Summary
Microsoft Purview Endpoint Data Loss Prevention on Windows will soon treat archive files as single atomic objects, meaning only the outer archive generates events rather than individual internal files. The rollout begins in late September 2026 and concludes by early November 2026. Administrators should update internal monitoring procedures and inform compliance teams about the new reporting behaviour.
Administrator impact: No direct administrator action is required.
End user impact: No direct end user impact is expected.
Score rationale: This update modifies event reporting behavior for archive files without requiring configuration changes.
Microsoft 365 Roadmap ID 570965
Microsoft Purview Endpoint DLP on Windows will classify archive files (.zip, .rar) as single atomic objects, reporting only the outer archive in events. This change, rolling out from September to November 2026, improves consistency and performance without requiring user or admin action.
Published: 18 Sept 2026
Expires: 7 Dec 2026
Last updated: 18 Sept 2026
Roadmap ID: 570965
Platforms: Web
Category: Stay Informed
Tags: Microsoft Purview, Feature update, User impact, Admin impact
Microsoft Message
We are updating archive file classification behavior for Microsoft Purview Endpoint Data Loss Prevention (DLP) on Windows endpoints to align with classification behavior across Microsoft cloud workloads. This change improves consistency in classification results, reduces event-reporting noise, and enhances performance when processing archive files.
This message is associated with Microsoft 365 Roadmap ID 570965.
Rollout schedule
- Public Preview: Beginning in late September 2026 and expected to complete in mid-October 2026
- General Availability (Worldwide): Beginning in late October 2026 and expected to complete in early November 2026
Impact on your organization
Who is affected
Organizations using Microsoft Purview Endpoint DLP on Windows endpoints with archive file classification enabled
Platforms and services
- Microsoft Purview
- Endpoint Data Loss Prevention (DLP)
- Windows endpoints
What will happen
- Archive files such as .zip and .rar files will be classified directly.
- Classification of archive files will occur as a single, atomic operation.
- Individual files contained within an archive will no longer generate separate classification events.
- Only the outer archive file will be reported in Endpoint DLP events.
- Context-based and sensitivity label-based policy evaluation will continue to apply to content within archive files.
- Existing DLP policy behavior for evaluating content within archive files is unchanged.
- No administrator configuration changes are required.
- No user action is required.
Action required and recommendations
No action is required.
We recommend that administrators:
- Review internal documentation that describes archive file classification behavior.
- Update operational and monitoring procedures if they reference individual event generation for files contained within archives.
- Inform compliance and security teams that Endpoint DLP reporting will show events for the outer archive file instead of individual files within the archive.
Compliance considerations
Question: Does the change alter how existing customer data is processed, stored, or accessed?
Answer: Archive files will be classified as a single atomic object and reported as the outer archive file rather than generating separate events for files within the archive.
Question: Does the change alter how admins can monitor, report on, or demonstrate compliance activities?
Answer: Yes. Administrators will see reporting and event-generation changes. Individual files inside archives will no longer generate separate events, and reporting will be associated with the outer archive file.