disable this rule to retain DLP alerts in the Defender XDR incident queue.

MC1465771 Microsoft Defender XDR DLP alerts will be set as behaviors by default

Microsoft 365 Message Center ID: MC1465771
Primary Service: Defender XDR
Admin Impact: Medium
User Impact: Low
Release Start: 12 Oct 2026
Release End: 12 Oct 2026
Last Modified: September 2, 2026
Category: Stay Informed
Tags: New feature, Admin impact
Status: Launched
Products & Platforms: Microsoft Defender XDR, Microsoft Purview

History

9/1/2026 Item Added to Message Center

Microsoft Message

Microsoft Defender XDR is introducing a new built-in alert tuning rule that sets Microsoft Purview Data Loss Prevention (DLP) alerts as behaviors. This change is designed to reduce alert volume in Microsoft Defender XDR while preserving DLP investigation data in Advanced Hunting and the Microsoft Purview portal.

Administrators can disable the rule if they prefer DLP events to continue generating standard alerts and appearing in the incident queues in Microsoft Defender XDR portal.

Rollout Schedule

The alert tuning rule is available for review today in Microsoft Defender XDR.

The rule will be enabled by default beginning October 12, 2026.

Impact on Your Organization

Who is affected

Security administrators and analysts who use Microsoft Defender XDR and Microsoft Purview DLP.

Services affected

Microsoft Defender XDR, Microsoft Purview Data Loss Prevention (DLP), Advanced Hunting.

After the change takes effect:

  • DLP alerts will no longer appear in the Microsoft Defender XDR incident queue by default.
  • DLP signals will remain available for investigation through the BehaviorInfo and BehaviorEntities tables in Advanced Hunting.
  • DLP alerts will continue to be available in the Microsoft Purview portal.
  • This change is controlled by the built-in alert tuning rule: Set-As-Behavior – Data Loss Prevention (DLP) Alerts.

Action Required / Recommendations

No action is required if you want to use the new default experience.

If your organization relies on DLP alerts appearing in the Microsoft Defender XDR incident queue, disable the rule before October 12, 2026, to keep the current experience. The rule can also be disabled at any time after it takes effect.

To continue receiving DLP alerts in the Microsoft Defender XDR incident queue:

  1. Go to Settings > Microsoft Defender XDR > Alert tuning.
  2. Locate the rule Set-As-Behavior – Data Loss Prevention (DLP) Alerts.
  3. Disable the rule.

Additional Considerations

Organizations that use Microsoft Defender XDR incidents and alerts as part of their Security Operations Center (SOC) processes should evaluate any downstream integrations, automation, reporting, monitoring, and alert triage workflows that depend on DLP alerts being present in the Defender XDR incident queue.

If your organization accesses DLP alerts programmatically through Graph Alerts V2, note that once the rule takes effect, the data will instead be available through the Microsoft Graph security runHuntingQuery API.