Microsoft Defender XDR: DLP alerts will be set as behaviors by default

🚨 The Signal: Microsoft Defender XDR will classify Purview DLP alerts as 'behaviors' by default, reducing alert volume in the incident queue. DLP data remains in Advanced Hunting and Purview portal for investigation, but security teams must adjust their alert triage workflows.

The Impact

Security administrators and analysts are affected, with a risk of delayed or missed DLP incident response if workflows are not updated.

  • Security Analysts: Risk of missing DLP alerts in Defender XDR incident queue.
  • Security Administrators: Need to review and potentially reconfigure alert tuning rules.
  • Incident Responders: Workflows for DLP incidents require adjustment to use Advanced Hunting or Purview portal.

The Action

  1. Review the 'Set-As-Behavior - Data Loss Prevention (DLP) Alerts' rule in Microsoft Defender XDR portal under Settings > Incidents & alerts > Alert tuning.
  2. If current workflows rely on DLP alerts in the Defender XDR incident queue, disable the 'Set-As-Behavior - Data Loss Prevention (DLP) Alerts' rule before October 12, 2026.
  3. Update incident response playbooks to incorporate Advanced Hunting (BehaviorInfo, BehaviorEntities tables) or the Microsoft Purview portal for DLP alert investigation.
  4. Communicate the change to all security operations center (SOC) personnel and provide training on updated DLP alert investigation procedures.

Domain: Defender · Impact: medium · Workload: Microsoft Defender